credstash
A utility for managing secrets in the cloud using AWS KMS and DynamoDB
Decision gist · record as of 2026-08-14
No—the project is abandoned (last release April 2020, last commit February 2022) and likely incompatible with current AWS SDK and Python versions. For new projects, use AWS Secrets Manager or Parameter Store instead. Only consider it for legacy systems already running CredStash that cannot be migrated.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- AWS credentials must be configured (environment variables, ~/.aws/credentials, or IAM role); a KMS key named 'credstash' and a DynamoDB table must exist; on Linux, build tools and libssl-dev/libffi-dev headers required before pip install.
- Low install friction on macOS and Windows; Linux requires build tools and development headers for the cryptography dependency (libssl-dev, libffi-dev, build-essential on Debian/Ubuntu; gcc, libffi-devel, openssl-devel on Fedora/RHEL).
- Project is abandoned as of 2022, with no releases since April 2020.
License · maintenance · safety
Apache2 (permissive) — Licensed under Apache 2.0 (permissive), allowing commercial use, modification, and distribution with minimal restrictions—suitable for most organizational contexts.
last release 2020-04-11 (2316 days) · last repo commit 2022-02-09 · 2,063 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 490,159 downloads/mo, #6,371 on PyPI
Alternatives
Verify before relying
pip install credstash
import credstash
# Requires AWS credentials and KMS key setup
secret = credstash.getSecret(name='myapp.db.prod')- Current compatibility with modern versions of boto3 and cryptography, given the project's abandonment in 2022.
- Whether the package works with current AWS API versions and DynamoDB behavior.
- Support status for Python versions beyond those tested during active maintenance.
What it is and what it does
CredStash is a credential management tool that integrates AWS KMS (for key encryption) and DynamoDB (for credential storage) to securely store, version, and distribute secrets across your infrastructure. It wraps each secret with a unique data encryption key encrypted by your KMS master key, then stores both the encrypted secret and wrapped key in DynamoDB. When you retrieve a secret, CredStash fetches the encrypted credential and key from DynamoDB, decrypts the key via KMS, and uses it to decrypt the secret.
The tool is designed for teams that want a lightweight, AWS-native alternative to dedicated secret-management systems. It supports versioning (so you can rotate credentials by creating new versions), encryption context (for audit trails and fine-grained access control via KMS policies), and simple CLI operations (put, get, list). However, the project has been abandoned since 2022 with no active maintenance, so it may not be compatible with current AWS SDK versions or modern Python environments without manual updates.
Use it for
- Store database passwords and API keys in DynamoDB, encrypted by KMS, for retrieval during application bootstrap.
- Rotate credentials by creating new versions of a secret and updating client code to fetch the latest version.
- Audit credential access by associating encryption context with secrets and reviewing KMS CloudTrail logs.
- Distribute secrets to multiple servers or containers by having them fetch from the same DynamoDB table using shared KMS permissions.
- Manage TLS/SSL certificates and private keys with fine-grained access control via KMS Key Policy conditions.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No—the project is abandoned (last release April 2020, last commit February 2022) and likely incompatible with current AWS SDK and Python versions.
For new projects, use AWS Secrets Manager or Parameter Store instead. Only consider it for legacy systems already running CredStash that cannot be migrated.
Install
credstash on PyPI
Before you install
Low install friction on macOS and Windows; Linux requires build tools and development headers for the cryptography dependency (libssl-dev, libffi-dev, build-essential on Debian/Ubuntu; gcc, libffi-devel, openssl-devel on Fedora/RHEL). Project is abandoned as of 2022, with no releases since April 2020.
AWS credentials must be configured (environment variables, ~/.aws/credentials, or IAM role); a KMS key named 'credstash' and a DynamoDB table must exist; on Linux, build tools and libssl-dev/libffi-dev headers required before pip install.
License in practice
Licensed under Apache 2.0 (permissive), allowing commercial use, modification, and distribution with minimal restrictions—suitable for most organizational contexts.
Quickstart
pip install credstash
import credstash
# Requires AWS credentials and KMS key setup
secret = credstash.getSecret(name='myapp.db.prod')
Verify before relying
- Current compatibility with modern versions of boto3 and cryptography, given the project's abandonment in 2022.
- Whether the package works with current AWS API versions and DynamoDB behavior.
- Support status for Python versions beyond those tested during active maintenance.
Package facts
| License | Apache2 permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagescryptographyboto3 |
| Maintenance | Abandoned 2,316 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 490,159 / month, #6,371 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Intended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software License |
Evidence: credstash-1.17.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “AWS secret management”
- credstashCredStash stores and retrieves secrets using AWS KMS for encryption…
- aws-cdk.aws-secretsmanagerAWS CDK construct library for provisioning and managing AWS Secrets…
- cerberus-python-clientA Python client library for reading and writing secrets to Cerberus,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also aws-cdk.aws-secretsmanager · docker-pycreds · aws-encryption-sdk-cli · dynamodb-encryption-sdk · aws-encryption-sdk · aws-cdk.aws-kms · infisicalsdk · infisical-python · aws-secretsmanager-caching · ssm-parameter-store