$npx skillfedfor your agent

pyscrypt

Pure-Python Implementation of the scrypt password-based key derivation function and scrypt file format library

SkipPyPI CryptographyReleased Feb 2015246.7K downloads / mopermissive licenseSource build

Decision gist · record as of 2026-08-14

sdist only — pyscrypt-1.6.2.tar.gz · builds from source
v1.6.2 · released 2015-02-03

No, unless you have a specific legacy dependency or educational need. The package is abandoned (last release 2015), explicitly slow by design, and the maintainer recommends C-wrappers for production use. For new projects, use a maintained scrypt library or bcrypt/argon2 instead. The lack of maintenance and known performance limitations make it unsuitable for most modern applications.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Python 3 requires password and salt as byte objects (b"..."), not strings.
  • ScryptFile mode must be 'rb' or 'wb'.
  • High install friction: the package is abandoned (last release 2015-02-03, last commit 2022-07-02) with no external dependencies but relies on pure Python, making it slow by design.

License · maintenance · safety

permissive license (permissive) — MIT license (permissive) means you can use, modify, and distribute this package freely in commercial and open-source projects with minimal restrictions, provided you include the license notice.

last release 2015-02-03 (4210 days) · last repo commit 2022-07-02 · 83 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 246,727 downloads/mo, #8,705 on PyPI

Verify before relying

import pyscrypt

# Hash a password
hashed = pyscrypt.hash(password=b"correct horse battery staple",
                       salt=b"seasalt",
                       N=1024, r=1, p=1, dkLen=32)

# Encrypt a file
with pyscrypt.ScryptFile('file.scrypt', b'password', 1024, 1, 1) as f:
    f.write(b"Hello World")
  • Whether the pure-Python implementation is suitable for your security requirements or if a C-wrapper is necessary for production.
  • Current compatibility with modern Python versions beyond the 2.x/3.x support stated in documentation.
  • Whether the reference implementation has been audited for cryptographic correctness.
Same gist for agents: .md · .json

What it is and what it does

pyscrypt is a pure-Python reference implementation of the scrypt password-based key derivation function (PBKDF). It provides two main capabilities: hashing passwords with configurable work factors (N, r, p parameters) to produce cryptographic keys, and reading/writing files encrypted with the scrypt file format. The package has no external dependencies and supports both Python 2 and 3, though it is intentionally slow—the documentation explicitly states it is 'not meant to be fast, more of a reference solution.' The scrypt algorithm itself is CPU and memory intensive by design, making brute-force password attacks computationally expensive.

The package includes a ScryptFile class for transparent file encryption/decryption and a hash function for key derivation. It comes with test cases that can be validated against the command-line scrypt utility. However, the project has been abandoned since 2015, with the maintainer noting that faster C-wrapper implementations exist for production use. For most real-world applications requiring scrypt, a maintained C-based library would be preferable.

Use it for

  • Hashing user passwords for authentication systems where you need a slow, memory-hard key derivation function.
  • Encrypting sensitive files using the scrypt file format for compatibility with the command-line scrypt utility.
  • Educational or reference purposes to understand how scrypt works without external C dependencies.
  • Legacy system maintenance where existing code depends on pyscrypt's pure-Python implementation.
  • Scenarios where you cannot use compiled C extensions and need scrypt functionality despite performance trade-offs.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No, unless you have a specific legacy dependency or educational need.

The package is abandoned (last release 2015), explicitly slow by design, and the maintainer recommends C-wrappers for production use. For new projects, use a maintained scrypt library or bcrypt/argon2 instead. The lack of maintenance and known performance limitations make it unsuitable for most modern applications.

Install

pyscrypt on PyPI

Before you install

High install friction: the package is abandoned (last release 2015-02-03, last commit 2022-07-02) with no external dependencies but relies on pure Python, making it slow by design. The maintainer explicitly notes it is 'not meant to be fast, more of a reference solution.' Consider a maintained C-wrapper alternative for production use.

Python 3 requires password and salt as byte objects (b"..."), not strings. ScryptFile mode must be 'rb' or 'wb'.

License in practice

MIT license (permissive) means you can use, modify, and distribute this package freely in commercial and open-source projects with minimal restrictions, provided you include the license notice.

Quickstart

import pyscrypt

# Hash a password
hashed = pyscrypt.hash(password=b"correct horse battery staple",
                       salt=b"seasalt",
                       N=1024, r=1, p=1, dkLen=32)

# Encrypt a file
with pyscrypt.ScryptFile('file.scrypt', b'password', 1024, 1, 1) as f:
    f.write(b"Hello World")

Verify before relying

  • Whether the pure-Python implementation is suitable for your security requirements or if a C-wrapper is necessary for production.
  • Current compatibility with modern Python versions beyond the 2.x/3.x support stated in documentation.
  • Whether the reference implementation has been audited for cryptographic correctness.

Package facts

Licensepermissive license permissive
Python supportNot specified
Install frictionHigh. Source build required
Runtime dependenciesNone
MaintenanceAbandoned 4,210 days since the last release
Last repo commit
First released
Downloads246,727 / month, #8,705 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 3Topic :: Security :: Cryptography

Evidence: pyscrypt-1.6.2.tar.gz

Tags

Capabilities
scrypt password hashingkey derivation function pythonpassword-based encryptionscrypt file encryptionpbkdf scrypt implementationpure python cryptographyscrypt file format
Topics
reference-implementationabandonedpure-python

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “scrypt file encryption”

  • pyscryptA pure-Python implementation of the scrypt password-based key…
  • scryptPython bindings for the scrypt key derivation function, enabling…
  • eth-keyfileLoads, creates, and decrypts Ethereum keyfiles—encrypted JSON files…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also hkdf · pyaes · scrypt · eth-keyfile · pyAesCrypt · pyDes · bcrypt · twofish · argon2-cffi · pysodium