pycryptodomex
Cryptographic library for Python
Decision gist · record as of 2026-08-14
Yes. PyCryptodomex is production-stable, actively maintained with no known vulnerabilities, and offers broad platform and Python version support with a permissive dual license. Install friction is moderate due to C compilation, but pre-built wheels cover most platforms. Use it when you need a self-contained cryptographic library without external dependencies.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- C extensions require a compiler toolchain on platforms without pre-built wheels.
- Medium install friction due to C extensions for performance-critical components.
- The package maintains active development with recent commits and broad wheel coverage across Python 2.7 through 3.13, indicating sustained maintenance.
License · maintenance · safety
BSD, Public Domain (permissive) — Dual-licensed under BSD and Public Domain with permissive treatment, allowing use in proprietary and open-source projects without significant restrictions.
last release 2025-05-17 (454 days) · last repo commit 2026-07-18 · 3,251 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 75,680,428 downloads/mo, #447 on PyPI
Alternatives
Verify before relying
pip install pycryptodomex
from pycryptodomex.Cipher import AES
from pycryptodomex.Random import get_random_bytes
key = get_random_bytes(32)
cipher = AES.new(key, AES.MODE_EAX)
ciphertext, tag = cipher.encrypt_and_digest(b'secret')- Whether all advertised features (HPKE, Shamir's Secret Sharing, deterministic ECDSA) are production-ready or experimental.
- Performance characteristics of pure-Python fallback implementations versus C-accelerated versions.
- Compatibility guarantees between pycryptodomex and the pycryptodome variant regarding API stability.
What it is and what it does
PyCryptodomex is a self-contained cryptographic library providing low-level primitives for symmetric encryption, hashing, digital signatures, and key derivation. It is a maintained fork of the dormant PyCrypto project, implementing algorithms in pure Python with C extensions only for performance-critical components like block ciphers. The package supports Python 2.7 and 3.7 onwards, including PyPy.
The library includes authenticated encryption modes (GCM, CCM, EAX, SIV, OCB, KW, KWP), elliptic curve support (NIST P-curves, Ed25519, Ed448, Curve25519), hash algorithms (SHA-3, BLAKE2), stream ciphers (Salsa20, ChaCha20), key derivation (scrypt, HKDF), and deterministic signature schemes. Random numbers are sourced directly from the operating system, and the API provides convenience features like automatic nonce generation and simplified CTR mode.
Use it for
- Encrypt and decrypt data using symmetric ciphers with authenticated modes to prevent tampering.
- Generate and verify digital signatures using RSA, DSA, or elliptic curve algorithms for authentication.
- Hash passwords and derive encryption keys using scrypt or HKDF for secure key management.
- Implement hybrid encryption combining public-key and symmetric algorithms for secure data exchange.
- Generate cryptographically secure random numbers and nonces for initialization vectors and salts.
- Perform elliptic curve operations for modern key exchange and signature schemes.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
PyCryptodomex is production-stable, actively maintained with no known vulnerabilities, and offers broad platform and Python version support with a permissive dual license. Install friction is moderate due to C compilation, but pre-built wheels cover most platforms. Use it when you need a self-contained cryptographic library without external dependencies.
Install
pycryptodomex on PyPI
Before you install
Medium install friction due to C extensions for performance-critical components. The package maintains active development with recent commits and broad wheel coverage across Python 2.7 through 3.13, indicating sustained maintenance.
C extensions require a compiler toolchain on platforms without pre-built wheels.
License in practice
Dual-licensed under BSD and Public Domain with permissive treatment, allowing use in proprietary and open-source projects without significant restrictions.
Quickstart
pip install pycryptodomex
from pycryptodomex.Cipher import AES
from pycryptodomex.Random import get_random_bytes
key = get_random_bytes(32)
cipher = AES.new(key, AES.MODE_EAX)
ciphertext, tag = cipher.encrypt_and_digest(b'secret')
Verify before relying
- Whether all advertised features (HPKE, Shamir's Secret Sharing, deterministic ECDSA) are production-ready or experimental.
- Performance characteristics of pure-Python fallback implementations versus C-accelerated versions.
- Compatibility guarantees between pycryptodomex and the pycryptodome variant regarding API stability.
Package facts
| License | BSD, Public Domain permissive |
| Python support | Supports the current Python release !=3.0.*,!=3.1.*,!=3.2.*,!=3.3.*,!=3.4.*,!=3.5.*,!=3.6.*,>=2.7 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 454 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 75,680,428 / month, #447 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseLicense :: Public DomainOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: UnixProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Security :: Cryptography |
Evidence: pycryptodomex-3.23.0-cp27-cp27m-macosx_10_9_x86_64.whl; pycryptodomex-3.23.0-cp27-cp27m-manylinux2010_i686.whl; pycryptodomex-3.23.0-cp27-cp27m-manylinux2010_x86_64.whl; pycryptodomex-3.23.0-cp27-cp27mu-manylinux2010_i686.whl; pycryptodomex-3.23.0-cp27-cp27mu-manylinux2010_x86_64.whl; pycryptodomex-3.23.0-cp27-cp27m-win32.whl; pycryptodomex-3.23.0-cp313-cp313t-macosx_10_13_universal2.whl; pycryptodomex-3.23.0-cp313-cp313t-macosx_10_13_x86_64.whl; pycryptodomex-3.23.0-cp313-cp313t-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; pycryptodomex-3.23.0-cp313-cp313t-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; pycryptodomex-3.23.0-cp313-cp313t-manylinux_2_5_i686.manylinux1_i686.manylinux_2_17_i686.manylinux2014_i686.whl; pycryptodomex-3.23.0-cp313-cp313t-musllinux_1_2_aarch64.whl; pycryptodomex-3.23.0-cp313-cp313t-musllinux_1_2_i686.whl; pycryptodomex-3.23.0-cp313-cp313t-musllinux_1_2_x86_64.whl; pycryptodomex-3.23.0-cp313-cp313t-win32.whl; pycryptodomex-3.23.0-cp313-cp313t-win_amd64.whl; pycryptodomex-3.23.0-cp313-cp313t-win_arm64.whl; pycryptodomex-3.23.0-cp37-abi3-macosx_10_9_universal2.whl; pycryptodomex-3.23.0-cp37-abi3-macosx_10_9_x86_64.whl; pycryptodomex-3.23.0-cp37-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “hash functions sha3 blake2”
- pycryptodomexPyCryptodomex provides low-level cryptographic primitives including…
- safe-pysha3Provides SHA-3, SHAKE, and Keccak hash functions for Python 3.9–3.13…
- pysha3Provides SHA-3, SHAKE, and Keccak hash functions for Python 2.7…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also pycrypto · unicrypto · pyhpke · py3rijndael · aes-pkcs5 · noiseprotocol · python-pkcs11 · pqcrypto · oscrypto