$npx skillfedfor your agent

biscuit-python

Python bindings for the biscuit auth platform

With conditionsPyPI CryptographyReleased Sep 202577.6K downloads / moPlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — biscuit_python-0.4.0-cp310-cp310-manylinux_2_17_aarch64.manylinux2014_aarch64.whl · biscuit_python-0.4.0-cp310-cp310-manylinux_2_17_armv7l.manylinux2014_armv7l.whl · biscuit_python-0.4.0-cp310-cp310-manylinux_2_17_ppc64le.manylinux2014_ppc64le.whl
v0.4.0 · released 2025-09-26

Yes, if you need biscuit-based authorization in Python and accept pre-1.0 API volatility. The package is actively maintained, has no runtime dependencies, covers all documented core use cases, and carries no known security vulnerabilities. The main caveats are medium install friction (compiled wheels) and unclear license metadata that should be verified against your project's requirements.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires pre-built wheels for your platform and Python version; source installation requires maturin and Rust toolchain.
  • Medium install friction due to compiled wheels required for multiple architectures and Python versions.
  • The package is actively maintained with recent releases, though it remains pre-1.0 and may see API changes.

License · maintenance · safety

(unclear) — License treatment is unclear in the metadata; the description indicates Apache License 2.0 applies, but this is not formally declared in the package metadata and should be verified before use in proprietary or restricted contexts.

last release 2025-09-26 (322 days) · last repo commit 2026-07-14 · 17 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 77,570 downloads/mo, #14,514 on PyPI

Verify before relying

pip install biscuit-python

import biscuit_python

# Build, append blocks, parse, and authorize tokens
  • Exact Python version support range (requires_python is unspecified in metadata)
  • Whether the Apache 2.0 license declared in description is formally recognized by package metadata
  • API stability guarantees or deprecation timeline for pre-1.0 releases
  • Specific module names and API surface available after import
Same gist for agents: .md · .json

What it is and what it does

biscuit-python is a Python wrapper around the Rust biscuit authentication library, providing cryptographic token operations for authorization workflows. It allows you to build tokens, append authorization blocks (both first-party and third-party), parse existing tokens, and validate them against authorization rules. The package has no runtime dependencies beyond the compiled extension itself.

The library is actively maintained and covers the core use cases for token-based authorization: creating tokens with embedded authorization logic, delegating authority through third-party blocks, and enforcing access control policies. As a pre-1.0 project, it is production-ready for its documented features but may introduce breaking API changes in future releases.

Use it for

  • Build and validate authorization tokens for microservice-to-microservice communication with embedded access policies.
  • Implement delegated authorization workflows where third parties can append their own authorization blocks to tokens.
  • Parse and verify cryptographic tokens in API gateways or middleware to enforce fine-grained access control.
  • Integrate biscuit-based authorization into Python web frameworks or authentication systems.
  • Validate token authorization rules against dynamic authorization policies.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need biscuit-based authorization in Python and accept pre-1.0 API volatility.

The package is actively maintained, has no runtime dependencies, covers all documented core use cases, and carries no known security vulnerabilities. The main caveats are medium install friction (compiled wheels) and unclear license metadata that should be verified against your project's requirements.

Install

biscuit-python on PyPI

Before you install

Medium install friction due to compiled wheels required for multiple architectures and Python versions. The package is actively maintained with recent releases, though it remains pre-1.0 and may see API changes.

Requires pre-built wheels for your platform and Python version; source installation requires maturin and Rust toolchain.

License in practice

License treatment is unclear in the metadata; the description indicates Apache License 2.0 applies, but this is not formally declared in the package metadata and should be verified before use in proprietary or restricted contexts.

Quickstart

pip install biscuit-python

import biscuit_python

# Build, append blocks, parse, and authorize tokens

Verify before relying

  • Exact Python version support range (requires_python is unspecified in metadata)
  • Whether the Apache 2.0 license declared in description is formally recognized by package metadata
  • API stability guarantees or deprecation timeline for pre-1.0 releases
  • Specific module names and API surface available after import

Package facts

LicenseNot declared unclear
Python supportNot specified
Install frictionMedium. Platform-specific wheel
Runtime dependenciesNone
MaintenanceActively maintained 322 days since the last release
Last repo commit
First released
Downloads77,570 / month, #14,514 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: biscuit_python-0.4.0-cp310-cp310-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; biscuit_python-0.4.0-cp310-cp310-manylinux_2_17_armv7l.manylinux2014_armv7l.whl; biscuit_python-0.4.0-cp310-cp310-manylinux_2_17_ppc64le.manylinux2014_ppc64le.whl; biscuit_python-0.4.0-cp310-cp310-manylinux_2_17_s390x.manylinux2014_s390x.whl; biscuit_python-0.4.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; biscuit_python-0.4.0-cp310-cp310-manylinux_2_5_i686.manylinux1_i686.whl; biscuit_python-0.4.0-cp310-cp310-musllinux_1_2_aarch64.whl; biscuit_python-0.4.0-cp310-cp310-musllinux_1_2_armv7l.whl; biscuit_python-0.4.0-cp310-cp310-musllinux_1_2_i686.whl; biscuit_python-0.4.0-cp310-cp310-musllinux_1_2_x86_64.whl; biscuit_python-0.4.0-cp310-cp310-win_amd64.whl; biscuit_python-0.4.0-cp311-cp311-macosx_10_12_x86_64.whl; biscuit_python-0.4.0-cp311-cp311-macosx_11_0_arm64.whl; biscuit_python-0.4.0-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; biscuit_python-0.4.0-cp311-cp311-manylinux_2_17_armv7l.manylinux2014_armv7l.whl; biscuit_python-0.4.0-cp311-cp311-manylinux_2_17_ppc64le.manylinux2014_ppc64le.whl; biscuit_python-0.4.0-cp311-cp311-manylinux_2_17_s390x.manylinux2014_s390x.whl; biscuit_python-0.4.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; biscuit_python-0.4.0-cp311-cp311-manylinux_2_5_i686.manylinux1_i686.whl; biscuit_python-0.4.0-cp311-cp311-musllinux_1_2_aarch64.whl

Tags

Capabilities
biscuit token authentication pythonauthorization token librarycryptographic token managementthird-party block authorizationtoken parsing and validationbiscuit auth bindingsaccess control tokens
Topics
authenticationauthorizationcryptography

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “biscuit token authentication python”

  • biscuit-pythonPython bindings for the biscuit authentication library, enabling…
  • coze-workload-identityImplements OAuth2.0 token exchange authentication for Coze workload…
  • requests-authAdds OAuth2, API key, Basic, and NTLM authentication support to the…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also chia-rs · databento-dbn · cedarpy · delta-kernel-rust-sharing-wrapper · py-ed25519-zebra-bindings · py-bip39-bindings · py-sr25519-bindings · pycasbin · eclipse-zenoh