$npx skillfedfor your agent

hvac

HashiCorp Vault API client

Worth itPyPI Released Oct 202532.2M downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — hvac-2.4.0-py3-none-any.whl
v2.4.0 · released 2025-10-30 · Python <4.0,>=3.8 · 1 runtime deps: requests

Yes. hvac is the standard Python client for Vault, widely deployed in production (top 1000 PyPI), has no known vulnerabilities, and carries a permissive Apache-2.0 license. Install friction is minimal. The aging maintenance status (288 days since last release) is a minor concern but not a blocker if you are using a stable Vault version; verify that your Vault version is within the supported range (v1.4.7 or later).AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a running Vault server accessible at the specified URL and appropriate authentication credentials (token, role, or other auth method).
  • Low install friction with a single runtime dependency (requests).
  • Maintenance status is aging—the last release was 288 days ago—but the repository remains active with recent commits and the package is widely used in production (top 1000 on PyPI).

License · maintenance · safety

Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), so you can use, modify, and distribute hvac freely in commercial and private projects with minimal restrictions.

last release 2025-10-30 (288 days) · last repo commit 2026-01-06 · 1,314 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 32,231,023 downloads/mo, #777 on PyPI

Verify before relying

pip install hvac

import hvac

client = hvac.Client(url='http://vault-server:port')
secret = client.secrets.kv.read_secret_version(path='secret/data/my-secret')
  • Whether the 288-day release gap reflects planned stability or reduced active development.
  • Current test coverage against Vault versions beyond v1.4.7 and whether all documented auth methods are fully maintained.
  • Whether the optional HCL parser extra (hvac[parser]) is actively maintained and what its dependencies are.
Same gist for agents: .md · .json

What it is and what it does

hvac is the official Python client for HashiCorp Vault, a secrets management and encryption platform. It wraps Vault's HTTP API to let you read, write, and manage secrets, handle authentication, and control encryption keys from Python code. The library depends only on requests and supports Python 3.8 through 3.12.

You use hvac when you need to integrate Vault into a Python application—retrieving database credentials at runtime, managing API keys, rotating secrets, or orchestrating authentication flows. It abstracts away HTTP details and provides a Pythonic interface to Vault's auth methods, secret engines, and policy management.

Use it for

  • Retrieve database credentials or API keys from Vault at application startup or on-demand.
  • Implement automated secret rotation by reading new credentials and updating application state.
  • Authenticate applications to Vault using AppRole, JWT, or other auth methods.
  • Manage encryption keys and perform encryption/decryption operations via Vault's transit engine.
  • Audit and control secret access by querying Vault's audit logs and policy endpoints.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

hvac is the standard Python client for Vault, widely deployed in production (top 1000 PyPI), has no known vulnerabilities, and carries a permissive Apache-2.0 license. Install friction is minimal. The aging maintenance status (288 days since last release) is a minor concern but not a blocker if you are using a stable Vault version; verify that your Vault version is within the supported range (v1.4.7 or later).

Install

hvac on PyPI

Before you install

Low install friction with a single runtime dependency (requests). Maintenance status is aging—the last release was 288 days ago—but the repository remains active with recent commits and the package is widely used in production (top 1000 on PyPI).

Requires a running Vault server accessible at the specified URL and appropriate authentication credentials (token, role, or other auth method).

License in practice

Licensed under Apache-2.0 (permissive), so you can use, modify, and distribute hvac freely in commercial and private projects with minimal restrictions.

Quickstart

pip install hvac

import hvac

client = hvac.Client(url='http://vault-server:port')
secret = client.secrets.kv.read_secret_version(path='secret/data/my-secret')

Verify before relying

  • Whether the 288-day release gap reflects planned stability or reduced active development.
  • Current test coverage against Vault versions beyond v1.4.7 and whether all documented auth methods are fully maintained.
  • Whether the optional HCL parser extra (hvac[parser]) is actively maintained and what its dependencies are.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release <4.0,>=3.8
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
requests
MaintenanceAging 288 days since the last release
Last repo commit
First released
Downloads32,231,023 / month, #777 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: Apache Software LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPython

Evidence: hvac-2.4.0-py3-none-any.whl

Tags

Capabilities
vault api client pythonhashicorp vault secrets managementvault authentication pythonsecrets storage clientvault key managementvault api wrapperpython vault integration
Topics
secrets-managementvault-integrationapi-client
PyPI keywords
hashicorpvault

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “vault api client python”

  • hvachvac is a Python client library for HashiCorp Vault that enables…
  • azure-keyvault-secretsSecurely store, retrieve, and manage secrets (passwords, tokens, API…
  • fireblocksPython SDK for integrating with the Fireblocks platform to manage…

Give your agent the search over MCP, or paste the wish link into any chat.

Similar packages

apache-airflow-providers-hashicorp With conditions
PyPI · Monitoring · released Aug 2026

Integrates Apache Airflow with HashiCorp Vault and other HashiCorp services, enabling Airflow workflows to authenticate, retrieve secrets, and interact with HashiCorp infrastructure.

Apache-2.0pure Python · 3.10+
681.7Kdownloads / mo
saltext.vault With conditions
PyPI · Cryptography · released Aug 2026

A Salt extension that integrates HashiCorp Vault (or OpenBao) with Salt for secrets management and configuration retrieval.

Apache-2.0pure Python · 3.10+
109.2Kdownloads / mo
onepassword Skip
PyPI · Security · released Jun 2020

Wrapper around the 1Password CLI that lets you query and retrieve secrets, documents, and credentials from a 1Password vault programmatically.

MITpure Pythonabandoned
74.1Kdownloads / mo
azure-keyvault-secrets Worth it
PyPI · Cryptography · released Aug 2026

Securely store, retrieve, and manage secrets (passwords, tokens, API keys, certificates) in Azure Key Vault from Python applications.

Install it if you are building on Azure and need to externalize secret management to Key Vault; it is the standard way to do so from Python.

MITpure Python · 3.9+
60.9Mdownloads / mo
pulumi-vault Worth it
PyPI · Build Tools · released Aug 2026

Pulumi resource provider for HashiCorp Vault that lets you define and manage Vault resources (secrets, auth methods, policies) as code within Pulumi infrastructure programs.

Install it if you use Pulumi and need to manage Vault resources programmatically; the tight integration with Pulumi's config and secret handling is its main value.

permissive licensepure Python · 3.9+
105.1Kdownloads / mo
pyhcl With conditions
PyPI · Text Processing · released Sep 2023

Parses HCL (HashiCorp Configuration Language) files into Python dictionaries, providing load/loads/dumps functions similar to the json module.

However, do not use it for modern Terraform (which requires HCL2 support); maintenance is aging with the last release in 2023-09-01, so expect limited support for new…

MPL-2.0pure Pythonaging
9.8Mdownloads / mo

See also types-hvac · azure-keyvault-certificates · environ-config · bitwarden-sdk