fernet
A simple python fernet implementation
Decision gist · record as of 2026-08-14
No, not for new projects. The maintainer explicitly recommends using the cryptography library instead. This package is abandoned (last release 2016-09-18, last commit 2018-12-31), making it unsuitable for production cryptography work. Install only if you are maintaining legacy code that already depends on it, and consider migrating to cryptography as soon as feasible.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- The package is abandoned and unmaintained since 2016.
- For production use, the maintainer explicitly recommends using the cryptography library instead.
- High install friction due to source distribution only.
License · maintenance · safety
MIT (permissive) — MIT license is permissive and poses no restrictions on use, modification, or distribution.
last release 2016-09-18 (3617 days) · last repo commit 2018-12-31 · 16 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 240,878 downloads/mo, #8,894 on PyPI
Alternatives
Verify before relying
pip install fernet
from fernet import Fernet
key = Fernet.generate_key()
cipher = Fernet(key)
token = cipher.encrypt(b'secret message')
plaintext = cipher.decrypt(token)- Whether this implementation has been audited or validated against the Fernet specification since its last release in 2016-09-18.
- Whether any security issues have been discovered in the Fernet specification itself that would affect this implementation.
- Current compatibility with modern Python versions beyond 3.5, given the classifier only lists up to Python 3.5.
What it is and what it does
Fernet is a pure Python implementation of the Fernet symmetric encryption standard, designed for situations where you cannot or will not use compiled C-based cryptographic modules. It provides token-based authenticated encryption—meaning it both encrypts data and verifies its authenticity in a single operation.
The package is explicitly positioned as a fallback or reference implementation. The maintainer's own documentation states you should only use this module when you cannot use the cryptography library. The implementation has no runtime dependencies and installs from source only, which creates installation friction. More importantly, the project is abandoned: the last commit was 2018-12-31 and the latest release dates to 2016-09-18, with no active maintenance.
Use it for
- Educational reference: studying how Fernet encryption works or implementing the spec in another language.
- Constrained environments: systems where C extensions cannot be compiled and the cryptography library is unavailable.
- Legacy compatibility: maintaining existing code that already depends on this specific package.
- Pure-Python-only deployments: scenarios where compiled dependencies are explicitly forbidden by policy.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No, not for new projects.
The maintainer explicitly recommends using the cryptography library instead. This package is abandoned (last release 2016-09-18, last commit 2018-12-31), making it unsuitable for production cryptography work. Install only if you are maintaining legacy code that already depends on it, and consider migrating to cryptography as soon as feasible.
Install
fernet on PyPI
Before you install
High install friction due to source distribution only. More critically, the package is abandoned—last commit was 2018-12-31 and no releases since 2016-09-18. Maintenance status is a serious concern for a cryptographic library.
The package is abandoned and unmaintained since 2016. For production use, the maintainer explicitly recommends using the cryptography library instead.
License in practice
MIT license is permissive and poses no restrictions on use, modification, or distribution.
Quickstart
pip install fernet
from fernet import Fernet
key = Fernet.generate_key()
cipher = Fernet(key)
token = cipher.encrypt(b'secret message')
plaintext = cipher.decrypt(token)
Verify before relying
- Whether this implementation has been audited or validated against the Fernet specification since its last release in 2016-09-18.
- Whether any security issues have been discovered in the Fernet specification itself that would affect this implementation.
- Current compatibility with modern Python versions beyond 3.5, given the classifier only lists up to Python 3.5.
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Abandoned 3,617 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 240,878 / month, #8,894 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3.4Programming Language :: Python :: 3.5Topic :: Security :: Cryptography |
Evidence: fernet-1.0.1.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “fernet encryption python”
- fernetA pure Python implementation of the Fernet symmetric encryption…
- djfernetProvides Fernet symmetric encryption for Django model fields,…
- django-fernet-fields-v2Provides Fernet symmetric encryption for Django model fields,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also django-fernet-fields-v2 · django-fernet-encrypted-fields · djfernet · spake2 · django-cryptography · snitun · django-cryptography-django5 · py3rijndael · libnacl