google-cloud-kms
Google Cloud Kms API client library
Decision gist · record as of 2026-08-14
Yes. This is the official, actively maintained client for Google Cloud KMS with low install friction, permissive licensing, no known vulnerabilities, and broad Python version support. Install it if your application needs to use Google Cloud's managed key service for encryption, key management, or compliance-driven key lifecycle operations. Requires GCP project setup and credentials configuration upfront.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Google Cloud authentication setup (service account credentials or Application Default Credentials) and an active GCP project with Cloud KMS enabled.
- Low install friction with a pure-Python wheel distribution.
- Actively maintained as of 29 days ago with recent commits.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing use in commercial and proprietary projects with minimal restrictions beyond attribution and liability disclaimers.
last release 2026-07-16 (29 days) · last repo commit 2026-08-14 · 5,371 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 150,610,135 downloads/mo, #267 on PyPI
Alternatives
Verify before relying
pip install google-cloud-kms
from google.cloud import kms_v1
client = kms_v1.KeyManagementServiceClient()
# Use client to call KMS methods (e.g., encrypt, decrypt, create_key)- Specific KMS operations supported (encrypt, decrypt, key rotation, etc.) beyond the general API client wrapper.
- Whether the library handles automatic credential discovery or requires explicit credential configuration.
- Performance characteristics and rate-limiting behavior for high-volume cryptographic operations.
What it is and what it does
google-cloud-kms is the official Python client library for Google Cloud Key Management Service, a managed cryptographic key service hosted on Google Cloud Platform. It wraps the KMS API to allow Python applications to create, manage, and use encryption keys without storing key material locally. The library handles authentication via Google Cloud credentials, serialization of requests and responses using Protocol Buffers, and gRPC communication with Google's KMS backend.
Typical usage involves instantiating a KeyManagementServiceClient, then calling methods to perform cryptographic operations (encryption, decryption, key creation, rotation) or manage key policies and permissions. The library is built on google-api-core and google-auth, inheriting their patterns for credential handling and API interaction. It supports current Python versions (3.10 through 3.14) and is actively maintained by Google as part of the broader google-cloud-python ecosystem.
Use it for
- Encrypt sensitive data at rest in applications running on or off Google Cloud Platform using centrally managed keys.
- Implement key rotation policies and audit trails for cryptographic key usage across multiple services.
- Secure credential storage by encrypting API keys, database passwords, and secrets with KMS-managed keys.
- Build compliance-ready applications that require hardware-backed key storage and centralized key lifecycle management.
- Integrate with Google Cloud services that natively support KMS (e.g., Cloud Storage, Cloud SQL) for transparent encryption.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is the official, actively maintained client for Google Cloud KMS with low install friction, permissive licensing, no known vulnerabilities, and broad Python version support. Install it if your application needs to use Google Cloud's managed key service for encryption, key management, or compliance-driven key lifecycle operations. Requires GCP project setup and credentials configuration upfront.
Install
google-cloud-kms on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Actively maintained as of 29 days ago with recent commits. Requires Python 3.10 or later and depends on standard Google Cloud libraries (google-api-core, google-auth, grpcio, proto-plus, protobuf, grpc-google-iam-v1).
Requires Google Cloud authentication setup (service account credentials or Application Default Credentials) and an active GCP project with Cloud KMS enabled.
License in practice
Licensed under Apache-2.0 (permissive), allowing use in commercial and proprietary projects with minimal restrictions beyond attribution and liability disclaimers.
Quickstart
pip install google-cloud-kms
from google.cloud import kms_v1
client = kms_v1.KeyManagementServiceClient()
# Use client to call KMS methods (e.g., encrypt, decrypt, create_key)
Verify before relying
- Specific KMS operations supported (encrypt, decrypt, key rotation, etc.) beyond the general API client wrapper.
- Whether the library handles automatic credential discovery or requires explicit credential configuration.
- Performance characteristics and rate-limiting behavior for high-volume cryptographic operations.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 6 packagesgoogle-api-coregoogle-authgrpcioproto-plusprotobufgrpc-google-iam-v1 |
| Maintenance | Actively maintained 29 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 150,610,135 / month, #267 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Internet |
Evidence: google_cloud_kms-3.16.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “google cloud kms python client”
- google-cloud-kmsProvides a Python client library for Google Cloud Key Management…
- alibabacloud-kms20160120Provides a Python client library for Alibaba Cloud's Key Management…
- aliyun-python-sdk-kmsProvides Python bindings to Aliyun's Key Management Service (KMS) for…
Give your agent the search over MCP, or paste the wish link into any chat.
More Internet packages
Botocore provides low-level, data-driven access to Amazon Web Services APIs, serving as the foundation for the AWS CLI and boto3 libraries.
Install it if you need programmatic access to AWS services.
Provides an async client for AWS services using botocore and aiohttp, allowing you to call AWS APIs asynchronously within asyncio-based applications.
Install it if you need to call AWS services from async Python code; it is the standard way to do so.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides a platform-independent file locking mechanism to coordinate access to files across processes and threads.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides common Protocol Buffer message definitions used across Google Cloud APIs, enabling Python clients to interact with Google services.
See also google-cloud-api-keys · tink · aliyun-python-sdk-kms · google-cloud-functions · PyKMIP · aws-cryptographic-material-providers · aws-encryption-sdk · google-cloud-monitoring · google-cloud-resource-manager · google-cloud-filestore