pip-api
An unofficial, importable pip API
Decision gist · record as of 2026-08-14
Yes. It is actively maintained, has no known vulnerabilities, installs with minimal friction, and solves a real problem—providing stable programmatic access to pip without depending on pip's unstable internals. Use it when you need to interact with pip from Python code rather than the command line.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires pip to be installed and available in the environment; functionality varies by pip version (some commands require pip>=8.0.0 or pip>=19.2).
- Low friction install with a single dependency on pip itself.
- Actively maintained with recent commits and a stable release cadence; last release was 2024-07-09 and the repository remains active.
License · maintenance · safety
permissive license (permissive) — Licensed under Apache License 2.0 (permissive), allowing free use, modification, and distribution with minimal restrictions.
last release 2024-07-09 (766 days) · last repo commit 2026-08-05 · 120 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 27,746,275 downloads/mo, #849 on PyPI
Alternatives
Verify before relying
pip install pip-api
import pip_api
version = pip_api.version()
installed = pip_api.installed_distributions()
requirements = pip_api.parse_requirements('requirements.txt')- Whether all advertised commands work reliably across the full range of supported pip versions in practice.
- Performance characteristics when querying large numbers of installed distributions.
What it is and what it does
pip-api is a wrapper around pip's command-line interface that exposes pip functionality as an importable Python library. Since pip itself does not provide an official, stable internal API, this package solves the problem of programmatically using pip from Python code without depending on pip's internal implementation details—which change frequently and break code that imports pip directly.
The library provides functions to retrieve the pip version, list installed distributions with metadata (name, version, location, editability), parse requirements files with full support for extras, specifiers, markers, and hashes, and compute file hashes using pip's algorithms. It wraps pip's CLI calls and internal APIs, raising an `Incompatible` exception when a requested command is not available in the installed pip version.
Use it for
- Audit tools like pip-audit that need to query installed packages and their versions to check for known vulnerabilities.
- Test frameworks that need to parse and validate requirements files against actual test dependencies.
- Build and packaging tools that need to compute file hashes for requirements pinning.
- Dependency analysis tools that need to list and inspect installed distributions programmatically.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
It is actively maintained, has no known vulnerabilities, installs with minimal friction, and solves a real problem—providing stable programmatic access to pip without depending on pip's unstable internals. Use it when you need to interact with pip from Python code rather than the command line.
Install
pip-api on PyPI
Before you install
Low friction install with a single dependency on pip itself. Actively maintained with recent commits and a stable release cadence; last release was 2024-07-09 and the repository remains active.
Requires pip to be installed and available in the environment; functionality varies by pip version (some commands require pip>=8.0.0 or pip>=19.2).
License in practice
Licensed under Apache License 2.0 (permissive), allowing free use, modification, and distribution with minimal restrictions.
Quickstart
pip install pip-api
import pip_api
version = pip_api.version()
installed = pip_api.installed_distributions()
requirements = pip_api.parse_requirements('requirements.txt')
Verify before relying
- Whether all advertised commands work reliably across the full range of supported pip versions in practice.
- Performance characteristics when querying large numbers of installed distributions.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagepip |
| Maintenance | Actively maintained 766 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 27,746,275 / month, #849 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: pip_api-0.0.34-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “pip programmatic api”
- pip-apiProvides an importable Python API that wraps pip's command-line…
- pipmasterProgrammatically ensures Python packages are installed and at correct…
- pypi-simpleA client library for querying PyPI and pip-compatible repositories…
Give your agent the search over MCP, or paste the wish link into any chat.
Similar packages
pip-audit scans Python environments and requirements files for packages with known vulnerabilities, using the Python Packaging Advisory Database and multiple vulnerability services.
Finds and downloads Python packages from package indexes by matching requirements, providing a stable library API for package discovery.
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Parses pip requirements files with the same correctness as pip itself, using pip's own parsing code extracted into a standalone, offline-capable library.
However, do not install if you require support for pip syntax changes after December 2022 or expect ongoing maintenance—the project is dormant and will not track…
Automates the process of adding cryptographic hashes to your requirements.txt file, enabling reproducible and verified package installations with pip's hash-checking mode.
Scans uv.lock, pylock.toml, and requirements.txt files for known vulnerabilities in PyPI dependencies by querying the PyPI API.
See also pyproject-api · requirementslib · requirements-parser · dparse