azure-keyvault-administration
Microsoft Corporation Key Vault Administration Client Library for Python
Decision gist · record as of 2026-08-14
Yes. This is the official, actively maintained Azure SDK library for Managed HSM administration. It has low install friction, permissive MIT licensing, no known vulnerabilities, and is in production-stable status. Install it if you need to programmatically manage access control, backups, or settings on an Azure Key Vault Managed HSM; do not use it for standard Key Vault operations.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later and an existing Azure Key Vault Managed HSM instance (does not work with standard Key Vault).
- Low install friction with three lightweight runtime dependencies (isodate, azure-core, typing-extensions).
- Active maintenance with a release 87 days ago and ongoing repository activity.
License · maintenance · safety
MIT License (permissive) — MIT License permits commercial use, modification, and distribution with minimal restrictions—suitable for most projects.
last release 2026-05-19 (87 days) · last repo commit 2026-08-14 · 5,588 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,241,871 downloads/mo, #2,131 on PyPI
Alternatives
Verify before relying
pip install azure-keyvault-administration
from azure.keyvault.administration import KeyVaultAccessControlClient
from azure.core import credential
client = KeyVaultAccessControlClient(vault_url=MANAGED_HSM_URL, credential=credential)- Whether async variants (azure.keyvault.administration.aio) are production-ready or have known limitations.
- Performance characteristics for large-scale backup/restore operations on Managed HSM.
- Support status for authentication methods beyond those documented in the package description.
What it is and what it does
This is the official Azure SDK client library for administering Key Vault Managed HSM instances. It provides three main client classes: KeyVaultAccessControlClient for managing role definitions and assignments, KeyVaultBackupClient for performing full and selective key backups and restores, and KeyVaultSettingsClient for configuring Managed HSM account settings. The library handles long-running operations like pre-backup checks and restore operations through polling abstractions.
The package is tightly integrated with azure-core for HTTP transport and credential handling. It is explicitly designed for Managed HSM only—operations against standard Key Vault instances will fail. The library supports Python 3.9 through 3.13 and is maintained as part of the official Azure SDK for Python.
Use it for
- Implement role-based access control (RBAC) for Managed HSM by creating and managing role assignments programmatically.
- Automate full or selective key backups and restores for disaster recovery and key rotation workflows.
- Configure Managed HSM account settings such as security policies or operational parameters via the settings client.
- Build administrative dashboards or CLI tools that list and manage role definitions across multiple Managed HSM instances.
- Integrate Managed HSM administration into Infrastructure-as-Code or DevOps pipelines for key vault lifecycle management.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is the official, actively maintained Azure SDK library for Managed HSM administration. It has low install friction, permissive MIT licensing, no known vulnerabilities, and is in production-stable status. Install it if you need to programmatically manage access control, backups, or settings on an Azure Key Vault Managed HSM; do not use it for standard Key Vault operations.
Install
azure-keyvault-administration on PyPI
Before you install
Low install friction with three lightweight runtime dependencies (isodate, azure-core, typing-extensions). Active maintenance with a release 87 days ago and ongoing repository activity.
Requires Python 3.9 or later and an existing Azure Key Vault Managed HSM instance (does not work with standard Key Vault).
License in practice
MIT License permits commercial use, modification, and distribution with minimal restrictions—suitable for most projects.
Quickstart
pip install azure-keyvault-administration
from azure.keyvault.administration import KeyVaultAccessControlClient
from azure.core import credential
client = KeyVaultAccessControlClient(vault_url=MANAGED_HSM_URL, credential=credential)
Verify before relying
- Whether async variants (azure.keyvault.administration.aio) are production-ready or have known limitations.
- Performance characteristics for large-scale backup/restore operations on Managed HSM.
- Support status for authentication methods beyond those documented in the package description.
Package facts
| License | MIT License permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesisodateazure-coretyping-extensions |
| Maintenance | Actively maintained 87 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 5,241,871 / month, #2,131 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableLicense :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9 |
Evidence: azure_keyvault_administration-4.7.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “azure key vault administration”
- azure-keyvault-administrationManages role-based access control, backup, restore, and settings for…
- azure-keyvault-keysManages cryptographic keys in Azure Key Vault—create, store,…
- azure-mgmt-keyvaultManages Azure Key Vault resources—vaults, keys, secrets, and managed…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also azure-keyvault-securitydomain · azure-keyvault-certificates · azure-keyvault-keys · azure-keyvault-secrets · azure-keyvault · azure-mgmt-keyvault · pydantic-settings-azure-app-configuration · consulate · azure-appconfiguration-provider · azure-mgmt-managedservices