pyOpenSSL
Python wrapper module around the OpenSSL library
Decision gist · record as of 2026-08-14
Yes, if you need TLS connections and are already using pyOpenSSL or require its specific connection API. No, if starting a new project—the maintainers recommend cryptography instead. The package is actively maintained, has no known vulnerabilities, and installs easily, but the documentation advises against new adoption for certificate and key operations.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; OpenSSL library must be available on the system.
- Low install friction with a pure-wheel distribution.
- Actively maintained with a recent release (13 days old) and active repository status.
License · maintenance · safety
Apache License, Version 2.0 (permissive) — Licensed under Apache License, Version 2.0 (permissive), allowing commercial and private use with minimal restrictions. No notable licensing constraints for typical adoption.
last release 2026-08-01 (13 days) · last repo commit 2026-08-06 · 944 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 294,217,086 downloads/mo, #140 on PyPI
Alternatives
Verify before relying
pip install pyopenssl
import pyopenssl
# Create SSL context and connection objects for TLS communication- Whether aws-lc can be used as a drop-in replacement for OpenSSL in all scenarios.
- Performance characteristics compared to cryptography's native TLS support for new projects.
- Specific use cases where pyOpenSSL remains preferable to cryptography beyond legacy TLS connections.
What it is and what it does
pyOpenSSL is a Python wrapper around OpenSSL that provides high-level SSL/TLS connection handling, certificate operations, and error handling mirroring OpenSSL's error codes. It wraps OpenSSL's functionality into Python-friendly objects for TLS communication, callbacks written in Python, and extensive error-handling mechanisms.
The package is mature and widely used, but its own documentation explicitly recommends using cryptography directly for new code unless you specifically need TLS connections. Recent versions have deprecated many certificate and key manipulation APIs in favor of cryptography's alternatives. It depends on cryptography and typing-extensions, supports Python 3.9 through 3.13, and runs on CPython and PyPy across macOS, Windows, and POSIX systems.
Use it for
- Establishing TLS connections in legacy Python applications already depending on this package's connection API.
- Wrapping raw sockets with SSL/TLS encryption when other approaches are not suitable.
- Handling OpenSSL-specific error codes and callbacks in applications requiring fine-grained SSL context control.
- Migrating older codebases using this package's certificate APIs before moving to cryptography.
- Applications requiring aws-lc as an OpenSSL alternative for compliance or performance reasons.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need TLS connections and are already using pyOpenSSL or require its specific connection API.
No, if starting a new project—the maintainers recommend cryptography instead. The package is actively maintained, has no known vulnerabilities, and installs easily, but the documentation advises against new adoption for certificate and key operations.
Install
pyopenssl on PyPI
Before you install
Low install friction with a pure-wheel distribution. Actively maintained with a recent release (13 days old) and active repository status. Two lightweight runtime dependencies: cryptography and typing-extensions.
Requires Python 3.9 or later; OpenSSL library must be available on the system.
License in practice
Licensed under Apache License, Version 2.0 (permissive), allowing commercial and private use with minimal restrictions. No notable licensing constraints for typical adoption.
Quickstart
pip install pyopenssl
import pyopenssl
# Create SSL context and connection objects for TLS communication
Verify before relying
- Whether aws-lc can be used as a drop-in replacement for OpenSSL in all scenarios.
- Performance characteristics compared to cryptography's native TLS support for new projects.
- Specific use cases where pyOpenSSL remains preferable to cryptography beyond legacy TLS connections.
Package facts
| License | Apache License, Version 2.0 permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagescryptographytyping-extensions |
| Maintenance | Actively maintained 13 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 294,217,086 / month, #140 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 6 - MatureIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Security :: CryptographyTopic :: Software Development :: Libraries :: Python ModulesTopic :: System :: Networking |
Evidence: pyopenssl-26.4.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “ssl tls connection wrapper”
- pyOpenSSLpyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing…
- secure-smtplibProvides secure SMTP subclasses with TLS/SSL certificate validation…
- urllib3urllib3 is an HTTP client library that provides thread-safe…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also backports.ssl · python3-dtls · ndg-httpsclient · service-identity · M2Crypto · nassl · openssl-ocsp-responder · sslpsk-pmd3 · tls-parser · awscrt