python-tss-sdk
The Delinea Secret Server Python SDK
Decision gist · record as of 2026-08-14
Yes, if you use Delinea Secret Server or Platform and need a Python client to retrieve secrets. The library is straightforward, has low install friction, and carries no known vulnerabilities. However, maintenance is aging (284 days since last release), so verify compatibility with your Secret Server version and check for any API changes.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.8 or higher.
- Valid Secret Server or Platform credentials and network access to the server instance are required.
- Low install friction with a single pure-Python wheel dependency on requests.
License · maintenance · safety
permissive license (permissive) — Licensed under Apache Software License (permissive), allowing use in most commercial and open-source projects without significant legal constraints.
last release 2025-11-03 (284 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 450,293 downloads/mo, #6,592 on PyPI
Alternatives
Verify before relying
pip install python-tss-sdk
from python_tss_sdk import SecretServerCloud, PasswordGrantAuthorizer
authorizer = PasswordGrantAuthorizer("https://hostname/SecretServer", username, password)
secret_server = SecretServerCloud(tenant="mytenant", authorizer=authorizer)
secret = secret_server.get_secret(secret_id)- Whether the SDK handles token refresh automatically or requires manual re-authentication after expiry.
- Performance characteristics when retrieving large numbers of secrets or working with large payloads.
- Compatibility with recent Secret Server or Platform API versions beyond the last release date.
What it is and what it does
This SDK is a REST client that connects to Delinea Secret Server or Platform to fetch secrets programmatically. It abstracts away HTTP details and provides classes for authentication (password-based, domain-based, or token-based) and secret retrieval, returning secrets as JSON objects or dataclass instances. The library depends only on requests and supports Python 3.8 through 3.11.
You use it by instantiating an authorizer with your credentials, creating a client, and calling get_secret() with a secret ID or path. It handles OAuth2 token exchange internally and can work with self-signed certificates via the REQUESTS_CA_BUNDLE environment variable. The SDK has not been updated in 284 days, so verify compatibility with your Secret Server version.
Use it for
- Retrieve database credentials at application startup to connect to production databases securely.
- Fetch API keys or tokens within a CI/CD pipeline for deployment automation.
- Access domain credentials for Windows authentication in hybrid environments.
- Integrate as a centralized credential store for microservices running on Kubernetes.
- Query secret paths programmatically in compliance and audit workflows.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you use Delinea Secret Server or Platform and need a Python client to retrieve secrets.
The library is straightforward, has low install friction, and carries no known vulnerabilities. However, maintenance is aging (284 days since last release), so verify compatibility with your Secret Server version and check for any API changes.
Install
python-tss-sdk on PyPI
Before you install
Low install friction with a single pure-Python wheel dependency on requests. Maintenance status is aging—last release was 284 days ago—so updates may lag behind upstream changes.
Requires Python 3.8 or higher. Valid Secret Server or Platform credentials and network access to the server instance are required.
License in practice
Licensed under Apache Software License (permissive), allowing use in most commercial and open-source projects without significant legal constraints.
Quickstart
pip install python-tss-sdk
from python_tss_sdk import SecretServerCloud, PasswordGrantAuthorizer
authorizer = PasswordGrantAuthorizer("https://hostname/SecretServer", username, password)
secret_server = SecretServerCloud(tenant="mytenant", authorizer=authorizer)
secret = secret_server.get_secret(secret_id)
Verify before relying
- Whether the SDK handles token refresh automatically or requires manual re-authentication after expiry.
- Performance characteristics when retrieving large numbers of secrets or working with large payloads.
- Compatibility with recent Secret Server or Platform API versions beyond the last release date.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagerequests |
| Maintenance | Aging 284 days since the last release |
| First released | |
| Downloads | 450,293 / month, #6,592 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: python_tss_sdk-2.0.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “secret server python client”
- python-tss-sdkA Python client library for retrieving secrets from Delinea Secret…
- python-barbicanclientPython client library and command-line tool for interacting with…
- onepasswordconnectsdkProvides Python access to 1Password vaults through a self-hosted…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also onepassword · bitwarden-sdk · onepassword-sdk · azure-keyvault-secrets · looker-sdk · azure-keyvault-certificates · robocorp-vault · oauth2-client · onepasswordconnectsdk · infisicalsdk