gssapi
Python GSSAPI Wrapper
Decision gist · record as of 2026-08-14
Yes, if you need Kerberos or GSSAPI authentication in Python and have a working GSSAPI implementation available on your system. The package is production-stable, actively maintained, and provides both low-level and high-level APIs. The main barrier is the system-level dependency on GSSAPI libraries and a C compiler; if those are already in place, installation is straightforward. Not suitable if you lack system GSSAPI support or cannot install a C compiler.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a working GSSAPI implementation (e.g., MIT Kerberos) with header files and a C compiler installed on the system.
- Medium install friction due to compiled C extension requiring a working GSSAPI implementation (such as MIT Kerberos) and a C compiler.
- The package is actively maintained with recent commits and provides pre-built wheels for common platforms and Python versions.
License · maintenance · safety
ISC (permissive) — ISC license is permissive and imposes minimal restrictions; you can use, modify, and distribute this package with few obligations.
last release 2026-01-26 (200 days) · last repo commit 2026-01-26 · 116 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,325,423 downloads/mo, #2,120 on PyPI
Alternatives
Verify before relying
pip install gssapi
from gssapi.raw import acquire_cred, init_context
from gssapi import Name
name = Name(b"user@REALM", name_type=None)
cred = acquire_cred(name=name)- Whether pre-built wheels cover all target deployment platforms or if source compilation is often needed in practice.
- Performance characteristics and thread-safety guarantees for the free-threading support (marked as beta in PEP 779).
- Real-world compatibility with non-Kerberos GSSAPI mechanisms beyond the documented RFC extensions.
What it is and what it does
Python-GSSAPI is a wrapper around the GSSAPI C libraries that enables Python applications to perform Kerberos authentication and related security operations. It exposes both a low-level C-style API that closely mirrors RFC 2744 and a high-level, Pythonic object-oriented API for easier integration. The package supports Kerberos as its primary mechanism but is designed to work with other GSSAPI mechanisms as well.
The library handles credential acquisition, context initialization, token exchange, and credential delegation. It includes support for multiple RFC extensions (GSS-API Negotiation, credential storage, SASL extensions, and Kerberos-specific features) and provides detailed error handling through typed exceptions. Installation requires a system GSSAPI implementation and C compiler, but pre-built wheels are available for common platforms and Python versions.
Use it for
- Implement Kerberos-based single sign-on (SSO) in web applications or services that need to authenticate against Active Directory or MIT Kerberos realms.
- Build client libraries that negotiate authentication using SPNEGO (GSS-API Negotiation Mechanism) for interoperability with Windows and Unix systems.
- Delegate user credentials to backend services while maintaining security boundaries in multi-tier applications.
- Integrate Kerberos authentication into Python-based system administration tools or monitoring agents that operate in enterprise environments.
- Implement mutual authentication and secure token exchange for inter-service communication in distributed systems.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need Kerberos or GSSAPI authentication in Python and have a working GSSAPI implementation available on your system.
The package is production-stable, actively maintained, and provides both low-level and high-level APIs. The main barrier is the system-level dependency on GSSAPI libraries and a C compiler; if those are already in place, installation is straightforward. Not suitable if you lack system GSSAPI support or cannot install a C compiler.
Install
gssapi on PyPI
Before you install
Medium install friction due to compiled C extension requiring a working GSSAPI implementation (such as MIT Kerberos) and a C compiler. The package is actively maintained with recent commits and provides pre-built wheels for common platforms and Python versions.
Requires a working GSSAPI implementation (e.g., MIT Kerberos) with header files and a C compiler installed on the system.
License in practice
ISC license is permissive and imposes minimal restrictions; you can use, modify, and distribute this package with few obligations.
Quickstart
pip install gssapi
from gssapi.raw import acquire_cred, init_context
from gssapi import Name
name = Name(b"user@REALM", name_type=None)
cred = acquire_cred(name=name)
Verify before relying
- Whether pre-built wheels cover all target deployment platforms or if source compilation is often needed in practice.
- Performance characteristics and thread-safety guarantees for the free-threading support (marked as beta in PEP 779).
- Real-world compatibility with non-Kerberos GSSAPI mechanisms beyond the documented RFC extensions.
Package facts
| License | ISC permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 1 packagedecorator |
| Maintenance | Aging 200 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 5,325,423 / month, #2,120 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: CythonProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Programming Language :: Python :: Free Threading :: 2 - BetaProgramming Language :: Python :: Implementation :: CPythonTopic :: SecurityTopic :: Software Development :: Libraries :: Python Modules |
Evidence: gssapi-1.11.1-cp310-cp310-macosx_10_9_x86_64.whl; gssapi-1.11.1-cp310-cp310-macosx_11_0_arm64.whl; gssapi-1.11.1-cp310-cp310-win32.whl; gssapi-1.11.1-cp310-cp310-win_amd64.whl; gssapi-1.11.1-cp311-abi3-macosx_10_9_x86_64.whl; gssapi-1.11.1-cp311-abi3-macosx_11_0_arm64.whl; gssapi-1.11.1-cp311-abi3-win32.whl; gssapi-1.11.1-cp311-abi3-win_amd64.whl; gssapi-1.11.1-cp314-cp314t-macosx_10_15_x86_64.whl; gssapi-1.11.1-cp314-cp314t-macosx_11_0_arm64.whl; gssapi-1.11.1-cp314-cp314t-win32.whl; gssapi-1.11.1-cp314-cp314t-win_amd64.whl; gssapi-1.11.1-cp39-cp39-macosx_10_9_x86_64.whl; gssapi-1.11.1-cp39-cp39-macosx_11_0_arm64.whl; gssapi-1.11.1-cp39-cp39-win32.whl; gssapi-1.11.1-cp39-cp39-win_amd64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “gssapi wrapper”
- gssapiPython-GSSAPI wraps the GSSAPI C libraries to provide both low-level…
- pykerberosProvides a Python wrapper for Kerberos (GSSAPI) authentication,…
- kerberosProvides a high-level Python wrapper for Kerberos (GSSAPI)…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also krb5 · sspilib · requests-gssapi · kerberos · pyspnego · pure-sasl · k5test · pykerberos · requests-credssp · requests-kerberos