$npx skillfedfor your agent

nkeys

A public-key signature system based on Ed25519 for the NATS ecosystem.

With conditionsPyPI CryptographyReleased Sep 2024513.5K downloads / moApache 2 LicenseSource build

Decision gist · record as of 2026-08-14

sdist only — nkeys-0.2.1.tar.gz · builds from source
v0.2.1 · released 2024-09-11 · Python >=3.6 · 1 runtime deps: pynacl

Yes, if you are building or integrating with NATS systems that require Ed25519-based authentication. The package is actively maintained, has no known vulnerabilities, and supports modern Python versions. The main trade-off is high install friction due to pynacl's compilation requirement; verify that pre-built wheels are available for your platform before committing.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • pynacl dependency requires a C compiler and libsodium development headers to build from source.
  • High install friction due to pynacl dependency, which requires compilation.
  • Package is actively maintained with recent commits and broad Python version support from 3.6 onward.

License · maintenance · safety

Apache 2 License (permissive) — Apache 2.0 permissive license allows commercial and private use with minimal restrictions; you must retain license notices in distributions.

last release 2024-09-11 (702 days) · last repo commit 2026-03-31 · 19 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 513,505 downloads/mo, #6,246 on PyPI

Verify before relying

import nkeys
import os

with open('user.nkey', 'rb', buffering=0) as f:
  seed = bytearray(os.fstat(f.fileno()).st_size)
  f.readinto(seed)
  user = nkeys.from_seed(seed)

data = b'arGTKH8q7XDmgy0'
sig = user.sign(data)
user.verify(data, sig)
user.wipe()
  • Whether pynacl is available as a pre-built wheel for your platform, which would avoid compilation.
  • Performance characteristics when signing or verifying large volumes of data.
Same gist for agents: .md · .json

What it is and what it does

nkeys is a Python library that implements Ed25519-based public-key cryptography tailored for the NATS messaging ecosystem. It handles the generation, storage, and use of cryptographic key pairs for identity, authentication, and authorization of NATS entities like accounts, users, servers, and clusters. The library encodes raw 32- and 64-byte keys in a human-readable Base32 format with version prefixes (e.g., 'SU' for a user seed, 'U' for a user public key), making key material easier to work with than raw bytes.

The package wraps Ed25519 operations from pynacl and adds seed-based key derivation, signature generation and verification, and secure memory wiping. It is designed for scenarios where only the seed needs to be stored securely, since both public and private keys can be regenerated from it. The NATS system itself never stores private keys, instead using challenge-response authentication with the public key infrastructure that nkeys provides.

Use it for

  • Generate and manage Ed25519 key pairs for NATS server, cluster, account, and user authentication.
  • Sign data with a private key and verify signatures in NATS-based distributed systems.
  • Load cryptographic seeds from files and derive public/private key pairs for identity verification.
  • Securely wipe key material from memory after use to prevent accidental exposure of secrets.
  • Implement custom authentication flows in NATS clients that require Ed25519 signatures.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are building or integrating with NATS systems that require Ed25519-based authentication.

The package is actively maintained, has no known vulnerabilities, and supports modern Python versions. The main trade-off is high install friction due to pynacl's compilation requirement; verify that pre-built wheels are available for your platform before committing.

Install

nkeys on PyPI

Before you install

High install friction due to pynacl dependency, which requires compilation. Package is actively maintained with recent commits and broad Python version support from 3.6 onward.

pynacl dependency requires a C compiler and libsodium development headers to build from source.

License in practice

Apache 2.0 permissive license allows commercial and private use with minimal restrictions; you must retain license notices in distributions.

Quickstart

import nkeys
import os

with open('user.nkey', 'rb', buffering=0) as f:
  seed = bytearray(os.fstat(f.fileno()).st_size)
  f.readinto(seed)
  user = nkeys.from_seed(seed)

data = b'arGTKH8q7XDmgy0'
sig = user.sign(data)
user.verify(data, sig)
user.wipe()

Verify before relying

  • Whether pynacl is available as a pre-built wheel for your platform, which would avoid compilation.
  • Performance characteristics when signing or verifying large volumes of data.

Package facts

LicenseApache 2 License permissive
Python supportSupports the current Python release >=3.6
Install frictionHigh. Source build required
Runtime dependencies
1 package
pynacl
MaintenanceActively maintained 702 days since the last release
Last repo commit
First released
Downloads513,505 / month, #6,246 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Intended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPython

Evidence: nkeys-0.2.1.tar.gz

Tags

Capabilities
ed25519 key generationnats authentication keyspublic key signature systemcryptographic keypair managementnats ecosystem identityed25519 seed managementnkeys for nats
Topics
nats-ecosystemed25519key-management

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ed25519 key generation”

  • nkeysGenerates, manages, and verifies Ed25519-based cryptographic key…
  • slip10Implements SLIP-0010 hierarchical deterministic key derivation for…
  • ecdsaPure-Python implementation of ECDSA, EdDSA, and ECDH cryptographic…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also ed25519-blake2b-fork · slip10 · pure25519 · taktile-auth · bip-utils · eth-keys · signedjson · py-ed25519-zebra-bindings · bip32 · nats-py