invenio-records-permissions
Permission policies for Invenio records.
Decision gist · record as of 2026-08-14
Yes, if you are building or extending an Invenio digital repository system. The package is actively maintained, has no security vulnerabilities, and carries a permissive MIT license. It is low-friction to install. If you are not working within the Invenio ecosystem, this package is not applicable.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; intended for use within an Invenio digital repository installation.
- Low install friction with a single runtime dependency (invenio-access).
- Active maintenance with a recent release 29 days ago; repository is not archived and receives ongoing commits.
License · maintenance · safety
MIT (permissive) — MIT license is permissive, allowing use in commercial and private projects with minimal restrictions beyond attribution.
last release 2026-07-16 (29 days) · last repo commit 2026-07-21 · 1 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 154,687 downloads/mo, #10,847 on PyPI
Alternatives
Verify before relying
pip install invenio-records-permissions
from invenio_records_permissions import RecordPermissionPolicy
# Define and apply permission policies to Invenio records- What specific permission models or policy types this package supports beyond the summary.
- Whether this package is intended for end-user applications or primarily for Invenio framework developers.
- Integration requirements or configuration steps needed beyond installing the dependency.
What it is and what it does
Invenio-Records-Permissions is a permission policy module for the Invenio digital repository framework. It provides the mechanisms to define and enforce access control rules on records—determining who can view, edit, or delete record data. The package depends on invenio-access for its underlying access control infrastructure.
This is a specialized library for Invenio deployments, not a standalone permission system. It is actively maintained, currently in alpha status, and carries no known security vulnerabilities. Installation is straightforward with minimal dependencies.
Use it for
- Define role-based access policies for records in an Invenio digital repository.
- Enforce permission rules when users attempt to read or modify record metadata.
- Integrate custom permission logic into an Invenio-based research data management system.
- Control visibility and editability of records based on user roles or organizational hierarchy.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building or extending an Invenio digital repository system.
The package is actively maintained, has no security vulnerabilities, and carries a permissive MIT license. It is low-friction to install. If you are not working within the Invenio ecosystem, this package is not applicable.
Install
invenio-records-permissions on PyPI
Before you install
Low install friction with a single runtime dependency (invenio-access). Active maintenance with a recent release 29 days ago; repository is not archived and receives ongoing commits.
Requires Python 3.9 or later; intended for use within an Invenio digital repository installation.
License in practice
MIT license is permissive, allowing use in commercial and private projects with minimal restrictions beyond attribution.
Quickstart
pip install invenio-records-permissions
from invenio_records_permissions import RecordPermissionPolicy
# Define and apply permission policies to Invenio records
Verify before relying
- What specific permission models or policy types this package supports beyond the summary.
- Whether this package is intended for end-user applications or primarily for Invenio framework developers.
- Integration requirements or configuration steps needed beyond installing the dependency.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageinvenio-access |
| Maintenance | Actively maintained 29 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 154,687 / month, #10,847 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - Alpha |
Evidence: invenio_records_permissions-4.0.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “invenio record permissions”
- invenio-records-permissionsDefines and enforces permission policies for records in Invenio…
- invenio-restInvenio-REST provides Flask-based REST API infrastructure with…
- salesforce-apiWraps Salesforce's REST and SOAP APIs to insert, update, upsert,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also invenio-rest · oslo.policy · pulumi-policy · Flask-Principal · django-permissions-policy · drf-access-policy · casbin · reuse · cerbos · recordlinkage