keystone
OpenStack Identity
Decision gist · record as of 2026-08-14
Yes, if you are deploying or operating an OpenStack cloud. Keystone is essential infrastructure for any OpenStack deployment. However, this is not a library for general application use—it is a service component. Be aware of 5 known vulnerabilities in the security database; verify that version 29.0.2 includes patches or plan mitigations. Requires Python 3.10+, substantial operational setup (database, messaging, identity backend), and integration with other OpenStack services.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Keystone is an OpenStack service component designed for deployment in a cloud infrastructure context, not a library for direct application import.
- Requires Python 3.10 or later and is intended to run as a standalone HTTP service.
- Low install friction with a pure-Python wheel distribution.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing commercial use, modification, and redistribution with minimal restrictions beyond attribution and liability disclaimers.
last release 2026-07-02 (43 days)
5 known vulnerabilities (OSV.dev, 2026-08-14) · 135,331 downloads/mo, #11,439 on PyPI
Alternatives
Verify before relying
pip install keystone
from keystone import service
# Keystone is typically deployed as an OpenStack service via configuration files
# and run as a daemon, not imported directly in application code.- Whether the 5 known vulnerabilities (GHSA-gf2q-j2qq-pjf2, GHSA-mrxv-65rv-6hxq, PYSEC-2012-19, PYSEC-2012-20, PYSEC-2026-833) have been patched in version 29.0.2 or remain open.
- Whether Keystone 29.0.2 is compatible with the specific OpenStack release cycle and other OpenStack components in your deployment.
- Operational requirements: database setup, message broker configuration, and LDAP or other identity backend integration specifics.
What it is and what it does
Keystone is OpenStack's identity and access management service. It provides centralized authentication (verifying who users are), authorization (determining what they can do), and service discovery (helping other OpenStack services find each other) via HTTP APIs. It is designed to be deployed as a standalone service in an OpenStack cloud, not as a library embedded in other applications.
The package includes a Flask-based HTTP server, integrates with SQLAlchemy for persistence, uses cryptography and bcrypt for secure credential handling, and supports multiple authentication backends including LDAP, OAuth, and SAML2. It depends on the oslo.* family of libraries for configuration, logging, caching, and policy enforcement—standard infrastructure components across OpenStack services. Deployment typically involves configuration files, a database, and integration with an identity provider.
Use it for
- Deploy as the identity service for an OpenStack cloud to authenticate users and issue tokens for API access.
- Integrate with an existing LDAP directory to provide cloud-native authentication without duplicating user accounts.
- Enable service-to-service authentication and discovery so OpenStack components (Nova, Glance, Cinder) can securely communicate.
- Support federated identity via SAML2 or OAuth to allow users from external identity providers to access the cloud.
- Manage role-based access control (RBAC) policies across OpenStack projects and services using oslo.policy.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are deploying or operating an OpenStack cloud.
Keystone is essential infrastructure for any OpenStack deployment. However, this is not a library for general application use—it is a service component. Be aware of 5 known vulnerabilities in the security database; verify that version 29.0.2 includes patches or plan mitigations. Requires Python 3.10+, substantial operational setup (database, messaging, identity backend), and integration with other OpenStack services.
Install
keystone on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Active maintenance with a release 43 days old. Requires Python 3.10 or later. Brings 31 runtime dependencies including Flask, SQLAlchemy, cryptography, and multiple oslo.* libraries, which is typical for OpenStack services but represents a substantial dependency footprint.
Keystone is an OpenStack service component designed for deployment in a cloud infrastructure context, not a library for direct application import. Requires Python 3.10 or later and is intended to run as a standalone HTTP service.
License in practice
Licensed under Apache-2.0 (permissive), allowing commercial use, modification, and redistribution with minimal restrictions beyond attribution and liability disclaimers.
Quickstart
pip install keystone
from keystone import service
# Keystone is typically deployed as an OpenStack service via configuration files
# and run as a daemon, not imported directly in application code.
Verify before relying
- Whether the 5 known vulnerabilities (GHSA-gf2q-j2qq-pjf2, GHSA-mrxv-65rv-6hxq, PYSEC-2012-19, PYSEC-2012-20, PYSEC-2026-833) have been patched in version 29.0.2 or remain open.
- Whether Keystone 29.0.2 is compatible with the specific OpenStack release cycle and other OpenStack components in your deployment.
- Operational requirements: database setup, message broker configuration, and LDAP or other identity backend integration specifics.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 31 packagespbrWebObFlaskFlask-RESTfulcryptographySQLAlchemystevedorepython-keystoneclientkeystonemiddlewarebcryptoslo.cacheoslo.configoslo.contextoslo.messagingoslo.dboslo.i18noslo.logoslo.middlewareoslo.policyoslo.serializationoslo.upgradecheckoslo.utilsoauthlibpysaml2PyJWTdogpile.cachejsonschemapycadfmsgpackosprofiler |
| Maintenance | Actively maintained 43 days since the last release |
| First released | |
| Downloads | 135,331 / month, #11,439 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | 5 GHSA-gf2q-j2qq-pjf2, GHSA-mrxv-65rv-6hxq, PYSEC-2012-19, PYSEC-2012-20, PYSEC-2026-833 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13 |
Evidence: keystone-29.0.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “openstack identity service”
- keystoneOpenStack Keystone provides authentication, authorization, and…
- python-keystoneclientPython client library for authenticating with and managing OpenStack…
- keystoneauth1Provides authentication plugins, API discovery, and session…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also castellan · keystoneauth1 · keystonemiddleware · python-keystoneclient · keystone-engine · oslo.policy · os-brick · os-service-types · python-barbicanclient · oslo.service