$npx skillfedfor your agent

azure-keyvault-secrets

Microsoft Corporation Key Vault Secrets Client Library for Python

Worth itPyPI CryptographyReleased Aug 202660.9M downloads / moMIT LicensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — azure_keyvault_secrets-4.11.1-py3-none-any.whl
v4.11.1 · released 2026-08-12 · Python >=3.9 · 3 runtime deps: isodate, azure-core, typing-extensions

Yes. This is a production-stable, actively maintained official Azure SDK library with no known vulnerabilities, low install friction, and permissive licensing. Install it if you are building on Azure and need to externalize secret management to Key Vault; it is the standard way to do so from Python. If you are not using Azure or do not have a Key Vault instance, it has no value.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later and an existing Azure Key Vault instance with a vault URL; authentication requires a credential object configured in your environment.
  • Low install friction with three lightweight runtime dependencies (isodate, azure-core, typing-extensions).
  • Actively maintained with a recent release; the repository is not archived and has substantial community engagement.

License · maintenance · safety

MIT License (permissive) — MIT License permits commercial and private use with minimal restrictions; you may use, modify, and distribute this package freely provided you include the license notice.

last release 2026-08-12 (2 days) · last repo commit 2026-08-14 · 5,587 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 60,940,459 downloads/mo, #498 on PyPI

Verify before relying

pip install azure-keyvault-secrets

from azure.keyvault.secrets import SecretClient

client = SecretClient(vault_url="https://my-key-vault.vault.azure.net/", credential=credential)
secret = client.get_secret("secret-name")
print(secret.value)
  • What credential types are supported and how to configure them for different authentication scenarios.
  • Whether async support (aio) is production-ready and what its performance characteristics are.
  • Specific rate limits or quotas imposed by Azure Key Vault on secret operations.
  • Behavior and retry logic when vault is temporarily unavailable or rate-limited.
Same gist for agents: .md · .json

What it is and what it does

This is the official Azure SDK client library for interacting with Azure Key Vault's secrets management service. It provides a Python interface to securely store, retrieve, update, and delete secrets (passwords, API keys, tokens, certificates) stored in Azure Key Vault, with full support for secret versioning, metadata management, and soft-delete operations.

The library wraps the Azure Key Vault REST API through azure-core and handles authentication via credential objects. It's designed for applications that need to externalize credential management to a centralized, access-controlled vault rather than embedding secrets in code or configuration files. Both synchronous and asynchronous APIs are available.

Use it for

  • Retrieve database passwords or connection strings at application startup without storing them in code or environment files.
  • Manage API keys for third-party services with centralized access control and audit logging via Azure Key Vault.
  • Rotate secrets programmatically and update application instances without redeployment.
  • Store and retrieve TLS/SSL certificate secrets alongside other application credentials.
  • Implement least-privilege access by granting applications only the secrets they need via RBAC.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

This is a production-stable, actively maintained official Azure SDK library with no known vulnerabilities, low install friction, and permissive licensing. Install it if you are building on Azure and need to externalize secret management to Key Vault; it is the standard way to do so from Python. If you are not using Azure or do not have a Key Vault instance, it has no value.

Install

azure-keyvault-secrets on PyPI

Before you install

Low install friction with three lightweight runtime dependencies (isodate, azure-core, typing-extensions). Actively maintained with a recent release; the repository is not archived and has substantial community engagement.

Requires Python 3.9 or later and an existing Azure Key Vault instance with a vault URL; authentication requires a credential object configured in your environment.

License in practice

MIT License permits commercial and private use with minimal restrictions; you may use, modify, and distribute this package freely provided you include the license notice.

Quickstart

pip install azure-keyvault-secrets

from azure.keyvault.secrets import SecretClient

client = SecretClient(vault_url="https://my-key-vault.vault.azure.net/", credential=credential)
secret = client.get_secret("secret-name")
print(secret.value)

Verify before relying

  • What credential types are supported and how to configure them for different authentication scenarios.
  • Whether async support (aio) is production-ready and what its performance characteristics are.
  • Specific rate limits or quotas imposed by Azure Key Vault on secret operations.
  • Behavior and retry logic when vault is temporarily unavailable or rate-limited.

Package facts

LicenseMIT License permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
isodateazure-coretyping-extensions
MaintenanceActively maintained 2 days since the last release
Last repo commit
First released
Downloads60,940,459 / month, #498 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableLicense :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9

Evidence: azure_keyvault_secrets-4.11.1-py3-none-any.whl

Tags

Capabilities
azure key vault secrets clientstore passwords securely azuremanage api keys azureazure secret management pythonkey vault credential storageazure sdk secretsvault secret retrieval
Topics
azure-sdksecrets-managementcloud-credentials
PyPI keywords
azureazure sdk

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “azure key vault secrets client”

  • azure-keyvault-secretsSecurely store, retrieve, and manage secrets (passwords, tokens, API…
  • azure-keyvaultA bundle package that installs three Azure Key Vault client libraries…
  • azure-mgmt-keyvaultManages Azure Key Vault resources—vaults, keys, secrets, and managed…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also azure-keyvault · azure-keyvault-certificates · azure-keyvault-keys · conjur-client · skyflow · pydantic-settings-azure-app-configuration · keeper-secrets-manager-core · azure-keyvault-administration · azure-appconfiguration-provider · azure-keyvault-securitydomain