$npx skillfedfor your agent

ff3

Format Preserving Encryption (FPE) with FF3

SkipPyPI CryptographyReleased Jan 2026217.4K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — ff3-1.0.3-py3-none-any.whl
v1.0.3 · released 2026-01-26 · Python >=3.10 · 1 runtime deps: pycryptodome

No—not for new production systems. NIST formally withdrew FF3 from its standard in February 2025 due to published vulnerabilities. The package itself carries no warranty and is explicitly labeled for educational and experimental use only. If you have an existing FF3 deployment, this implementation passes official test vectors, but for new projects requiring format-preserving encryption, you should evaluate alternatives or wait for NIST's approved successor. Use only if you fully understand the cryptographic risks and your threat model accepts them.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Key must be 128, 192, or 256 bits; tweak must be 7 bytes (FF3-1) or 8 bytes (FF3).
  • Plaintext length is limited by radix: radix 10 allows max 56 characters, radix 36 allows max 36 characters.

License · maintenance · safety

permissive license (permissive) — Apache 2.0 permissive license allows commercial and private use without restriction, though you must retain license notices in distributions.

last release 2026-01-26 (200 days) · last repo commit 2026-01-26 · 104 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 217,379 downloads/mo, #9,359 on PyPI

Verify before relying

pip install ff3

from ff3 import FF3Cipher

key = "2DE79D232DF5585D68CE47882AE256D6"
tweak = "CBD09280979564"
c = FF3Cipher(key, tweak)
ciphertext = c.encrypt("3992520240")
decrypted = c.decrypt(ciphertext)
  • Whether this package has undergone independent security review or formal cryptographic validation beyond NIST test vectors.
  • Current status and adoption of FF3-1 in production systems, given NIST's February 2025 withdrawal of FF3 from the standard.
  • Real-world performance on modern hardware (benchmark in description is from MacBook Air with 1.1 GHz i5, not current).
Same gist for agents: .md · .json

What it is and what it does

FF3 is a Python implementation of the NIST FF3 and FF3-1 format-preserving encryption algorithms. It encrypts data using a Feistel cipher while keeping the output in the same format as the input—numbers stay numbers, custom alphabets stay within their alphabet. This makes it useful for encrypting sensitive data like credit card numbers or identification codes while maintaining their original structure for systems that expect a specific format.

The package depends only on pycryptodome for AES encryption and supports radix values from 2 to 256, allowing encryption of digits, alphanumeric strings, or custom character sets. It includes command-line tools (ff3_encrypt, ff3_decrypt) and passes official NIST test vectors. However, the description explicitly notes that NIST withdrew FF3 from its standard in February 2025 due to published vulnerabilities, and the package carries no warranty. It is intended for developers and researchers familiar with cryptographic standards.

Use it for

  • Encrypt credit card numbers or bank account identifiers while preserving their numeric format for legacy systems that validate digit-only strings.
  • Tokenize personally identifiable information (PII) like social security numbers or driver license numbers in a reversible, format-preserving way.
  • Encrypt custom identifiers (e.g., order IDs, patient records) using a custom alphabet while maintaining the original character set.
  • Educational and research exploration of format-preserving encryption and Feistel cipher design.
  • Reversible data obfuscation for testing or development environments where you need to mask real data but recover it later.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No—not for new production systems.

NIST formally withdrew FF3 from its standard in February 2025 due to published vulnerabilities. The package itself carries no warranty and is explicitly labeled for educational and experimental use only. If you have an existing FF3 deployment, this implementation passes official test vectors, but for new projects requiring format-preserving encryption, you should evaluate alternatives or wait for NIST's approved successor. Use only if you fully understand the cryptographic risks and your threat model accepts them.

Install

ff3 on PyPI

Before you install

Low friction: pure Python wheel with a single dependency (pycryptodome). Last release was 200 days ago; repository is active but maintenance is aging. Suitable for projects that can tolerate infrequent updates.

Requires Python 3.10 or later. Key must be 128, 192, or 256 bits; tweak must be 7 bytes (FF3-1) or 8 bytes (FF3). Plaintext length is limited by radix: radix 10 allows max 56 characters, radix 36 allows max 36 characters.

License in practice

Apache 2.0 permissive license allows commercial and private use without restriction, though you must retain license notices in distributions.

Quickstart

pip install ff3

from ff3 import FF3Cipher

key = "2DE79D232DF5585D68CE47882AE256D6"
tweak = "CBD09280979564"
c = FF3Cipher(key, tweak)
ciphertext = c.encrypt("3992520240")
decrypted = c.decrypt(ciphertext)

Verify before relying

  • Whether this package has undergone independent security review or formal cryptographic validation beyond NIST test vectors.
  • Current status and adoption of FF3-1 in production systems, given NIST's February 2025 withdrawal of FF3 from the standard.
  • Real-world performance on modern hardware (benchmark in description is from MacBook Air with 1.1 GHz i5, not current).

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
pycryptodome
MaintenanceAging 200 days since the last release
Last repo commit
First released
Downloads217,379 / month, #9,359 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: Financial and Insurance IndustryIntended Audience :: Healthcare IndustryLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Security :: Cryptography

Evidence: ff3-1.0.3-py3-none-any.whl

Tags

Capabilities
format preserving encryptionFPE cipherdata tokenization encryptionreversible data encryptionNIST FF3 implementationfeistel cipher pythonencrypt preserve format
Topics
format-preserving-encryptionwithdrawn-standardfeistel-cipher

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “FPE cipher”

  • ff3Implements NIST FF3 and FF3-1 format-preserving encryption (FPE)…
  • chacha20poly1305-reuseableProvides a reusable ChaCha20Poly1305 AEAD cipher implementation…
  • twofishProvides Python bindings to the Twofish block cipher for encrypting…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also noiseprotocol · pyffx · py3rijndael · pyDes · cpe · aes-pkcs5 · cryptg · miscreant · pqcrypto · sigfig