$npx skillfedfor your agent

pyspnego

Windows Negotiate Authentication Client and Server

Worth itPyPI CryptographyReleased Mar 202623.1M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pyspnego-0.12.1-py3-none-any.whl
v0.12.1 · released 2026-03-02 · Python >=3.9 · 2 runtime deps: cryptography, sspilib

Yes. pyspnego is actively maintained, carries no known vulnerabilities, has low install friction, and is the primary Python library for SPNEGO/NTLM/Kerberos authentication. Install it if you need to authenticate against Windows domains or Kerberos realms. Be aware that acceptor (server-side) NTLM authentication is less thoroughly tested than GSSAPI implementations, and Kerberos on Linux requires optional system and Python packages.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • CPython 3.9+; sspilib is Windows-only; Kerberos support on Linux requires system packages (libkrb5-dev or equivalent) and optional python-gssapi/pykrb5.
  • Low friction: pure Python wheel with only two runtime dependencies (cryptography and sspilib).
  • Actively maintained with recent commits; last release 165 days ago.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution in both open-source and commercial contexts with minimal obligations.

last release 2026-03-02 (165 days) · last repo commit 2026-08-04 · 66 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 23,143,044 downloads/mo, #956 on PyPI

Verify before relying

pip install pyspnego

from pyspnego.client import Client

client = Client(username='user', password='pass', hostname='target')
token = client.get_token()
  • Whether acceptor (server-side) NTLM authentication is production-ready given the stated caveat about testing coverage.
  • Whether optional dependencies (python-gssapi, pykrb5, ruamel.yaml) are automatically installed or require explicit extras specification.
Same gist for agents: .md · .json

What it is and what it does

pyspnego is a Python library for implementing SPNEGO (Negotiate), NTLM, Kerberos, and CredSSP authentication on Windows and Linux. It provides both client and server authentication flows, allowing applications to authenticate against Windows domains and Kerberos realms. The library wraps system GSSAPI on Unix-like systems and SSPI on Windows, but also includes pure-Python implementations of NTLM and CredSSP for cases where system libraries are unavailable.

Beyond authentication, pyspnego includes a packet parser (pyspnego-parse) that decodes raw SPNEGO, NTLM, and Kerberos tokens into human-readable format for debugging and analysis. It depends on cryptography for cryptographic operations and sspilib (Windows only) for SSPI integration. Kerberos support on Linux requires optional system packages and Python libraries. The library is actively maintained, supports Python 3.9 through 3.14, and carries no known security vulnerabilities.

Use it for

  • Authenticate Python applications against Windows Active Directory domains using NTLM or Kerberos.
  • Implement server-side authentication to accept SPNEGO tokens from Windows clients in enterprise environments.
  • Debug SPNEGO/NTLM/Kerberos authentication failures by parsing and inspecting raw protocol tokens.
  • Build CredSSP clients for remote desktop or other CredSSP-based protocols.
  • Integrate Kerberos authentication into Linux applications without writing C bindings to system GSSAPI.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

pyspnego is actively maintained, carries no known vulnerabilities, has low install friction, and is the primary Python library for SPNEGO/NTLM/Kerberos authentication. Install it if you need to authenticate against Windows domains or Kerberos realms. Be aware that acceptor (server-side) NTLM authentication is less thoroughly tested than GSSAPI implementations, and Kerberos on Linux requires optional system and Python packages.

Install

pyspnego on PyPI

Before you install

Low friction: pure Python wheel with only two runtime dependencies (cryptography and sspilib). Actively maintained with recent commits; last release 165 days ago. Requires CPython 3.9+.

CPython 3.9+; sspilib is Windows-only; Kerberos support on Linux requires system packages (libkrb5-dev or equivalent) and optional python-gssapi/pykrb5.

License in practice

MIT license permits unrestricted use, modification, and distribution in both open-source and commercial contexts with minimal obligations.

Quickstart

pip install pyspnego

from pyspnego.client import Client

client = Client(username='user', password='pass', hostname='target')
token = client.get_token()

Verify before relying

  • Whether acceptor (server-side) NTLM authentication is production-ready given the stated caveat about testing coverage.
  • Whether optional dependencies (python-gssapi, pykrb5, ruamel.yaml) are automatically installed or require explicit extras specification.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
cryptographysspilib
MaintenanceActively maintained 165 days since the last release
Last repo commit
First released
Downloads23,143,044 / month, #956 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9

Evidence: pyspnego-0.12.1-py3-none-any.whl

Tags

Capabilities
spnego ntlm kerberos authenticationwindows negotiate auth clientkerberos authentication pythonntlm token parsercredssp authenticationgssapi python wrapperspnego packet decoder
Topics
authenticationwindows-domainkerberos
PyPI keywords
windowsspnegonegotiatentlmkerberossspigssapiauth

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “spnego ntlm kerberos authentication”

  • pyspnegoHandles SPNEGO, NTLM, Kerberos, and CredSSP authentication protocols;…
  • requests-credsspAdds CredSSP authentication support to the requests library, enabling…
  • requests-gssapiAdds GSSAPI/Kerberos authentication support to the requests HTTP…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also requests-credssp · smbprotocol · requests-gssapi · gssapi · requests-negotiate-sspi · sspilib · ntlm-auth · requests-kerberos · krb5 · requests-ntlm