$npx skillfedfor your agent

pyseto

A Python implementation of PASETO/PASERK.

Worth itPyPI CryptographyReleased Jul 2026195.4K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pyseto-1.10.0-py3-none-any.whl
v1.10.0 · released 2026-07-19 · Python <4.0,>=3.10 · 4 runtime deps: argon2-cffi, cryptography, iso8601, pycryptodomex

Yes. PySETO is actively maintained, has no known vulnerabilities, uses permissive MIT licensing, and provides a complete, spec-compliant implementation of PASETO/PASERK with low install friction. Install it if you need stateless token authentication or secure key serialization and prefer a standards-based alternative to JWT or custom token schemes.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; PEM-formatted keys must be provided as bytes.
  • Low install friction with a pure-wheel distribution.
  • The package is actively maintained with a recent release (26 days old) and an active repository.

License · maintenance · safety

MIT (permissive) — MIT license permits commercial and private use with minimal restrictions; you may use, modify, and distribute this package freely as long as you include the license notice.

last release 2026-07-19 (26 days) · last repo commit 2026-08-13 · 112 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 195,383 downloads/mo, #9,816 on PyPI

Verify before relying

pip install pyseto

import pyseto
from pyseto import Key

private_key = Key.new(version=4, purpose="public", key=private_key_pem)
token = pyseto.encode(private_key, b'{"data": "message"}')

public_key = Key.new(version=4, purpose="public", key=public_key_pem)
decoded = pyseto.decode(public_key, token)
  • Whether the package has undergone independent security audit or formal verification of PASETO spec compliance beyond the official test vectors.
  • Performance characteristics (token generation/verification latency) under typical workloads.
Same gist for agents: .md · .json

What it is and what it does

PySETO is a complete Python implementation of the PASETO and PASERK standards, which define secure token formats for authentication and key serialization. It supports all four PASETO protocol versions (v1, v2, v3, v4) and both use cases: v*.public for asymmetric public-key signatures and v*.local for symmetric authenticated encryption. The package also implements PASERK, a standard for serializing and wrapping cryptographic keys, including password-based key encryption and key wrapping.

The library is built on top of cryptography, argon2-cffi, iso8601, and pycryptodomex, delegating the actual cryptographic operations to these battle-tested dependencies. It provides a simple API: create a Key object with a version and purpose, then call encode() to sign or encrypt a payload and decode() to verify and decrypt. The package has passed all official PASETO test vectors and supports both raw bytes and JSON serialization of payloads and footers.

Use it for

  • Generate and verify stateless authentication tokens for REST APIs or microservices using v4.public asymmetric signing.
  • Encrypt and authenticate session data or sensitive payloads using v4.local symmetric encryption without a database.
  • Serialize and store cryptographic keys securely using PASERK with password-based or key-wrapping protection.
  • Build multi-version token support for gradual protocol migration (e.g., from v2 to v4) across distributed systems.
  • Implement registered claims (exp, iat) and custom footers (e.g., key IDs) in tokens for standards-compliant authentication.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

PySETO is actively maintained, has no known vulnerabilities, uses permissive MIT licensing, and provides a complete, spec-compliant implementation of PASETO/PASERK with low install friction. Install it if you need stateless token authentication or secure key serialization and prefer a standards-based alternative to JWT or custom token schemes.

Install

pyseto on PyPI

Before you install

Low install friction with a pure-wheel distribution. The package is actively maintained with a recent release (26 days old) and an active repository. Dependencies on cryptography, argon2-cffi, iso8601, and pycryptodomex are all standard, well-maintained cryptographic libraries.

Requires Python 3.10 or later; PEM-formatted keys must be provided as bytes.

License in practice

MIT license permits commercial and private use with minimal restrictions; you may use, modify, and distribute this package freely as long as you include the license notice.

Quickstart

pip install pyseto

import pyseto
from pyseto import Key

private_key = Key.new(version=4, purpose="public", key=private_key_pem)
token = pyseto.encode(private_key, b'{"data": "message"}')

public_key = Key.new(version=4, purpose="public", key=public_key_pem)
decoded = pyseto.decode(public_key, token)

Verify before relying

  • Whether the package has undergone independent security audit or formal verification of PASETO spec compliance beyond the official test vectors.
  • Performance characteristics (token generation/verification latency) under typical workloads.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release <4.0,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
argon2-cfficryptographyiso8601pycryptodomex
MaintenanceActively maintained 26 days since the last release
Last repo commit
First released
Downloads195,383 / month, #9,816 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Typing :: Typed

Evidence: pyseto-1.10.0-py3-none-any.whl

Tags

Capabilities
paseto token implementationpaserk key serializationauthenticated encryption tokensplatform-agnostic security tokenspython cryptographic token librarypaseto v4 public localsymmetric and asymmetric token signing
Topics
cryptographyauthenticationtoken-signing

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “paseto token implementation”

  • pysetoPySETO implements PASETO (Platform-Agnostic SEcurity TOkens) and…
  • scitokensImplements the SciTokens JSON Web Token (JWT) format for generating,…
  • jwtEncodes and decodes JSON Web Tokens (JWTs) with signature…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also sslcrypto · josepy · pysequoia · jwskate · eth-keys · pqcrypto · starkbank-ecdsa · fernet · jose · python-jose