PyNaCl
Python binding to the Networking and Cryptography (NaCl) library
Decision gist · record as of 2026-08-14
Yes. PyNaCl is actively maintained, widely used (position 161 on PyPI), has no known vulnerabilities, and ships with prebuilt wheels for most platforms. The permissive Apache-2.0 license poses no restrictions. Medium install friction is acceptable given the compiled dependency is bundled and wheels are available; use it for any application requiring modern cryptographic primitives.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires cffi runtime dependency; on Linux source builds may need libsodium development headers or SODIUM_INSTALL environment variable configuration.
- Medium install friction due to compiled C dependencies via cffi, but mitigated by prebuilt wheels across macOS, Windows, and Linux platforms.
- Actively maintained with last commit 2026-07-30.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows use in commercial and proprietary projects with minimal restrictions; attribution required but no copyleft obligations.
last release 2026-01-01 (225 days) · last repo commit 2026-07-30 · 1,204 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 246,596,488 downloads/mo, #161 on PyPI
Alternatives
Verify before relying
pip install pynacl
import pynacl
from pynacl.public import PrivateKey
sk = PrivateKey.generate()- Whether bundled libsodium 1.0.20-stable resolves CVE-2025-69277 completely or if additional mitigations are needed.
- Performance characteristics of AEAD AES low-level bindings relative to alternatives.
- Specific use-case examples for free-threaded Python 3.14 support added in 1.6.0.
What it is and what it does
PyNaCl is a Python wrapper around libsodium, a C cryptography library designed for usability and security. It exposes high-level and low-level APIs for authenticated encryption, digital signatures, key exchange, password hashing, and random number generation. The package bundles libsodium by default, eliminating external system dependencies on most platforms; on Linux you can optionally link against your distribution's libsodium instead.
Typically used in applications that need to encrypt data at rest or in transit, sign messages, derive keys from passwords, or perform key exchange. The library handles nonce generation automatically in many cases and provides both simple high-level constructions and lower-level bindings for advanced use cases. Supports Python 3.8 and later, including free-threaded Python 3.14.
Use it for
- Encrypt and decrypt messages between parties using public-key encryption.
- Hash and verify passwords securely using argon2i, argon2id, or scrypt with automatic salt handling.
- Sign and verify data authenticity with Ed25519 digital signatures.
- Perform authenticated encryption with associated data using ChaCha20-Poly1305 or AES-GCM.
- Generate cryptographically secure random nonces and keys for encryption operations.
- Derive encryption keys from passwords using password-based key derivation functions.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
PyNaCl is actively maintained, widely used (position 161 on PyPI), has no known vulnerabilities, and ships with prebuilt wheels for most platforms. The permissive Apache-2.0 license poses no restrictions. Medium install friction is acceptable given the compiled dependency is bundled and wheels are available; use it for any application requiring modern cryptographic primitives.
Install
pynacl on PyPI
Before you install
Medium install friction due to compiled C dependencies via cffi, but mitigated by prebuilt wheels across macOS, Windows, and Linux platforms. Actively maintained with last commit 2026-07-30.
Requires cffi runtime dependency; on Linux source builds may need libsodium development headers or SODIUM_INSTALL environment variable configuration.
License in practice
Apache-2.0 permissive license allows use in commercial and proprietary projects with minimal restrictions; attribution required but no copyleft obligations.
Quickstart
pip install pynacl
import pynacl
from pynacl.public import PrivateKey
sk = PrivateKey.generate()
Verify before relying
- Whether bundled libsodium 1.0.20-stable resolves CVE-2025-69277 completely or if additional mitigations are needed.
- Performance characteristics of AEAD AES low-level bindings relative to alternatives.
- Specific use-case examples for free-threaded Python 3.14 support added in 1.6.0.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 1 packagecffi |
| Maintenance | Actively maintained 225 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 246,596,488 / month, #161 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Free Threading :: 3 - StableProgramming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy |
Evidence: pynacl-1.6.2-cp314-cp314t-macosx_10_10_universal2.whl; pynacl-1.6.2-cp314-cp314t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; pynacl-1.6.2-cp314-cp314t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl; pynacl-1.6.2-cp314-cp314t-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; pynacl-1.6.2-cp314-cp314t-manylinux_2_26_x86_64.manylinux_2_28_x86_64.whl; pynacl-1.6.2-cp314-cp314t-manylinux_2_34_aarch64.whl; pynacl-1.6.2-cp314-cp314t-manylinux_2_34_x86_64.whl; pynacl-1.6.2-cp314-cp314t-musllinux_1_2_aarch64.whl; pynacl-1.6.2-cp314-cp314t-musllinux_1_2_x86_64.whl; pynacl-1.6.2-cp314-cp314t-win32.whl; pynacl-1.6.2-cp314-cp314t-win_amd64.whl; pynacl-1.6.2-cp314-cp314t-win_arm64.whl; pynacl-1.6.2-cp38-abi3-macosx_10_10_universal2.whl; pynacl-1.6.2-cp38-abi3-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; pynacl-1.6.2-cp38-abi3-manylinux2014_x86_64.manylinux_2_17_x86_64.whl; pynacl-1.6.2-cp38-abi3-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; pynacl-1.6.2-cp38-abi3-manylinux_2_26_x86_64.manylinux_2_28_x86_64.whl; pynacl-1.6.2-cp38-abi3-manylinux_2_34_aarch64.whl; pynacl-1.6.2-cp38-abi3-manylinux_2_34_x86_64.whl; pynacl-1.6.2-cp38-abi3-musllinux_1_2_aarch64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “digital signatures encryption”
- PyNaClPyNaCl provides Python bindings to libsodium for digital signatures,…
- tinkTink provides cryptographic APIs designed to be secure by default and…
- libnaclPython bindings to libsodium's NaCl cryptography library, providing…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
Keyring provides safe password and credential storage by interfacing with the system's native credential manager (macOS Keychain, Windows Credential Locker, Freedesktop Secret Service, or KDE KWallet).
Install it if your application needs to store or retrieve passwords securely without managing encryption yourself.
See also libnacl · pysodium · argon2-cffi-bindings · bcrypt · ed25519-blake2b-fork · pure25519 · scrypt · pyscrypt · securesystemslib