hvac
HashiCorp Vault API client
Decision gist · record as of 2026-08-14
Yes. hvac is the standard Python client for Vault, widely deployed in production (top 1000 PyPI), has no known vulnerabilities, and carries a permissive Apache-2.0 license. Install friction is minimal. The aging maintenance status (288 days since last release) is a minor concern but not a blocker if you are using a stable Vault version; verify that your Vault version is within the supported range (v1.4.7 or later).AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a running Vault server accessible at the specified URL and appropriate authentication credentials (token, role, or other auth method).
- Low install friction with a single runtime dependency (requests).
- Maintenance status is aging—the last release was 288 days ago—but the repository remains active with recent commits and the package is widely used in production (top 1000 on PyPI).
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), so you can use, modify, and distribute hvac freely in commercial and private projects with minimal restrictions.
last release 2025-10-30 (288 days) · last repo commit 2026-01-06 · 1,314 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 32,231,023 downloads/mo, #777 on PyPI
Alternatives
Verify before relying
pip install hvac
import hvac
client = hvac.Client(url='http://vault-server:port')
secret = client.secrets.kv.read_secret_version(path='secret/data/my-secret')- Whether the 288-day release gap reflects planned stability or reduced active development.
- Current test coverage against Vault versions beyond v1.4.7 and whether all documented auth methods are fully maintained.
- Whether the optional HCL parser extra (hvac[parser]) is actively maintained and what its dependencies are.
What it is and what it does
hvac is the official Python client for HashiCorp Vault, a secrets management and encryption platform. It wraps Vault's HTTP API to let you read, write, and manage secrets, handle authentication, and control encryption keys from Python code. The library depends only on requests and supports Python 3.8 through 3.12.
You use hvac when you need to integrate Vault into a Python application—retrieving database credentials at runtime, managing API keys, rotating secrets, or orchestrating authentication flows. It abstracts away HTTP details and provides a Pythonic interface to Vault's auth methods, secret engines, and policy management.
Use it for
- Retrieve database credentials or API keys from Vault at application startup or on-demand.
- Implement automated secret rotation by reading new credentials and updating application state.
- Authenticate applications to Vault using AppRole, JWT, or other auth methods.
- Manage encryption keys and perform encryption/decryption operations via Vault's transit engine.
- Audit and control secret access by querying Vault's audit logs and policy endpoints.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
hvac is the standard Python client for Vault, widely deployed in production (top 1000 PyPI), has no known vulnerabilities, and carries a permissive Apache-2.0 license. Install friction is minimal. The aging maintenance status (288 days since last release) is a minor concern but not a blocker if you are using a stable Vault version; verify that your Vault version is within the supported range (v1.4.7 or later).
Install
hvac on PyPI
Before you install
Low install friction with a single runtime dependency (requests). Maintenance status is aging—the last release was 288 days ago—but the repository remains active with recent commits and the package is widely used in production (top 1000 on PyPI).
Requires a running Vault server accessible at the specified URL and appropriate authentication credentials (token, role, or other auth method).
License in practice
Licensed under Apache-2.0 (permissive), so you can use, modify, and distribute hvac freely in commercial and private projects with minimal restrictions.
Quickstart
pip install hvac
import hvac
client = hvac.Client(url='http://vault-server:port')
secret = client.secrets.kv.read_secret_version(path='secret/data/my-secret')
Verify before relying
- Whether the 288-day release gap reflects planned stability or reduced active development.
- Current test coverage against Vault versions beyond v1.4.7 and whether all documented auth methods are fully maintained.
- Whether the optional HCL parser extra (hvac[parser]) is actively maintained and what its dependencies are.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release <4.0,>=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagerequests |
| Maintenance | Aging 288 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 32,231,023 / month, #777 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPython |
Evidence: hvac-2.4.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “vault api client python”
- hvachvac is a Python client library for HashiCorp Vault that enables…
- azure-keyvault-secretsSecurely store, retrieve, and manage secrets (passwords, tokens, API…
- fireblocksPython SDK for integrating with the Fireblocks platform to manage…
Give your agent the search over MCP, or paste the wish link into any chat.
Similar packages
Integrates Apache Airflow with HashiCorp Vault and other HashiCorp services, enabling Airflow workflows to authenticate, retrieve secrets, and interact with HashiCorp infrastructure.
A Salt extension that integrates HashiCorp Vault (or OpenBao) with Salt for secrets management and configuration retrieval.
Wrapper around the 1Password CLI that lets you query and retrieve secrets, documents, and credentials from a 1Password vault programmatically.
Securely store, retrieve, and manage secrets (passwords, tokens, API keys, certificates) in Azure Key Vault from Python applications.
Install it if you are building on Azure and need to externalize secret management to Key Vault; it is the standard way to do so from Python.
Pulumi resource provider for HashiCorp Vault that lets you define and manage Vault resources (secrets, auth methods, policies) as code within Pulumi infrastructure programs.
Install it if you use Pulumi and need to manage Vault resources programmatically; the tight integration with Pulumi's config and secret handling is its main value.
Parses HCL (HashiCorp Configuration Language) files into Python dictionaries, providing load/loads/dumps functions similar to the json module.
However, do not use it for modern Terraform (which requires HCL2 support); maintenance is aging with the last release in 2023-09-01, so expect limited support for new…
See also types-hvac · azure-keyvault-certificates · environ-config · bitwarden-sdk