keyrings.cryptfile
Encrypted file keyring backend
Decision gist · record as of 2026-08-14
Yes, with conditions. Install if you need portable encrypted password storage and can tolerate high build friction (C compiler, development headers) and the ~1 second delay per password operation. The MIT license and active maintenance are favorable. Skip if your system already has a working keyring service or if build dependencies are unavailable; the package is not suitable for high-frequency password access due to intentional KDF slowness.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires C compiler and development headers (python-devel, openssl-devel) to build cryptographic dependencies; KDF operations introduce ~1 second delay per password operation.
- High install friction: the package requires compilation of cryptographic dependencies (argon2-cffi, pycryptodome, cryptography) and system development packages (python-devel, openssl-devel).
- Maintenance is active with a recent commit (2026-06-26), though the latest release is from 2022-11-20.
License · maintenance · safety
MIT (permissive) — MIT license is permissive, allowing commercial and private use with minimal restrictions—suitable for most projects.
last release 2022-11-20 (1363 days) · last repo commit 2026-06-26 · 43 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 391,796 downloads/mo, #7,012 on PyPI
Alternatives
Verify before relying
from keyrings.cryptfile.cryptfile import CryptFileKeyring
kr = CryptFileKeyring()
kr.set_password("service", "user", "secret")
password = kr.get_password("service", "user")- Whether the Argon2 parameters (m=65536, t=15, p=2) remain resistant to modern attacks beyond 2017.
- Current security posture of the static reference value encryption scheme against known-plaintext attacks.
- Whether keyring integration requires additional setup beyond instantiation.
What it is and what it does
keyrings.cryptfile provides an encrypted file-based keyring backend for the keyring package, designed for scenarios where the system's default keyring storage (like GNOME Keyring or KDE Wallet) is unavailable or unsuitable. It stores passwords in a portable .ini-format file secured with Argon2 key derivation and authenticated AES encryption (GCM by default), with support for CCM, EAX, and OCB schemes.
The package encrypts each password with a keyring master password, deriving an Argon2 hash that serves as the encryption key. Service and user identifiers are included as associated data in the authenticated encryption, preventing tampering. The resulting encrypted data, salt, nonce, and MAC are stored in a text file. Operations are intentionally slow (around 1 second per call) due to the Argon2 KDF, which raises the computational cost of brute-force attacks.
Use it for
- Store API keys and database passwords in a portable encrypted file for development environments without a system keyring.
- Secure credential storage in containerized or headless systems where desktop keyring services are unavailable.
- Protect plaintext passwords in configuration files by replacing them with keyring lookups.
- Implement password management in cross-platform scripts that need consistent credential handling.
- Archive encrypted credentials in version control or backups with protection against casual inspection.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
Install if you need portable encrypted password storage and can tolerate high build friction (C compiler, development headers) and the ~1 second delay per password operation. The MIT license and active maintenance are favorable. Skip if your system already has a working keyring service or if build dependencies are unavailable; the package is not suitable for high-frequency password access due to intentional KDF slowness.
Install
keyrings-cryptfile on PyPI
Before you install
High install friction: the package requires compilation of cryptographic dependencies (argon2-cffi, pycryptodome, cryptography) and system development packages (python-devel, openssl-devel). Maintenance is active with a recent commit (2026-06-26), though the latest release is from 2022-11-20.
Requires C compiler and development headers (python-devel, openssl-devel) to build cryptographic dependencies; KDF operations introduce ~1 second delay per password operation.
License in practice
MIT license is permissive, allowing commercial and private use with minimal restrictions—suitable for most projects.
Quickstart
from keyrings.cryptfile.cryptfile import CryptFileKeyring
kr = CryptFileKeyring()
kr.set_password("service", "user", "secret")
password = kr.get_password("service", "user")
Verify before relying
- Whether the Argon2 parameters (m=65536, t=15, p=2) remain resistant to modern attacks beyond 2017.
- Current security posture of the static reference value encryption scheme against known-plaintext attacks.
- Whether keyring integration requires additional setup beyond instantiation.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.5 |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Actively maintained 1,363 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 391,796 / month, #7,012 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: keyrings.cryptfile-1.3.9.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “encrypted password storage file”
- keyrings.cryptfileA keyring backend that stores passwords in an encrypted file using…
- pyzipperpyzipper replaces Python's standard zipfile module to read and write…
- keyringKeyring provides safe password and credential storage by interfacing…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also keyring · keyrings.alt · SecretStorage · spake2 · aws-encryption-sdk · hkdf · argon2-cffi-bindings · argon2-cffi · aes-pkcs5 · borgbackup