kerberos
Kerberos high-level interface
Decision gist · record as of 2026-08-14
No—do not install for new projects. The package is abandoned (last release January 2021, repository archived), carries at least one known security vulnerability (PYSEC-2017-49), and has medium install friction due to compiled C dependencies. If you must use Kerberos authentication in Python, evaluate actively maintained alternatives or consider using system-level Kerberos libraries directly. Only install if you are maintaining legacy code already depending on this package and cannot migrate.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a valid Kerberos installation (Kerberos framework on macOS, krb5 development headers on Linux) and a working KDC; not installable on systems without Kerberos infrastructure.
- Medium install friction due to compiled C extensions requiring a Kerberos framework or development headers on the system.
- Repository is archived and last released in 2021, with no commits since February 2024—maintenance has ceased.
License · maintenance · safety
Apache License, Version 2.0 (permissive) — Licensed under Apache License 2.0 (permissive), allowing commercial and private use with minimal restrictions, though you must retain license notices.
last release 2021-01-09 (2043 days) · last repo commit 2024-02-24 · 119 stars · archived
1 known vulnerabilities (OSV.dev, 2026-08-14) · 2,565,986 downloads/mo, #2,998 on PyPI
Alternatives
Verify before relying
import kerberos
result, context = kerberos.authGSSClientInit('HTTP@example.com')
kerberos.authGSSClientStep(context, '')
kerberos.authGSSClientClean(context)- Whether the single known vulnerability (PYSEC-2017-49) has been patched or remains exploitable in version 1.3.1.
- Current compatibility with modern Python versions beyond those in the wheel filenames (cp27, cp38, cp39).
- Whether the checkPassword method's testing-only limitation affects real-world deployment scenarios.
What it is and what it does
PyKerberos is a thin Python wrapper around the Kerberos/GSSAPI C libraries, designed to handle client and server authentication flows without requiring you to wrap the entire Kerberos framework yourself. It exposes a limited set of functions for initiating authentication contexts, stepping through the Kerberos handshake, and managing channel bindings for enhanced security. The package has no runtime Python dependencies and compiles against system Kerberos libraries.
The library is intended for applications that need to authenticate users or services using Kerberos tickets, such as web servers enforcing Kerberos-based SSO or internal tools integrating with Active Directory. It supports channel bindings (useful for meeting Microsoft Extended Protection requirements) and offers both client-side and server-side authentication primitives. However, the project is no longer maintained—the repository was archived after its final release in January 2021, and there have been no updates since.
Use it for
- Authenticate HTTP clients against a Kerberos-protected web server using SPNEGO/Negotiate.
- Build a Kerberos-aware reverse proxy or gateway that validates incoming Kerberos tickets.
- Implement SSO integration in internal applications that rely on Active Directory or MIT Kerberos.
- Add channel binding support to TLS connections to meet enterprise security policies.
- Test Kerberos authentication flows in a development environment with a local KDC.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No—do not install for new projects.
The package is abandoned (last release January 2021, repository archived), carries at least one known security vulnerability (PYSEC-2017-49), and has medium install friction due to compiled C dependencies. If you must use Kerberos authentication in Python, evaluate actively maintained alternatives or consider using system-level Kerberos libraries directly. Only install if you are maintaining legacy code already depending on this package and cannot migrate.
Install
kerberos on PyPI
Before you install
Medium install friction due to compiled C extensions requiring a Kerberos framework or development headers on the system. Repository is archived and last released in 2021, with no commits since February 2024—maintenance has ceased.
Requires a valid Kerberos installation (Kerberos framework on macOS, krb5 development headers on Linux) and a working KDC; not installable on systems without Kerberos infrastructure.
License in practice
Licensed under Apache License 2.0 (permissive), allowing commercial and private use with minimal restrictions, though you must retain license notices.
Quickstart
import kerberos
result, context = kerberos.authGSSClientInit('HTTP@example.com')
kerberos.authGSSClientStep(context, '')
kerberos.authGSSClientClean(context)
Verify before relying
- Whether the single known vulnerability (PYSEC-2017-49) has been patched or remains exploitable in version 1.3.1.
- Current compatibility with modern Python versions beyond those in the wheel filenames (cp27, cp38, cp39).
- Whether the checkPassword method's testing-only limitation affects real-world deployment scenarios.
Package facts
| License | Apache License, Version 2.0 permissive |
| Python support | Not specified |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Abandoned 2,043 days since the last release |
| Last repo commit | repository archived |
| First released | |
| Downloads | 2,565,986 / month, #2,998 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | 1 PYSEC-2017-49 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 2Programming Language :: Python :: 3Topic :: Software Development :: Libraries :: Python ModulesTopic :: System :: Systems Administration :: Authentication/Directory |
Evidence: kerberos-1.3.1-cp27-cp27m-macosx_11_1_x86_64.whl; kerberos-1.3.1-cp38-cp38-macosx_10_15_x86_64.whl; kerberos-1.3.1-cp39-cp39-macosx_10_9_x86_64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “kerberos client server auth”
- kerberosProvides a high-level Python wrapper for Kerberos (GSSAPI)…
- pyspnegoHandles SPNEGO, NTLM, Kerberos, and CredSSP authentication protocols;…
- winkerberosProvides native Kerberos client authentication on Windows by wrapping…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also pykerberos · scramp · gssapi · winkerberos · k5test · requests-kerberos · requests-gssapi · python-kadmin-rs · pyspnego · minikerberos