$npx skillfedfor your agent

credstash

A utility for managing secrets in the cloud using AWS KMS and DynamoDB

SkipPyPI SecurityReleased Apr 2020490.2K downloads / moApache2Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — credstash-1.17.1-py3-none-any.whl
v1.17.1 · released 2020-04-11 · 2 runtime deps: cryptography, boto3

No—the project is abandoned (last release April 2020, last commit February 2022) and likely incompatible with current AWS SDK and Python versions. For new projects, use AWS Secrets Manager or Parameter Store instead. Only consider it for legacy systems already running CredStash that cannot be migrated.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • AWS credentials must be configured (environment variables, ~/.aws/credentials, or IAM role); a KMS key named 'credstash' and a DynamoDB table must exist; on Linux, build tools and libssl-dev/libffi-dev headers required before pip install.
  • Low install friction on macOS and Windows; Linux requires build tools and development headers for the cryptography dependency (libssl-dev, libffi-dev, build-essential on Debian/Ubuntu; gcc, libffi-devel, openssl-devel on Fedora/RHEL).
  • Project is abandoned as of 2022, with no releases since April 2020.

License · maintenance · safety

Apache2 (permissive) — Licensed under Apache 2.0 (permissive), allowing commercial use, modification, and distribution with minimal restrictions—suitable for most organizational contexts.

last release 2020-04-11 (2316 days) · last repo commit 2022-02-09 · 2,063 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 490,159 downloads/mo, #6,371 on PyPI

Verify before relying

pip install credstash

import credstash

# Requires AWS credentials and KMS key setup
secret = credstash.getSecret(name='myapp.db.prod')
  • Current compatibility with modern versions of boto3 and cryptography, given the project's abandonment in 2022.
  • Whether the package works with current AWS API versions and DynamoDB behavior.
  • Support status for Python versions beyond those tested during active maintenance.
Same gist for agents: .md · .json

What it is and what it does

CredStash is a credential management tool that integrates AWS KMS (for key encryption) and DynamoDB (for credential storage) to securely store, version, and distribute secrets across your infrastructure. It wraps each secret with a unique data encryption key encrypted by your KMS master key, then stores both the encrypted secret and wrapped key in DynamoDB. When you retrieve a secret, CredStash fetches the encrypted credential and key from DynamoDB, decrypts the key via KMS, and uses it to decrypt the secret.

The tool is designed for teams that want a lightweight, AWS-native alternative to dedicated secret-management systems. It supports versioning (so you can rotate credentials by creating new versions), encryption context (for audit trails and fine-grained access control via KMS policies), and simple CLI operations (put, get, list). However, the project has been abandoned since 2022 with no active maintenance, so it may not be compatible with current AWS SDK versions or modern Python environments without manual updates.

Use it for

  • Store database passwords and API keys in DynamoDB, encrypted by KMS, for retrieval during application bootstrap.
  • Rotate credentials by creating new versions of a secret and updating client code to fetch the latest version.
  • Audit credential access by associating encryption context with secrets and reviewing KMS CloudTrail logs.
  • Distribute secrets to multiple servers or containers by having them fetch from the same DynamoDB table using shared KMS permissions.
  • Manage TLS/SSL certificates and private keys with fine-grained access control via KMS Key Policy conditions.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No—the project is abandoned (last release April 2020, last commit February 2022) and likely incompatible with current AWS SDK and Python versions.

For new projects, use AWS Secrets Manager or Parameter Store instead. Only consider it for legacy systems already running CredStash that cannot be migrated.

Install

credstash on PyPI

Before you install

Low install friction on macOS and Windows; Linux requires build tools and development headers for the cryptography dependency (libssl-dev, libffi-dev, build-essential on Debian/Ubuntu; gcc, libffi-devel, openssl-devel on Fedora/RHEL). Project is abandoned as of 2022, with no releases since April 2020.

AWS credentials must be configured (environment variables, ~/.aws/credentials, or IAM role); a KMS key named 'credstash' and a DynamoDB table must exist; on Linux, build tools and libssl-dev/libffi-dev headers required before pip install.

License in practice

Licensed under Apache 2.0 (permissive), allowing commercial use, modification, and distribution with minimal restrictions—suitable for most organizational contexts.

Quickstart

pip install credstash

import credstash

# Requires AWS credentials and KMS key setup
secret = credstash.getSecret(name='myapp.db.prod')

Verify before relying

  • Current compatibility with modern versions of boto3 and cryptography, given the project's abandonment in 2022.
  • Whether the package works with current AWS API versions and DynamoDB behavior.
  • Support status for Python versions beyond those tested during active maintenance.

Package facts

LicenseApache2 permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
cryptographyboto3
MaintenanceAbandoned 2,316 days since the last release
Last repo commit
First released
Downloads490,159 / month, #6,371 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Intended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software License

Evidence: credstash-1.17.1-py3-none-any.whl

Tags

Capabilities
AWS secret managementKMS credential storageDynamoDB secretscredential rotationencrypted secret distributionAWS credential managementsecret versioning
Topics
aws-integrationsecret-managementabandoned

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “AWS secret management”

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also aws-cdk.aws-secretsmanager · docker-pycreds · aws-encryption-sdk-cli · dynamodb-encryption-sdk · aws-encryption-sdk · aws-cdk.aws-kms · infisicalsdk · infisical-python · aws-secretsmanager-caching · ssm-parameter-store