azure-keyvault-keys
Microsoft Corporation Azure Key Vault Keys Client Library for Python
Decision gist · record as of 2026-08-14
Yes. This is an actively maintained, production-stable library from Microsoft with no known vulnerabilities, low install friction, and broad adoption (top 1000 on PyPI). Install it if you need to manage cryptographic keys in Azure Key Vault from Python. The only caveat is that license treatment is unclear—verify the actual license before use in proprietary or restricted-license projects.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Python 3.9 or later required; requires an existing Azure Key Vault and Azure credentials configured for DefaultAzureCredential.
- Low install friction with a wheel distribution.
- Actively maintained with a recent release 87 days ago.
License · maintenance · safety
(unclear)
last release 2026-05-19 (87 days) · last repo commit 2026-08-14 · 5,587 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 25,830,046 downloads/mo, #900 on PyPI
Alternatives
Verify before relying
pip install azure-keyvault-keys
from azure.identity import DefaultAzureCredential
from azure.keyvault.keys import KeyClient
VAULT_URL = "https://my-key-vault.vault.azure.net/"
credential = DefaultAzureCredential()
client = KeyClient(vault_url=VAULT_URL, credential=credential)
rsa_key = client.create_rsa_key("my-key", size=2048)- Whether async operations via azure.keyvault.keys.aio are production-ready or experimental.
- Performance characteristics and rate limits for bulk cryptographic operations.
- Specific HSM operation support and limitations beyond what Azure Key Vault service provides.
What it is and what it does
This is the Azure SDK's Python client library for managing cryptographic keys stored in Azure Key Vault. It provides a KeyClient interface to create, retrieve, update, and delete RSA and elliptic curve keys in a vault, with optional hardware security module protection. The library handles key versioning automatically—creating a new version when you update an existing key name—and supports cryptographic operations like signing and encryption directly against vault-stored keys.
The package requires Python 3.9 or later and depends on azure-core for HTTP communication, cryptography for local operations, isodate for timestamp handling, and typing-extensions for type hints. It integrates with azure-identity for authentication and is one of four specialized Key Vault client libraries—the others handle secrets, certificates, and vault administration separately.
Use it for
- Create and manage RSA or elliptic curve keys for application encryption without storing key material locally.
- Rotate encryption keys automatically using the key rotation policy API.
- Retrieve and use vault-stored keys for signing or encryption operations in a secure, audited manner.
- Disable or delete keys when they reach end-of-life, with soft-delete recovery if needed.
- Integrate key management into Azure-hosted applications using managed identity authentication.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is an actively maintained, production-stable library from Microsoft with no known vulnerabilities, low install friction, and broad adoption (top 1000 on PyPI). Install it if you need to manage cryptographic keys in Azure Key Vault from Python. The only caveat is that license treatment is unclear—verify the actual license before use in proprietary or restricted-license projects.
Install
azure-keyvault-keys on PyPI
Before you install
Low install friction with a wheel distribution. Actively maintained with a recent release 87 days ago. Depends on four runtime packages (isodate, azure-core, typing-extensions, cryptography), all standard Azure SDK components.
Python 3.9 or later required; requires an existing Azure Key Vault and Azure credentials configured for DefaultAzureCredential.
Quickstart
pip install azure-keyvault-keys
from azure.identity import DefaultAzureCredential
from azure.keyvault.keys import KeyClient
VAULT_URL = "https://my-key-vault.vault.azure.net/"
credential = DefaultAzureCredential()
client = KeyClient(vault_url=VAULT_URL, credential=credential)
rsa_key = client.create_rsa_key("my-key", size=2048)
Verify before relying
- Whether async operations via azure.keyvault.keys.aio are production-ready or experimental.
- Performance characteristics and rate limits for bulk cryptographic operations.
- Specific HSM operation support and limitations beyond what Azure Key Vault service provides.
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagesisodateazure-coretyping-extensionscryptography |
| Maintenance | Actively maintained 87 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 25,830,046 / month, #900 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9 |
Evidence: azure_keyvault_keys-4.11.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “azure key vault key management”
- azure-keyvault-keysManages cryptographic keys in Azure Key Vault—create, store,…
- azure-mgmt-keyvaultManages Azure Key Vault resources—vaults, keys, secrets, and managed…
- azure-keyvault-administrationManages role-based access control, backup, restore, and settings for…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also azure-keyvault-certificates · azure-keyvault-secrets · azure-keyvault-administration · azure-keyvault · azure-keyvault-securitydomain · azure-appconfiguration-provider · pydantic-settings-azure-app-configuration · keepercommander · azure-mgmt-keyvault · azure-schemaregistry