M2Crypto
A Python crypto and SSL toolkit
Decision gist · record as of 2026-08-14
Yes, but with conditions. Install M2Crypto only if you are maintaining existing code that already depends on it or if you need direct OpenSSL interoperability that modern alternatives do not provide. Do not use it for new projects—the maintainer explicitly recommends alternatives instead. Medium install friction (compiled extension) is acceptable for established deployments. No known vulnerabilities and permissive licensing support continued use.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires OpenSSL development headers and a C compiler; on Windows prebuilt wheels are available for Python 3.10–3.14.
- Medium install friction due to compiled C extension requiring OpenSSL headers and build tools.
- Active maintenance with recent release (83 days old), though explicitly in maintenance mode since 2014—suitable for existing deployments but new projects should consider alternatives.
License · maintenance · safety
BSD-2-Clause (permissive) — BSD-2-Clause is permissive; you may use, modify, and distribute M2Crypto freely in commercial and private projects with minimal restrictions.
last release 2026-05-23 (83 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 263,997 downloads/mo, #8,346 on PyPI
Alternatives
Verify before relying
pip install m2crypto
from M2Crypto import BIO, RSA
key = RSA.gen_key()- Whether the library's documented memory-leak caveats and lack of key-clearing features pose practical risks for your use case.
- Current state of the SWIG bindings and whether all OpenSSL features you need are exposed.
- Specific key generation parameters and their defaults for RSA and DSA operations.
What it is and what it does
M2Crypto is a Python wrapper around OpenSSL that exposes cryptographic operations and TLS functionality through a high-level API. It provides RSA, DSA, DH key generation and operations, symmetric ciphers (including AES), HMAC and message digest functions, and full TLS client/server implementation. It also extends Python's standard httplib, urllib, and xmlrpclib with HTTPS support, and includes S/MIME v2 messaging and FTP/TLS capabilities.
The library has been in maintenance mode since 2014 and is actively maintained but explicitly recommended only for existing applications. The maintainer directs new projects toward more modern alternatives. M2Crypto depends only on packaging at runtime and requires OpenSSL headers and a C compiler to install; prebuilt wheels exist for recent Python versions on Windows.
Use it for
- Migrate legacy Python applications that already use M2Crypto for TLS and cryptographic operations without rewriting.
- Implement HTTPS clients or servers when you need direct OpenSSL control and already have M2Crypto in your codebase.
- Add HMAC-based session management (AuthCookies) to web applications requiring unforgeable authentication tokens.
- Perform RSA or DSA key generation and cryptographic operations in systems where OpenSSL interoperability is critical.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, but with conditions.
Install M2Crypto only if you are maintaining existing code that already depends on it or if you need direct OpenSSL interoperability that modern alternatives do not provide. Do not use it for new projects—the maintainer explicitly recommends alternatives instead. Medium install friction (compiled extension) is acceptable for established deployments. No known vulnerabilities and permissive licensing support continued use.
Install
m2crypto on PyPI
Before you install
Medium install friction due to compiled C extension requiring OpenSSL headers and build tools. Active maintenance with recent release (83 days old), though explicitly in maintenance mode since 2014—suitable for existing deployments but new projects should consider alternatives.
Requires OpenSSL development headers and a C compiler; on Windows prebuilt wheels are available for Python 3.10–3.14.
License in practice
BSD-2-Clause is permissive; you may use, modify, and distribute M2Crypto freely in commercial and private projects with minimal restrictions.
Quickstart
pip install m2crypto
from M2Crypto import BIO, RSA
key = RSA.gen_key()
Verify before relying
- Whether the library's documented memory-leak caveats and lack of key-clearing features pose practical risks for your use case.
- Current state of the SWIG bindings and whether all OpenSSL features you need are exposed.
- Specific key generation parameters and their defaults for RSA and DSA operations.
Package facts
| License | BSD-2-Clause permissive |
| Python support | Supports the current Python release >=3.6 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 1 packagepackaging |
| Maintenance | Actively maintained 83 days since the last release |
| First released | |
| Downloads | 263,997 / month, #8,346 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: CProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Security :: CryptographyTopic :: Software Development :: Libraries :: Python Modules |
Evidence: m2crypto-0.48.0-cp310-cp310-win_amd64.whl; m2crypto-0.48.0-cp311-cp311-win_amd64.whl; m2crypto-0.48.0-cp312-cp312-win_amd64.whl; m2crypto-0.48.0-cp313-cp313-win_amd64.whl; m2crypto-0.48.0-cp314-cp314-win_amd64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “tls ssl client server”
- M2CryptoM2Crypto wraps OpenSSL via SWIG to provide Python access to…
- certbotCertbot is a command-line client that automatically obtains TLS…
- nasslnassl is an OpenSSL wrapper for Python that exposes low-level SSL/TLS…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also oscrypto · tlslite-ng · pyOpenSSL · nassl · sslcrypto · sshpubkeys · cryptg · python3-dtls · asn1crypto · PyKCS11