$npx skillfedfor your agent

msal-extensions

Microsoft Authentication Library extensions (MSAL EX) provides a persistence API that can save your data on disk, encrypted on Windows, macOS and Linux. Concurrent data access will be coordinated by a file lock mechanism.

With conditionsPyPI CryptographyReleased Mar 2025166.4M downloads / moMIT LicensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — msal_extensions-1.3.1-py3-none-any.whl
v1.3.1 · released 2025-03-14 · Python >=3.9 · 1 runtime deps: msal

Yes, if you are building a desktop or client application with MSAL Python and need secure token persistence. The library handles platform-specific encryption transparently and integrates seamlessly with msal. However, note that the last release was 518 days ago (aging maintenance), so verify that the current version meets your msal compatibility requirements. Not suitable for web applications.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires msal as a runtime dependency; encryption support depends on platform-specific system libraries (DPAPI on Windows, Keychain on macOS, LibSecret on Linux).
  • Low install friction with a single pure-Python dependency (msal).
  • Maintenance status is aging—last release was 518 days ago, though the repository remains active with a recent commit on 2025-09-10.

License · maintenance · safety

MIT License (permissive) — MIT License permits commercial and private use with minimal restrictions; suitable for most projects.

last release 2025-03-14 (518 days) · last repo commit 2025-09-10 · 45 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 166,408,976 downloads/mo, #251 on PyPI

Verify before relying

pip install msal-extensions

from msal_extensions import PersistedTokenCache, FilePersistence
import msal

persistence = FilePersistence("token_cache.bin")
cache = PersistedTokenCache(persistence)
app = msal.PublicClientApplication("client_id", token_cache=cache)
  • Whether LibSecret, Keychain, or DPAPI are automatically available or require separate installation on each platform.
  • Performance characteristics when used with high-frequency token access patterns.
  • Compatibility with msal versions beyond what the fact sheet specifies.
Same gist for agents: .md · .json

What it is and what it does

msal-extensions extends the Microsoft Authentication Library for Python by adding secure, persistent token cache storage across Windows, macOS, and Linux. It wraps platform-native encryption (DPAPI, Keychain, LibSecret) to save authentication tokens to disk with automatic file locking and reload behavior, eliminating the need for developers to implement their own cross-platform persistence layer.

The library is designed for desktop and client applications that need to cache tokens between sessions. It provides a PersistedTokenCache class that integrates directly with MSAL's PublicClientApplication, and also offers a lower-level persistence API for storing arbitrary encrypted data. The documentation explicitly recommends it only for public client applications like desktop apps, not for web services where session-based caching is preferred.

Use it for

  • Desktop applications using Azure AD authentication that need to cache tokens securely across application restarts.
  • Cross-platform CLI tools requiring persistent authentication without re-prompting users on each invocation.
  • Client applications storing sensitive configuration or secrets alongside authentication tokens using the generic persistence API.
  • Fallback scenarios where encrypted storage is preferred but graceful degradation to plaintext is acceptable.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are building a desktop or client application with MSAL Python and need secure token persistence.

The library handles platform-specific encryption transparently and integrates seamlessly with msal. However, note that the last release was 518 days ago (aging maintenance), so verify that the current version meets your msal compatibility requirements. Not suitable for web applications.

Install

msal-extensions on PyPI

Before you install

Low install friction with a single pure-Python dependency (msal). Maintenance status is aging—last release was 518 days ago, though the repository remains active with a recent commit on 2025-09-10.

Requires msal as a runtime dependency; encryption support depends on platform-specific system libraries (DPAPI on Windows, Keychain on macOS, LibSecret on Linux).

License in practice

MIT License permits commercial and private use with minimal restrictions; suitable for most projects.

Quickstart

pip install msal-extensions

from msal_extensions import PersistedTokenCache, FilePersistence
import msal

persistence = FilePersistence("token_cache.bin")
cache = PersistedTokenCache(persistence)
app = msal.PublicClientApplication("client_id", token_cache=cache)

Verify before relying

  • Whether LibSecret, Keychain, or DPAPI are automatically available or require separate installation on each platform.
  • Performance characteristics when used with high-frequency token access patterns.
  • Compatibility with msal versions beyond what the fact sheet specifies.

Package facts

LicenseMIT License permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
msal
MaintenanceAging 518 days since the last release
Last repo commit
First released
Downloads166,408,976 / month, #251 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: msal_extensions-1.3.1-py3-none-any.whl

Tags

Capabilities
msal token cache persistenceencrypted token storage pythonazure authentication cachecross-platform credential storagemsal extensions
Topics
azure-authtoken-cachecredential-storage

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “msal token cache persistence”

  • msal-extensionsProvides secure, platform-specific token cache persistence for MSAL…
  • msalMSAL for Python handles OAuth2 and OpenID Connect authentication with…
  • identityProvides a high-level authentication and authorization API for Python…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also msal · adal · microsoft-kiota-authentication-azure · azure-mgmt-core · identity · microsoft-agents-authentication-msal · streamlit-msal · keyring · redis-entraid · azure-identity-broker