$npx skillfedfor your agent

ecdsa

ECDSA cryptographic signature library (pure python)

With conditionsPyPI CryptographyReleased Mar 202660.6M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — ecdsa-0.19.2-py2.py3-none-any.whl
v0.19.2 · released 2026-03-26 · Python !=3.0.*,!=3.1.*,!=3.2.*,!=3.3.*,!=3.4.*,!=3.5.*,>=2.6 · 1 runtime deps: six

Yes, with conditions. Install if you need pure-Python elliptic curve cryptography for non-production use, testing, or educational purposes, or as a fallback when native cryptographic libraries are unavailable. Do not use in production systems without thorough security review—the package itself warns against this, and two known vulnerabilities are recorded. Verify that the specific curves and algorithms you need are supported and that the security limitations do not affect your use case.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • The package documentation explicitly states it should not be used in production settings; see the Security section of the project documentation for details.
  • Low friction: pure-Python wheel with only one runtime dependency (six).
  • Active maintenance with recent release and steady repository activity.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution in both open-source and proprietary projects with minimal obligations.

last release 2026-03-26 (141 days) · last repo commit 2026-06-08 · 974 stars

2 known vulnerabilities (OSV.dev, 2026-08-14) · 60,610,013 downloads/mo, #501 on PyPI

Verify before relying

pip install ecdsa

from ecdsa import SigningKey, NIST256p
sk = SigningKey.generate(curve=NIST256p)
vk = sk.get_verifying_key()
message = b'test'
signature = sk.sign(message)
assert vk.verify(signature, message)
  • What specific security issues or limitations make this unsuitable for production use, and whether they affect specific use cases or all applications.
  • Whether the two known vulnerabilities (GHSA-wj6h-64fc-37mp, PYSEC-2026-1325) have been patched in version 0.19.2 or remain open.
  • Performance characteristics when gmpy2 or gmpy are not installed versus the baseline pure-Python performance shown in the documentation.
Same gist for agents: .md · .json

What it is and what it does

ecdsa is a pure-Python cryptographic library implementing elliptic curve algorithms: ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm), and ECDH (Elliptic Curve Diffie-Hellman). It provides key pair generation, message signing, signature verification, and shared secret derivation across multiple standardized curves including NIST Suite B curves (192, 224, 256, 384, 521 bits), Brainpool curves (160–512 bits), Bitcoin's secp256k1, and Edwards curves (Ed25519, Ed448).

The library depends only on Python and the six package, making it portable across Python 2.6, 2.7, and 3.6+, including PyPy. It can optionally use gmpy2 or gmpy for faster arithmetic if installed. However, the package explicitly warns against production use; developers should consult the security documentation before deploying it in critical systems. The library is actively maintained and widely used (top 1000 on PyPI), but the presence of known vulnerabilities warrants careful evaluation.

Use it for

  • Generate and manage ECDSA key pairs for signing and verifying digital signatures in applications where pure-Python portability is required.
  • Implement ECDH key exchange protocols to establish shared secrets between parties using standardized elliptic curves.
  • Sign and verify messages using Ed25519 or Ed448 curves for applications needing Edwards-curve cryptography.
  • Integrate elliptic curve cryptography into educational or testing frameworks where native code dependencies are undesirable.
  • Work with Bitcoin-compatible secp256k1 signatures when a pure-Python implementation is acceptable.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

Install if you need pure-Python elliptic curve cryptography for non-production use, testing, or educational purposes, or as a fallback when native cryptographic libraries are unavailable. Do not use in production systems without thorough security review—the package itself warns against this, and two known vulnerabilities are recorded. Verify that the specific curves and algorithms you need are supported and that the security limitations do not affect your use case.

Install

ecdsa on PyPI

Before you install

Low friction: pure-Python wheel with only one runtime dependency (six). Active maintenance with recent release and steady repository activity.

The package documentation explicitly states it should not be used in production settings; see the Security section of the project documentation for details.

License in practice

MIT license permits unrestricted use, modification, and distribution in both open-source and proprietary projects with minimal obligations.

Quickstart

pip install ecdsa

from ecdsa import SigningKey, NIST256p
sk = SigningKey.generate(curve=NIST256p)
vk = sk.get_verifying_key()
message = b'test'
signature = sk.sign(message)
assert vk.verify(signature, message)

Verify before relying

  • What specific security issues or limitations make this unsuitable for production use, and whether they affect specific use cases or all applications.
  • Whether the two known vulnerabilities (GHSA-wj6h-64fc-37mp, PYSEC-2026-1325) have been patched in version 0.19.2 or remain open.
  • Performance characteristics when gmpy2 or gmpy are not installed versus the baseline pure-Python performance shown in the documentation.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release !=3.0.*,!=3.1.*,!=3.2.*,!=3.3.*,!=3.4.*,!=3.5.*,>=2.6
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
six
MaintenanceActively maintained 141 days since the last release
Last repo commit
First released
Downloads60,610,013 / month, #501 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilities2 GHSA-wj6h-64fc-37mp, PYSEC-2026-1325
Classifiers
Programming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: ecdsa-0.19.2-py2.py3-none-any.whl

Tags

Capabilities
elliptic curve cryptography pythonecdsa signing verificationpure python ecdh key exchangebitcoin secp256k1 curveed25519 ed448 signaturesnist curve implementationpython cryptographic signatures
Topics
cryptographypure-pythonecdsa-ecdh

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ed25519 ed448 signatures”

  • ecdsaPure-Python implementation of ECDSA, EdDSA, and ECDH cryptographic…
  • ECPyECPy is a pure Python elliptic curve library providing ECDSA, EdDSA…
  • ed25519-blake2b-forkProvides Python bindings to Ed25519 digital signatures using BLAKE2b…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also fastecdsa · starkbank-ecdsa · ECPy · lightdsa · coincurve · sslcrypto · lightecc · pure25519 · tlslite-ng · slip10