$npx skillfedfor your agent

pyhpke

A Python implementation of HPKE.

With conditionsPyPI CryptographyReleased Jul 2026309.5K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pyhpke-0.6.5-py3-none-any.whl
v0.6.5 · released 2026-07-16 · Python <4.0,>=3.10 · 1 runtime deps: cryptography

Yes, if you need RFC 9180 HPKE for non-critical applications or prototyping. The library is actively maintained, has low install friction, carries no known vulnerabilities, and uses a permissive MIT license. However, note that it has not been formally audited—do not use it for high-security applications without independent security review.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; recipient must have corresponding private key to decrypt.
  • Low install friction: pure Python wheel with a single runtime dependency on cryptography.
  • Active maintenance with a release 29 days ago and commits through August 2026.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) allows free use, modification, and distribution with minimal restrictions, suitable for both open-source and proprietary projects.

last release 2026-07-16 (29 days) · last repo commit 2026-08-11 · 13 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 309,516 downloads/mo, #7,754 on PyPI

Verify before relying

from pyhpke import AEADId, CipherSuite, KDFId, KEMId, KEMKey

suite = CipherSuite.new(
    KEMId.DHKEM_P256_HKDF_SHA256, KDFId.HKDF_SHA256, AEADId.AES128_GCM
)
enc, sender = suite.create_sender_context(public_key)
ct = sender.seal(b"message")
  • Whether formal security audit has been completed since the unaudited status noted in the description.
  • Real-world performance characteristics compared to alternative HPKE implementations.
Same gist for agents: .md · .json

What it is and what it does

PyHPKE is a Python library implementing the HPKE standard from RFC 9180, enabling secure message encryption between a sender and recipient using hybrid public-key cryptography. It supports all four HPKE modes (Base, PSK, Auth, AuthPSK) and provides multiple cipher suite combinations across key encapsulation mechanisms (DHKEM variants for P-256, P-384, P-521, X25519, X448), key derivation functions (HKDF-SHA256/384/512), and authenticated encryption algorithms (AES-GCM, ChaCha20Poly1305, Export Only).

The library wraps cryptographic operations from the cryptography package and exposes a straightforward API: create a cipher suite, load or derive keys from JWK or PEM formats, establish sender and recipient contexts, and seal or open messages. It has been tested against RFC 9180 official test vectors but has not undergone formal security audit, making it suitable for non-critical applications or as a reference implementation rather than as a drop-in replacement for audited production cryptography libraries.

Use it for

  • Encrypt messages for a known recipient when you have their public key and need authenticated encryption.
  • Implement end-to-end encryption in protocols or applications requiring RFC 9180 compliance.
  • Derive cryptographic keys from seed material using standardized key encapsulation and derivation functions.
  • Test HPKE cipher suite combinations and modes without external dependencies beyond cryptography.
  • Build multi-recipient encryption systems using HPKE's authenticated modes with pre-shared keys.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need RFC 9180 HPKE for non-critical applications or prototyping.

The library is actively maintained, has low install friction, carries no known vulnerabilities, and uses a permissive MIT license. However, note that it has not been formally audited—do not use it for high-security applications without independent security review.

Install

pyhpke on PyPI

Before you install

Low install friction: pure Python wheel with a single runtime dependency on cryptography. Active maintenance with a release 29 days ago and commits through August 2026.

Requires Python 3.10 or later; recipient must have corresponding private key to decrypt.

License in practice

MIT license (permissive) allows free use, modification, and distribution with minimal restrictions, suitable for both open-source and proprietary projects.

Quickstart

from pyhpke import AEADId, CipherSuite, KDFId, KEMId, KEMKey

suite = CipherSuite.new(
    KEMId.DHKEM_P256_HKDF_SHA256, KDFId.HKDF_SHA256, AEADId.AES128_GCM
)
enc, sender = suite.create_sender_context(public_key)
ct = sender.seal(b"message")

Verify before relying

  • Whether formal security audit has been completed since the unaudited status noted in the description.
  • Real-world performance characteristics compared to alternative HPKE implementations.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release <4.0,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
cryptography
MaintenanceActively maintained 29 days since the last release
Last repo commit
First released
Downloads309,516 / month, #7,754 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Typing :: Typed

Evidence: pyhpke-0.6.5-py3-none-any.whl

Tags

Capabilities
HPKE hybrid public key encryptionRFC 9180 implementationauthenticated encryption pythonpublic key encryption libraryelliptic curve key encapsulationAEAD cipher suitekey derivation function
Topics
cryptographypublic-key-encryptionrfc-9180

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “HPKE hybrid public key encryption”

  • pyhpkePyHPKE implements HPKE (Hybrid Public Key Encryption) as defined in…
  • eciespyEncrypts and decrypts data using Elliptic Curve Integrated Encryption…
  • PyNaClPyNaCl provides Python bindings to libsodium for digital signatures,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also py-ecc · eciespy · aes-pkcs5 · pycryptodomex · xxtea · jwskate · py3rijndael · pyDes · slip10