python-barbicanclient
Client Library for OpenStack Barbican Key Management API
Decision gist · record as of 2026-08-14
Yes, if you are working with OpenStack Barbican. The package is actively maintained, has low install friction, carries a permissive license, and provides the standard client interface for Barbican's key management API. Install it only if you have a Barbican server running and need to manage encrypted secrets from Python; it is not useful outside an OpenStack environment.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a running Barbican server configured with Keystone middleware and valid OpenStack credentials (auth_url, username, password, project details).
- Low install friction with a pure Python wheel distribution.
- Active maintenance status with a release within the last 36 days.
License · maintenance · safety
permissive license (permissive) — Licensed under Apache Software License (permissive), meaning you can use, modify, and distribute this package freely with minimal restrictions, provided you include the license notice.
last release 2026-07-09 (36 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 322,412 downloads/mo, #7,611 on PyPI
Alternatives
Verify before relying
pip install python-barbicanclient
from keystoneauth1 import session
from keystoneauth1.identity import v3
from barbicanclient import client
auth = v3.Password(auth_url='http://localhost:5000/v3',
username='user', password='pass',
project_name='demo', user_domain_name='Default',
project_domain_name='Default')
sess = session.Session(auth=auth)
barbican = client.Client(session=sess)
secret = barbican.secrets.create(name='test', payload='data')
secret.store()- Whether the package supports Python 3.13+ beyond the stated 3.10, 3.11, 3.12 classifiers.
- Current state of the upstream Barbican project and whether this client is actively maintained alongside it.
What it is and what it does
python-barbicanclient is the official Python client for OpenStack Barbican, a key management service that encrypts and securely stores sensitive data in the cloud. It provides both a Python library (barbicanclient module) and a command-line tool (barbican command) for programmatic and interactive access to Barbican's API. The library handles authentication via Keystone, allowing you to create secrets, store them encrypted on the Barbican server, retrieve them later, and manage access control lists—all without handling raw encryption yourself.
The package is built on OpenStack's standard authentication and utility stack (keystoneauth1, oslo.* libraries, cliff for CLI scaffolding) and is designed for operators and developers working within OpenStack environments. It supports Python 3.10, 3.11, and 3.12, and is actively maintained as part of the broader OpenStack ecosystem.
Use it for
- Store API keys, database passwords, and certificates in Barbican from a Python application using Keystone authentication.
- Retrieve encrypted secrets programmatically at runtime without embedding credentials in code or configuration files.
- Manage secret access control and audit trails through the command-line tool in OpenStack deployment scripts.
- Integrate secret management into OpenStack-based infrastructure automation and orchestration workflows.
- Protect sensitive data in multi-tenant cloud environments where encryption and access isolation are required.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are working with OpenStack Barbican.
The package is actively maintained, has low install friction, carries a permissive license, and provides the standard client interface for Barbican's key management API. Install it only if you have a Barbican server running and need to manage encrypted secrets from Python; it is not useful outside an OpenStack environment.
Install
python-barbicanclient on PyPI
Before you install
Low install friction with a pure Python wheel distribution. Active maintenance status with a release within the last 36 days. Depends on well-established OpenStack libraries (keystoneauth1, cliff, oslo.* packages) and common utilities (pbr, requests).
Requires a running Barbican server configured with Keystone middleware and valid OpenStack credentials (auth_url, username, password, project details).
License in practice
Licensed under Apache Software License (permissive), meaning you can use, modify, and distribute this package freely with minimal restrictions, provided you include the license notice.
Quickstart
pip install python-barbicanclient
from keystoneauth1 import session
from keystoneauth1.identity import v3
from barbicanclient import client
auth = v3.Password(auth_url='http://localhost:5000/v3',
username='user', password='pass',
project_name='demo', user_domain_name='Default',
project_domain_name='Default')
sess = session.Session(auth=auth)
barbican = client.Client(session=sess)
secret = barbican.secrets.create(name='test', payload='data')
secret.store()
Verify before relying
- Whether the package supports Python 3.13+ beyond the stated 3.10, 3.11, 3.12 classifiers.
- Current state of the upstream Barbican project and whether this client is actively maintained alongside it.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 7 packagespbrrequestscliffkeystoneauth1oslo.i18noslo.serializationoslo.utils |
| Maintenance | Actively maintained 36 days since the last release |
| First released | |
| Downloads | 322,412 / month, #7,611 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: OpenStackIntended Audience :: Information TechnologyIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12 |
Evidence: python_barbicanclient-7.5.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “barbican secret storage api”
- python-barbicanclientPython client library and command-line tool for interacting with…
- castellanCastellan provides a unified interface for interacting with key…
- SecretStorageProvides Python bindings to the FreeDesktop.org Secret Service API…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also python-keystoneclient · python-cinderclient · castellan · python-troveclient · python-swiftclient · python-designateclient · python-heatclient · python-glanceclient · cerberus-python-client · py-consul