aws-msk-iam-sasl-signer-python
Amazon MSK Library in Python for SASL/OAUTHBEARER Auth
Decision gist · record as of 2026-08-14
Yes, if you use Amazon MSK and need IAM-based authentication. The package is Production/Stable, supports Python 3.8 through 3.13, has no known vulnerabilities, and is maintained by AWS. Install friction is low. Maintenance is aging (527 days since last release), so verify compatibility with your Kafka client library version before committing.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires AWS credentials configured in your environment (via default chain, named profile, assumed role, or custom credential provider); MSK cluster must support SASL/OAUTHBEARER mechanism.
- Low install friction; pure Python wheel with three runtime dependencies (Click, boto3, botocore).
- Last release 527 days ago; repository not archived but maintenance is aging.
License · maintenance · safety
Apache Software License 2.0 (permissive) — Apache Software License 2.0 is permissive; you may use, modify, and distribute freely in commercial and private projects with minimal restrictions.
last release 2025-03-05 (527 days) · last repo commit 2026-02-03 · 45 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,407,085 downloads/mo, #2,108 on PyPI
Alternatives
Verify before relying
pip install aws-msk-iam-sasl-signer-python
from aws_msk_iam_sasl_signer import MSKAuthTokenProvider
auth_token, expiry_ms = MSKAuthTokenProvider.generate_auth_token('')- Whether the package works with all Kafka client libraries supporting SASL/OAUTHBEARER or only specific ones.
- Performance characteristics when generating tokens at scale or under high frequency.
- Compatibility with non-standard AWS credential sources beyond those documented.
What it is and what it does
This package provides a Python library to generate base64-encoded signed authentication tokens for Amazon MSK clusters using IAM credentials. It implements the SASL/OAUTHBEARER mechanism and can source credentials from the AWS default chain, named profiles, assumed roles, or custom credential providers. The library depends on boto3 and botocore for AWS credential handling and Click for CLI support.
You integrate it by creating a token callback that calls one of the token generation methods and passing that callback to your Kafka client's OAUTHBEARER configuration. The library handles IAM signing and token expiry tracking, returning both the token and its expiration time in milliseconds.
Use it for
- Authenticate Kafka producers and consumers to MSK clusters using IAM roles instead of static credentials.
- Integrate MSK authentication into applications running on EC2 instances with instance profiles or ECS tasks with task roles.
- Use assumed IAM roles to generate temporary tokens for cross-account MSK access.
- Implement token refresh logic in long-running Kafka applications by extracting expiry time from returned values.
- Debug credential chain issues by enabling aws_debug_creds to log which IAM principal is being used.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you use Amazon MSK and need IAM-based authentication.
The package is Production/Stable, supports Python 3.8 through 3.13, has no known vulnerabilities, and is maintained by AWS. Install friction is low. Maintenance is aging (527 days since last release), so verify compatibility with your Kafka client library version before committing.
Install
aws-msk-iam-sasl-signer-python on PyPI
Before you install
Low install friction; pure Python wheel with three runtime dependencies (Click, boto3, botocore). Last release 527 days ago; repository not archived but maintenance is aging.
Requires AWS credentials configured in your environment (via default chain, named profile, assumed role, or custom credential provider); MSK cluster must support SASL/OAUTHBEARER mechanism.
License in practice
Apache Software License 2.0 is permissive; you may use, modify, and distribute freely in commercial and private projects with minimal restrictions.
Quickstart
pip install aws-msk-iam-sasl-signer-python
from aws_msk_iam_sasl_signer import MSKAuthTokenProvider
auth_token, expiry_ms = MSKAuthTokenProvider.generate_auth_token('')
Verify before relying
- Whether the package works with all Kafka client libraries supporting SASL/OAUTHBEARER or only specific ones.
- Performance characteristics when generating tokens at scale or under high frequency.
- Compatibility with non-standard AWS credential sources beyond those documented.
Package facts
| License | Apache Software License 2.0 permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesClickboto3botocore |
| Maintenance | Aging 527 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 5,407,085 / month, #2,108 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: aws_msk_iam_sasl_signer_python-1.0.2-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “MSK Kafka IAM authentication”
- aws-msk-iam-sasl-signer-pythonGenerates IAM-signed SASL/OAUTHBEARER authentication tokens for…
- google-cloud-managedkafkaPython client library for Google Cloud's Managed Service for Apache…
- matrice-commonmatrice_common provides authentication, RPC client, streaming, and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Internet packages
Botocore provides low-level, data-driven access to Amazon Web Services APIs, serving as the foundation for the AWS CLI and boto3 libraries.
Install it if you need programmatic access to AWS services.
Provides an async client for AWS services using botocore and aiohttp, allowing you to call AWS APIs asynchronously within asyncio-based applications.
Install it if you need to call AWS services from async Python code; it is the standard way to do so.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides a platform-independent file locking mechanism to coordinate access to files across processes and threads.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides common Protocol Buffer message definitions used across Google Cloud APIs, enabling Python clients to interact with Google services.
See also requests-aws-sign · aws-cdk.aws-signer · aws-requests-auth · aws-cdk.aws-iam · awacs · kafka · mastercard-oauth1-signer · mcp-proxy-for-aws · aws-assume-role-lib · boto_session_manager