python-keystoneclient
Client Library for OpenStack Identity
Decision gist · record as of 2026-08-14
Yes, if you are building applications or tools that interact with OpenStack Keystone. The package is actively maintained, has low install friction, carries no known vulnerabilities, and is the standard client for this purpose. Not relevant for non-OpenStack environments.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; requires a running OpenStack Keystone service with network access.
- Low install friction with a pure-Python wheel distribution.
- Actively maintained with a recent release (168 days ago).
License · maintenance · safety
permissive license (permissive) — Licensed under Apache Software License (permissive), allowing use in commercial and proprietary projects with minimal restrictions.
last release 2026-02-27 (168 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,180,408 downloads/mo, #4,259 on PyPI
Alternatives
Verify before relying
pip install python-keystoneclient
from keystoneauth1.identity import v3
from keystoneauth1 import session
from keystoneclient.v3 import client
auth = v3.Password(auth_url="http://example.com:5000/v3",
username="admin", password="password",
project_name="admin", user_domain_id="default",
project_domain_id="default")
sess = session.Session(auth=auth)
keystone = client.Client(session=sess)
keystone.projects.list()- Whether keystoneauth1 is the recommended authentication path or if direct token-based auth is also supported.
- Performance characteristics when managing large numbers of projects or users.
- Compatibility with non-standard or custom Keystone deployments.
What it is and what it does
python-keystoneclient is the official Python client library for OpenStack's Keystone Identity service. It provides a programmatic interface to authenticate users, manage projects and users, handle tokens, and interact with the broader OpenStack Identity API. The library wraps HTTP calls to a Keystone server and exposes them as Python objects and methods, abstracting away the REST protocol details.
Typically used in OpenStack deployments to build automation tools, CLI applications, or services that need to authenticate against Keystone or perform identity management operations. It integrates with keystoneauth1 for flexible authentication strategies and relies on oslo libraries for configuration, serialization, and internationalization. The package is maintained by the OpenStack community and supports Python 3.10, 3.11, and 3.12.
Use it for
- Authenticate applications against an OpenStack Keystone service to obtain tokens for accessing other OpenStack APIs.
- Automate user and project provisioning in OpenStack environments programmatically.
- Build custom CLI tools or management scripts that interact with Keystone's identity and access control features.
- Integrate OpenStack identity operations into Python-based infrastructure-as-code or orchestration workflows.
- Query and manage project hierarchies, roles, and service catalogs in OpenStack deployments.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building applications or tools that interact with OpenStack Keystone.
The package is actively maintained, has low install friction, carries no known vulnerabilities, and is the standard client for this purpose. Not relevant for non-OpenStack environments.
Install
python-keystoneclient on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Actively maintained with a recent release (168 days ago). Depends on 10 runtime packages including keystoneauth1 for authentication and oslo libraries for configuration and serialization.
Requires Python 3.10 or later; requires a running OpenStack Keystone service with network access.
License in practice
Licensed under Apache Software License (permissive), allowing use in commercial and proprietary projects with minimal restrictions.
Quickstart
pip install python-keystoneclient
from keystoneauth1.identity import v3
from keystoneauth1 import session
from keystoneclient.v3 import client
auth = v3.Password(auth_url="http://example.com:5000/v3",
username="admin", password="password",
project_name="admin", user_domain_id="default",
project_domain_id="default")
sess = session.Session(auth=auth)
keystone = client.Client(session=sess)
keystone.projects.list()
Verify before relying
- Whether keystoneauth1 is the recommended authentication path or if direct token-based auth is also supported.
- Performance characteristics when managing large numbers of projects or users.
- Compatibility with non-standard or custom Keystone deployments.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 10 packagespbrdebtcollectorkeystoneauth1oslo.configoslo.i18noslo.serializationoslo.utilsrequestsstevedorepackaging |
| Maintenance | Actively maintained 168 days since the last release |
| First released | |
| Downloads | 1,180,408 / month, #4,259 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: OpenStackIntended Audience :: Information TechnologyIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12 |
Evidence: python_keystoneclient-5.8.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “openstack identity client”
- python-keystoneclientPython client library for authenticating with and managing OpenStack…
- keystoneauth1Provides authentication plugins, API discovery, and session…
- python-openstackclientA unified command-line client for OpenStack cloud infrastructure that…
Give your agent the search over MCP, or paste the wish link into any chat.
More Internet packages
Botocore provides low-level, data-driven access to Amazon Web Services APIs, serving as the foundation for the AWS CLI and boto3 libraries.
Install it if you need programmatic access to AWS services.
Provides an async client for AWS services using botocore and aiohttp, allowing you to call AWS APIs asynchronously within asyncio-based applications.
Install it if you need to call AWS services from async Python code; it is the standard way to do so.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides a platform-independent file locking mechanism to coordinate access to files across processes and threads.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides common Protocol Buffer message definitions used across Google Cloud APIs, enabling Python clients to interact with Google services.
See also keystone · python-barbicanclient · python-novaclient · keystoneauth1 · keystonemiddleware · python-neutronclient · python-ironicclient · python-heatclient · python-designateclient · stravalib