$npx skillfedfor your agent

dilithium-py

A pure python implementation of ML-DSA (FIPS 204)

With conditionsPyPI CryptographyReleased Dec 2025156.5K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — dilithium_py-1.4.0-py3-none-any.whl
v1.4.0 · released 2025-12-17 · Python >=3.9

Yes, if your goal is learning or experimentation with post-quantum cryptography. The implementation is actively maintained, has no runtime dependencies, and passes all official test vectors. However, do not install for production cryptographic use—the package explicitly warns against this and is not designed to resist side-channel attacks. For production ML-DSA, use a hardened C or Rust implementation.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later.
  • Not suitable for production cryptographic applications—use only for learning and experimentation.
  • Low install friction with no runtime dependencies.

License · maintenance · safety

MIT (permissive) — MIT license (permissive). You may use, modify, and distribute freely with minimal restrictions.

last release 2025-12-17 (240 days) · last repo commit 2026-06-09 · 128 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 156,519 downloads/mo, #10,781 on PyPI

Verify before relying

pip install dilithium-py

from dilithium_py.ml_dsa import ML_DSA_44

pk, sk = ML_DSA_44.keygen()
msg = b"Your message"
sig = ML_DSA_44.sign(sk, msg)
assert ML_DSA_44.verify(pk, msg, sig)
  • Whether pycryptodome is an optional or required runtime dependency for deterministic CSRNG use
  • Whether xoflib is required or optional for production-grade performance
  • Actual performance characteristics in real-world scenarios beyond the benchmarks shown
Same gist for agents: .md · .json

What it is and what it does

This package provides a pure-Python implementation of ML-DSA (the NIST standardized version of Dilithium from FIPS 204) and the original CRYSTALS-Dilithium specification. It exposes three core functions: keygen() to generate keypairs, sign() to create signatures, and verify() to validate them. The implementation passes all known test vectors (KATs) for both ML-DSA and Dilithium v3.1.

The package is explicitly designed for educational purposes and learning about post-quantum lattice-based cryptography. The code is not constant-time and not optimized for performance; instead, it prioritizes readability and close correspondence with the published specifications. The disclaimer is unambiguous: do not use this for actual cryptographic applications. It includes optional support for the xoflib package for better performance with XOF operations, and uses pycryptodome for AES256 CTR DRBG if deterministic randomness is needed.

Use it for

  • Learning how ML-DSA and Dilithium work by reading well-commented, specification-aligned code
  • Experimenting with post-quantum signature schemes in a controlled, educational environment
  • Comparing the differences between the original Dilithium v3.1 and the standardized ML-DSA
  • Testing interoperability with ML-DSA implementations by validating against official KAT vectors
  • Prototyping quantum-resistant signature workflows before deploying production systems

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if your goal is learning or experimentation with post-quantum cryptography.

The implementation is actively maintained, has no runtime dependencies, and passes all official test vectors. However, do not install for production cryptographic use—the package explicitly warns against this and is not designed to resist side-channel attacks. For production ML-DSA, use a hardened C or Rust implementation.

Install

dilithium-py on PyPI

Before you install

Low install friction with no runtime dependencies. Active maintenance (last commit 2026-06-09) and recent releases. Suitable for learning and experimentation.

Requires Python 3.9 or later. Not suitable for production cryptographic applications—use only for learning and experimentation.

License in practice

MIT license (permissive). You may use, modify, and distribute freely with minimal restrictions.

Quickstart

pip install dilithium-py

from dilithium_py.ml_dsa import ML_DSA_44

pk, sk = ML_DSA_44.keygen()
msg = b"Your message"
sig = ML_DSA_44.sign(sk, msg)
assert ML_DSA_44.verify(pk, msg, sig)

Verify before relying

  • Whether pycryptodome is an optional or required runtime dependency for deterministic CSRNG use
  • Whether xoflib is required or optional for production-grade performance
  • Actual performance characteristics in real-world scenarios beyond the benchmarks shown

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 240 days since the last release
Last repo commit
First released
Downloads156,519 / month, #10,781 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Programming Language :: Python :: 3Topic :: Security :: Cryptography

Evidence: dilithium_py-1.4.0-py3-none-any.whl

Tags

Capabilities
post-quantum cryptographyML-DSA signaturedilithium implementationNIST FIPS 204lattice-based signaturesquantum-resistant signingeducational cryptography
Topics
post-quantumeducationallattice-crypto

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “post-quantum cryptography”

  • dilithium-pyA pure-Python implementation of ML-DSA (FIPS 204) and…
  • pqcryptoProvides Python bindings to post-quantum cryptographic algorithms…
  • liboqs-pythonPython 3 wrapper for the liboqs C library, providing post-quantum…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also SLH-DSA · pqcrypto · pysodium · pycryptodomex · pure25519 · ed25519-blake2b-fork · securesystemslib · josepy · endesive · liboqs-python