Packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
Keyring provides safe password and credential storage by interfacing with the system's native credential manager (macOS Keychain, Windows Credential Locker, Freedesktop Secret Service, or KDE KWallet).
Install it if your application needs to store or retrieve passwords securely without managing encryption yourself.
ItsDangerous cryptographically signs data to create tamper-proof tokens for safely passing information to untrusted environments and verifying it on return.
bcrypt provides modern password hashing using the bcrypt algorithm, with functions to hash passwords, verify them against stored hashes, and derive keys via bcrypt_pbkdf.
Install it if you need bcrypt specifically; if you're choosing a password hashing algorithm fresh, evaluate argon2id or scrypt as documented alternatives, but bcrypt…
A pure Python library for parsing and serializing ASN.1 structures, with built-in support for X.509 certificates, keys, CRLs, OCSP, and other cryptographic standards.
Provides secure, platform-specific token cache persistence for MSAL Python applications using OS-level encryption (DPAPI on Windows, Keychain on macOS, LibSecret on Linux).
However, note that the last release was 518 days ago (aging maintenance), so verify that the current version meets your msal compatibility requirements.
Paramiko is a pure-Python SSH protocol library providing both client and server functionality for low-level SSH operations and advanced use cases beyond what higher-level tools offer.
However, if your goal is simply running remote commands or transferring files, use Fabric instead—the maintainers explicitly recommend it for those common cases.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Truststore exposes native system certificate stores through an SSL context API, allowing Python applications to verify HTTPS certificates using the operating system's trust store instead of relying on a static certificate bundle.
PyCryptodomex provides low-level cryptographic primitives including symmetric ciphers, hash functions, public-key algorithms, and authenticated encryption modes.
Provides a simple Python interface to Argon2, a modern password hashing algorithm that won the Password Hashing Competition, for securely hashing and verifying passwords.
Install it if your application needs to hash or verify passwords.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
Scramp implements the SCRAM authentication protocol in Python, supporting SCRAM-SHA-1, SCRAM-SHA-256, SCRAM-SHA-512, and SCRAM-SHA3-512 variants with optional channel binding.
Install it if you need to authenticate against a SCRAM-capable service or build SCRAM authentication into your application.
Securely store, retrieve, and manage secrets (passwords, tokens, API keys, certificates) in Azure Key Vault from Python applications.
Install it if you are building on Azure and need to externalize secret management to Key Vault; it is the standard way to do so from Python.
Pure-Python implementation of ECDSA, EdDSA, and ECDH cryptographic algorithms with support for NIST curves, Brainpool curves, and Edwards curves for key generation, signing, verification, and shared secret derivation.
Passlib provides a framework for hashing and verifying passwords using different algorithms, supporting both legacy hash verification and modern password security for multi-user applications.
Generates OIDC identity tokens by automatically detecting the current environment (GitHub Actions, GitLab, Google Cloud, Buildkite, CircleCI) and retrieving ambient credentials without manual configuration.
Manages cryptographic keys in Azure Key Vault—create, store, retrieve, update, and delete RSA and elliptic curve keys, plus perform cryptographic operations on them.
Install it if you need to manage cryptographic keys in Azure Key Vault from Python.
Handles SPNEGO, NTLM, Kerberos, and CredSSP authentication protocols; includes a packet parser for decoding raw authentication tokens into human-readable format.
Install it if you need to authenticate against Windows domains or Kerberos realms.
oscrypto provides TLS sockets, key generation, encryption, decryption, signing, and verification using the operating system's native crypto libraries, with no compiler required.
However, the last release was 2022-03-18 and the repository shows no recent activity, so it is best suited for maintenance or legacy integration rather than new…
Python bindings for the BLAKE3 cryptographic hash function, exposing the official Rust implementation with support for keyed hashing, key derivation, extendable output, and multithreaded hashing.
Install it if you need modern hashing with keyed or key-derivation modes; the medium install friction is acceptable for most environments since binary wheels are…
Provides type stubs for pyOpenSSL to enable static type checking with mypy, pyright, pytype, and other type checkers.
AsyncSSH provides an asynchronous SSH client and server implementation for Python 3.10+, supporting SSHv2, SFTP, and SCP protocols with full key exchange, authentication, and channel management.
Install it if you need async SSH functionality in Python.
Verifies that cryptography or pyOpenSSL certificates are valid for a specific hostname or IP address, implementing RFC 6125 hostname verification and service identity inspection.
Install it if you're building TLS clients or servers with cryptography or pyOpenSSL and need robust hostname verification beyond basic SSL defaults.
Manages SSL/TLS certificates stored in Azure Key Vault—create, retrieve, update, delete, and control versions of certificates with support for certificate policies and issuers.
Install it if you need to manage certificates in Azure Key Vault; it is the standard choice for this task.
Decrypts and encrypts Microsoft Office files (Word, Excel, PowerPoint) protected with passwords or cryptographic keys, supporting both modern OOXML and legacy binary formats.
However, maintenance is aging (last release 214 days ago), and the encryption feature is experimental—use decryption for production workflows but treat encryption as…
A bundle package that installs three Azure Key Vault client libraries for managing cryptographic keys, secrets, and certificates in Azure Key Vault.
pyHanko is a Python library for adding, validating, and managing digital signatures in PDF documents, supporting standards like PAdES and PKCS#11.
Provides cryptographic hash functions (SHA256, RIPEMD160) and symmetric/asymmetric encryption algorithms (AES, DES, RSA, ElGamal) plus a cryptographically secure random number generator.
Pure Python ECDSA implementation supporting secp256k1 and prime256v1 curves for signing, verification, and key generation with OpenSSL compatibility.
PGPy implements OpenPGP (RFC 4880) in pure Python, enabling you to load, create, and verify RSA, DSA, and ECDSA signatures, and encrypt/decrypt messages using RSA and ECDH.
eth-account signs Ethereum transactions and messages using local private keys, enabling cryptographic operations for blockchain interactions without relying on external key management.
Implements server-side WebAuthn validation for passwordless authentication using FIDO2-compliant authenticators like security keys, biometrics, and platform authenticators.
Install it if you need to add WebAuthn support to a Python backend and are targeting Python 3.10+.
Provides the keccak256 hashing function used by Ethereum through a pluggable backend architecture.