magic-wormhole
Securely transfer data between computers
Decision gist · record as of 2026-08-14
Yes. Magic Wormhole is actively maintained, has no known vulnerabilities, low install friction, and solves a real problem—secure, code-based file transfer with minimal setup. The MIT license is permissive. Install it if you need to move files between machines without pre-arrangement or if you want to add encrypted transfer to a Python application. The only caveat is that it depends on external relay infrastructure (mailbox and transit servers) that you do not control; verify those services remain available for your use case.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or higher; depends on system-level networking and cryptographic libraries that twisted and pynacl may require compilation for on some platforms.
- Low install friction with a pure-Python wheel.
- Active maintenance as of 2026-07-26 with 22816 repository stars.
License · maintenance · safety
MIT (permissive) — Released under the MIT license (permissive), allowing use in both open-source and proprietary projects with minimal restrictions.
last release 2026-05-05 (101 days) · last repo commit 2026-07-26 · 22,816 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 684,088 downloads/mo, #5,359 on PyPI
Alternatives
Verify before relying
pip install magic-wormhole
from wormhole import create
wormhole_code = create() # generates a code to share
# or use the CLI: wormhole send <file>- Whether the mailbox server and transit relay infrastructure remain publicly available and maintained
- Performance characteristics when transferring very large files or directories
- Whether pywin32 dependency affects non-Windows installation or is conditionally installed
What it is and what it does
Magic Wormhole is a tool for securely moving files, directories, or short text between two computers without requiring prior setup, shared infrastructure, or manual configuration. The sender generates a short, human-pronounceable code (like a passphrase) that the receiver types into their machine; the two endpoints then establish an encrypted connection and transfer the data. The codes are single-use, do not need memorization, and support tab-completion to minimize typing.
The package works as both a command-line utility and a Python library, making it suitable for ad-hoc transfers as well as programmatic integration. It relies on end-to-end encryption (via pynacl and cryptography), a relay server for initial connection brokering, and the Twisted networking framework for asynchronous I/O. The tool is designed for simplicity and security: no accounts, no passwords, no pre-shared keys—just a code.
Use it for
- Send a file or folder to a colleague without setting up cloud storage or email
- Programmatically transfer data between two Python applications on different machines
- Securely share sensitive files with end-to-end encryption and no persistent server storage
- Quickly move a directory tree across a network without SSH or rsync setup
- Integrate encrypted peer-to-peer file transfer into a Python application
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Magic Wormhole is actively maintained, has no known vulnerabilities, low install friction, and solves a real problem—secure, code-based file transfer with minimal setup. The MIT license is permissive. Install it if you need to move files between machines without pre-arrangement or if you want to add encrypted transfer to a Python application. The only caveat is that it depends on external relay infrastructure (mailbox and transit servers) that you do not control; verify those services remain available for your use case.
Install
magic-wormhole on PyPI
Before you install
Low install friction with a pure-Python wheel. Active maintenance as of 2026-07-26 with 22816 repository stars. Requires Python 3.10 or higher and depends on 15 runtime packages including cryptographic libraries (pynacl, cryptography) and networking stacks (twisted, autobahn).
Requires Python 3.10 or higher; depends on system-level networking and cryptographic libraries that twisted and pynacl may require compilation for on some platforms.
License in practice
Released under the MIT license (permissive), allowing use in both open-source and proprietary projects with minimal restrictions.
Quickstart
pip install magic-wormhole
from wormhole import create
wormhole_code = create() # generates a code to share
# or use the CLI: wormhole send <file>
Verify before relying
- Whether the mailbox server and transit relay infrastructure remain publicly available and maintained
- Performance characteristics when transferring very large files or directories
- Whether pywin32 dependency affects non-Windows installation or is conditionally installed
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 15 packagesspake2pynaclattrstwistedautobahnautomatcryptographytqdmclickhumanizetxtorconzipstream-ngiterable-ioqrcodepywin32 |
| Maintenance | Actively maintained 101 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 684,088 / month, #5,359 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaEnvironment :: ConsoleProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: Implementation :: CPythonTopic :: Security :: CryptographyTopic :: System :: NetworkingTopic :: System :: Systems AdministrationTopic :: Utilities |
Evidence: magic_wormhole-0.24.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “secure file transfer between computers”
- magic-wormholeMagic Wormhole transfers files, directories, and text between…
- globus-sdkProvides a Python interface to Globus APIs for managing data…
- sendsafelyIntegrates SendSafely secure file transfer and messaging into Python…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also python-olm · wakeonlan · pysmb · sendsafely · xmodem · davey · django-magiclink · aws-encryption-sdk-cli · keyrings.cryptfile · python-magic-bin