azure-keyvault-certificates
Microsoft Corporation Key Vault Certificates Client Library for Python
Decision gist · record as of 2026-08-14
Yes. This is the official, actively maintained Azure SDK library for certificate management. It has low install friction, no known vulnerabilities, permissive licensing, and is widely used (top 5000 PyPI packages). Install it if you need to manage certificates in Azure Key Vault; it is the standard choice for this task.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; requires an existing Azure Key Vault and Azure subscription; authentication credential must be configured separately.
- Low install friction with three lightweight runtime dependencies (isodate, azure-core, typing-extensions).
- Actively maintained with a recent release and no known vulnerabilities.
License · maintenance · safety
MIT License (permissive) — MIT License permits commercial and private use with minimal restrictions; suitable for most projects.
last release 2026-05-05 (101 days) · last repo commit 2026-08-14 · 5,588 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 14,008,812 downloads/mo, #1,255 on PyPI
Alternatives
Verify before relying
pip install azure-keyvault-certificates
from azure.keyvault.certificates import CertificateClient
from azure.core import credential
client = CertificateClient(vault_url="https://my-key-vault.vault.azure.net/", credential=credential)
certificate = client.get_certificate("cert-name")- Whether async operations (aio.CertificateClient) are production-ready or have known limitations.
- Performance characteristics for bulk certificate operations or large-scale deployments.
- Whether certificate import/export functionality is supported beyond creation and retrieval.
- Specific authentication methods supported beyond what the fact sheet documents.
What it is and what it does
This is the official Azure SDK client library for managing certificates in Azure Key Vault. It provides a Python interface to create, store, retrieve, update, and delete SSL/TLS certificates in a managed vault, with support for certificate versioning, policies, issuers, and metadata. The library depends on azure-core for HTTP communication and isodate for date handling, abstracting REST API calls to Key Vault.
Typically used in applications that need centralized certificate lifecycle management—issuing new certificates, rotating versions, enforcing policies, or retrieving certificates for use in TLS/SSL configurations. It integrates with the broader Azure Key Vault ecosystem and is part of the official Azure SDK for Python.
Use it for
- Automate SSL/TLS certificate creation and renewal in Azure Key Vault for web applications and services.
- Retrieve and deploy the latest certificate version to load balancers or reverse proxies without manual intervention.
- Enforce certificate policies (validity periods, key sizes, issuer constraints) across an organization.
- Manage certificate metadata and track certificate versions for compliance and audit purposes.
- Integrate certificate management into CI/CD pipelines for automated infrastructure provisioning.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is the official, actively maintained Azure SDK library for certificate management. It has low install friction, no known vulnerabilities, permissive licensing, and is widely used (top 5000 PyPI packages). Install it if you need to manage certificates in Azure Key Vault; it is the standard choice for this task.
Install
azure-keyvault-certificates on PyPI
Before you install
Low install friction with three lightweight runtime dependencies (isodate, azure-core, typing-extensions). Actively maintained with a recent release and no known vulnerabilities.
Requires Python 3.9 or later; requires an existing Azure Key Vault and Azure subscription; authentication credential must be configured separately.
License in practice
MIT License permits commercial and private use with minimal restrictions; suitable for most projects.
Quickstart
pip install azure-keyvault-certificates
from azure.keyvault.certificates import CertificateClient
from azure.core import credential
client = CertificateClient(vault_url="https://my-key-vault.vault.azure.net/", credential=credential)
certificate = client.get_certificate("cert-name")
Verify before relying
- Whether async operations (aio.CertificateClient) are production-ready or have known limitations.
- Performance characteristics for bulk certificate operations or large-scale deployments.
- Whether certificate import/export functionality is supported beyond creation and retrieval.
- Specific authentication methods supported beyond what the fact sheet documents.
Package facts
| License | MIT License permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesisodateazure-coretyping-extensions |
| Maintenance | Actively maintained 101 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 14,008,812 / month, #1,255 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableLicense :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9 |
Evidence: azure_keyvault_certificates-4.11.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “azure key vault certificate management”
- azure-keyvault-certificatesManages SSL/TLS certificates stored in Azure Key Vault—create,…
- azure-keyvault-secretsSecurely store, retrieve, and manage secrets (passwords, tokens, API…
- azure-mgmt-keyvaultManages Azure Key Vault resources—vaults, keys, secrets, and managed…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also azure-keyvault-keys · azure-keyvault-secrets · azure-keyvault · azure-keyvault-administration · azure-keyvault-securitydomain · PyKMIP · azure-appconfiguration-provider · hvac · azure-schemaregistry · azure-mgmt-keyvault