pyspnego
Windows Negotiate Authentication Client and Server
Decision gist · record as of 2026-08-14
Yes. pyspnego is actively maintained, carries no known vulnerabilities, has low install friction, and is the primary Python library for SPNEGO/NTLM/Kerberos authentication. Install it if you need to authenticate against Windows domains or Kerberos realms. Be aware that acceptor (server-side) NTLM authentication is less thoroughly tested than GSSAPI implementations, and Kerberos on Linux requires optional system and Python packages.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- CPython 3.9+; sspilib is Windows-only; Kerberos support on Linux requires system packages (libkrb5-dev or equivalent) and optional python-gssapi/pykrb5.
- Low friction: pure Python wheel with only two runtime dependencies (cryptography and sspilib).
- Actively maintained with recent commits; last release 165 days ago.
License · maintenance · safety
MIT (permissive) — MIT license permits unrestricted use, modification, and distribution in both open-source and commercial contexts with minimal obligations.
last release 2026-03-02 (165 days) · last repo commit 2026-08-04 · 66 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 23,143,044 downloads/mo, #956 on PyPI
Alternatives
Verify before relying
pip install pyspnego
from pyspnego.client import Client
client = Client(username='user', password='pass', hostname='target')
token = client.get_token()- Whether acceptor (server-side) NTLM authentication is production-ready given the stated caveat about testing coverage.
- Whether optional dependencies (python-gssapi, pykrb5, ruamel.yaml) are automatically installed or require explicit extras specification.
What it is and what it does
pyspnego is a Python library for implementing SPNEGO (Negotiate), NTLM, Kerberos, and CredSSP authentication on Windows and Linux. It provides both client and server authentication flows, allowing applications to authenticate against Windows domains and Kerberos realms. The library wraps system GSSAPI on Unix-like systems and SSPI on Windows, but also includes pure-Python implementations of NTLM and CredSSP for cases where system libraries are unavailable.
Beyond authentication, pyspnego includes a packet parser (pyspnego-parse) that decodes raw SPNEGO, NTLM, and Kerberos tokens into human-readable format for debugging and analysis. It depends on cryptography for cryptographic operations and sspilib (Windows only) for SSPI integration. Kerberos support on Linux requires optional system packages and Python libraries. The library is actively maintained, supports Python 3.9 through 3.14, and carries no known security vulnerabilities.
Use it for
- Authenticate Python applications against Windows Active Directory domains using NTLM or Kerberos.
- Implement server-side authentication to accept SPNEGO tokens from Windows clients in enterprise environments.
- Debug SPNEGO/NTLM/Kerberos authentication failures by parsing and inspecting raw protocol tokens.
- Build CredSSP clients for remote desktop or other CredSSP-based protocols.
- Integrate Kerberos authentication into Linux applications without writing C bindings to system GSSAPI.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
pyspnego is actively maintained, carries no known vulnerabilities, has low install friction, and is the primary Python library for SPNEGO/NTLM/Kerberos authentication. Install it if you need to authenticate against Windows domains or Kerberos realms. Be aware that acceptor (server-side) NTLM authentication is less thoroughly tested than GSSAPI implementations, and Kerberos on Linux requires optional system and Python packages.
Install
pyspnego on PyPI
Before you install
Low friction: pure Python wheel with only two runtime dependencies (cryptography and sspilib). Actively maintained with recent commits; last release 165 days ago. Requires CPython 3.9+.
CPython 3.9+; sspilib is Windows-only; Kerberos support on Linux requires system packages (libkrb5-dev or equivalent) and optional python-gssapi/pykrb5.
License in practice
MIT license permits unrestricted use, modification, and distribution in both open-source and commercial contexts with minimal obligations.
Quickstart
pip install pyspnego
from pyspnego.client import Client
client = Client(username='user', password='pass', hostname='target')
token = client.get_token()
Verify before relying
- Whether acceptor (server-side) NTLM authentication is production-ready given the stated caveat about testing coverage.
- Whether optional dependencies (python-gssapi, pykrb5, ruamel.yaml) are automatically installed or require explicit extras specification.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagescryptographysspilib |
| Maintenance | Actively maintained 165 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 23,143,044 / month, #956 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9 |
Evidence: pyspnego-0.12.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “spnego ntlm kerberos authentication”
- pyspnegoHandles SPNEGO, NTLM, Kerberos, and CredSSP authentication protocols;…
- requests-credsspAdds CredSSP authentication support to the requests library, enabling…
- requests-gssapiAdds GSSAPI/Kerberos authentication support to the requests HTTP…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also requests-credssp · smbprotocol · requests-gssapi · gssapi · requests-negotiate-sspi · sspilib · ntlm-auth · requests-kerberos · krb5 · requests-ntlm