Packages
Provides Python bindings to C-KZG-4844, a cryptographic library implementing polynomial commitments for Ethereum's EIP-4844 and EIP-7594 specifications.
Validates X.509 certificate paths with support for revocation checks (CRL and OCSP), point-in-time validation, and policy constraints.
Provides a unified API for Ethereum key operations including private key generation, public key derivation, message signing, and signature verification using elliptic curve cryptography.
Loads, creates, and decrypts Ethereum keyfiles—encrypted JSON files that store private keys using PBKDF2 or Scrypt key derivation with AES-128-CTR encryption.
However, the aging maintenance status (550 days since last release) and Pre-Alpha classifier for v4 suggest you should verify v4 stability for your use case before…
Manages role-based access control, backup, restore, and settings for Azure Key Vault Managed HSM instances.
Install it if you need to programmatically manage access control, backups, or settings on an Azure Key Vault Managed HSM; do not use it for standard Key Vault…
Manages security domains for Azure Key Vault Managed HSM—download, upload, and transfer security domain artifacts for HSM activation and disaster recovery.
Encodes and decodes data using Base58 and Base58Check formats compatible with Bitcoin and other networks, with support for custom alphabets like XRP.
However, do not use it if you require active security monitoring or bug fixes—the abandoned status means issues will not be addressed.
Pulumi resource provider for creating and managing TLS keys and certificates within infrastructure-as-code programs.
Install only if you have Pulumi CLI already set up and a Pulumi project initialized.
Provides alternate keyring backend implementations for the keyring package, including plaintext and other non-standard credential storage methods.
Install only if you have a specific need for an alternate backend and accept responsibility for the security implications.
Encrypts and decrypts data using AWS KMS keys and keyrings, implementing the AWS Encryption SDK specification for Python.
Install it if you need to encrypt/decrypt data with AWS KMS in Python.
Implements encrypted content encoding for HTTP messages, allowing you to encrypt and decrypt HTTP request/response bodies using the standard HTTP Content-Encoding mechanism.
Pure-Python implementation of AES encryption with support for all key sizes and common modes of operation (CBC, CFB, CTR, ECB, OFB), plus stream and block-level APIs for encrypting and decrypting data.
coincurve provides Python bindings to libsecp256k1, enabling fast elliptic curve cryptography operations on the secp256k1 curve used by Bitcoin and Ethereum.
Install it if you need secp256k1 operations; the medium install friction is justified by the performance and correctness guarantees of the underlying C library.
Automatically configures Python to use the operating system's certificate store for SSL/TLS verification instead of bundled certificates, working transparently with pip, requests, urllib3, and other standard Python libraries.
Generates PKCE (Proof Key for Code Exchange) code verifiers and challenges for OAuth authorization flows, implementing RFC 7636.
Provides a modern, easy-to-use wrapper for hashing and verifying passwords using secure algorithms, designed as a contemporary alternative to older password hashing libraries.
Install it if you want a simple, secure alternative; skip it only if you need legacy algorithm support or broader feature coverage.
Implements FIDO2 and WebAuthn protocols for communicating with USB authenticators and verifying cryptographic signatures for passwordless authentication.
Implements RFC 8785 (JSON Canonicalization Scheme) to produce deterministic, byte-for-byte identical JSON serialization regardless of input order or representation.
Install it if you need deterministic JSON serialization for cryptography, signatures, or any use case where byte-for-byte reproducibility matters.
Provides PEP 561 type stubs for the cryptography package, enabling static type checkers to validate code using cryptography.
A Python wrapper around GnuPG that lets you generate keys, encrypt, and decrypt messages programmatically, with patches for shell injection vulnerabilities.
However, it is dormant—last release was 2017-09-06—so it may not support modern Python versions or recent GnuPG features.
pylibsrtp encrypts and decrypts Secure Real-time Transport Protocol (SRTP) packets, providing confidentiality, message authentication, and replay protection for RTP streams.
ocspbuilder creates and signs OCSP requests and responses for X.509 certificates, enabling certificate status validation in PKI systems.
Encodes and decodes Base64 data without RFC 4648 padding characters, supporting protocols that omit the trailing "=" bytes.
However, for new projects, consider whether the standard library base64 module with manual padding removal would suffice, since this package will not receive updates.
diceware generates memorable passphrases by randomly selecting words from wordlists and concatenating them, following the diceware method for creating cryptographically sound passwords.
Install it if you need memorable, high-entropy passphrases for personal accounts or system administration; review the license if you plan to integrate it into…
Canonicalizes JSON according to RFC 8785, producing a deterministic byte representation suitable for hashing and digital signatures.
However, verify that the algorithm meets your security requirements and test thoroughly, since there will be no upstream fixes for any future issues you discover.
Provides automatic credential retrieval for Azure Artifacts feeds, integrating with keyring to enable pip and twine to authenticate with Azure DevOps package repositories.
Provides misuse-resistant authenticated encryption using AES-SIV, AES-PMAC-SIV, and STREAM constructions for encrypting messages, keys, and file streams.
Constructs and serializes EIP-712 structured data for Ethereum signing, mapping Solidity-like types to Python objects with domain separation and message encoding.
Generates and cryptographically signs orders for Polymarket's CLOB (Central Limit Order Book) exchange, producing JSON-formatted order and signature data ready for API submission.
However, dormant maintenance (last update 2024-07-29) means you should verify compatibility with the current Polymarket API and Ethereum tooling before committing to…
Implements elliptic curve cryptography operations for secp256k1, alt_bn128, and bls12_381 curves in pure Python.
However, the explicit lack of audit and experimental status mean it should not be used for applications handling real cryptographic secrets or financial transactions…
Retrieves, decodes, and verifies Vercel OIDC tokens for Python applications, with support for both synchronous and asynchronous token lookup and optional JWT signature verification.
trustme generates fake TLS certificates and certificate authorities for testing network code without needing real certificates or disabling certificate validation in tests.
Install it if you test any code that makes HTTPS connections.
Sigstore is a Python tool for generating and verifying keyless signatures on files and Python package distributions using OpenID Connect identities and Sigstore's transparency log infrastructure.
Install it if supply chain security and keyless identity-based signing align with your workflow; skip it if you prefer traditional key-based signing or have no need…
Provides command-line tools to encrypt and decrypt files using GPG with AES256 cipher, supporting single files, directories, and optional tar archiving before encryption.
However, verify Python and GPG compatibility first, since the package has not been actively maintained since 2015 and may have undiscovered issues with modern…
PyMacaroons implements macaroons—bearer credentials with embedded authorization caveats that can be created, serialized, and cryptographically verified.
However, if you require active development, recent Python version support beyond 3.9, or performance-critical use, consider whether libmacaroons bindings or an…
Provides Fernet symmetric encryption for Django model fields, allowing you to encrypt sensitive data at the database level using the cryptography library.
Install only if your Django and Python versions are locked to those it was tested on, or if you are willing to fork and maintain it yourself.
Implements RFC 3161 Time-Stamp Protocol to build timestamp requests and verify timestamp responses using cryptographic certificates.
Provides Python data models for Rekor's API types, enabling type-safe interaction with Rekor's data structures through pydantic-based validation.
Generates mnemonic word sequences and converts them to cryptographic seeds following the Bitcoin standard for deterministic wallet creation.
However, dormant maintenance (no updates in 952 days) means no active support for bugs or security issues—acceptable for a narrow, mature specification but worth…
Macaroonbakery provides HTTP authentication and cookie handling for macaroon-based access control, integrating with the requests library to manage macaroon cookies across protected API calls.