pyu2f
U2F host library for interacting with a U2F device over USB.
Decision gist · record as of 2026-08-14
No. The package is abandoned, its repository archived, and the maintainers explicitly recommend python-fido2 instead. U2F is an outdated FIDO spec. Install only if you must maintain legacy code already using pyu2f; for new projects, use python-fido2.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a U2F-compatible USB device connected to the system; SK_SIGNING_PLUGIN environment variable can optionally redirect signing to an external tool.
- High install friction due to source distribution only.
- Maintenance is abandoned as of 2020-10-30; the repository is archived and the maintainers recommend migrating to python-fido2 for FIDO2 support and ongoing security updates.
License · maintenance · safety
Apache 2.0 (permissive) — Apache 2.0 is permissive; you may use, modify, and distribute this code freely provided you retain license notices and do not hold the authors liable.
last release 2020-10-30 (2114 days) · last repo commit 2025-02-24 · 84 stars · archived
0 known vulnerabilities (OSV.dev, 2026-08-14) · 442,599 downloads/mo, #6,634 on PyPI
Alternatives
Verify before relying
from pyu2f import model
from pyu2f.convenience import authenticator
registered_key = model.RegisteredKey(b64_encoded_key)
challenge_data = [{'key': registered_key, 'challenge': raw_challenge_data}]
api = authenticator.CreateCompositeAuthenticator(origin)
response = api.Authenticate(app_id, challenge_data)- Whether the ctypes-based USB HID calls work reliably on modern versions of Windows, macOS, and Linux kernels.
- Current compatibility with modern U2F devices and whether deprecated U2F protocol support poses a security risk in production use.
What it is and what it does
pyu2f is a Python library for communicating with U2F (Universal 2nd Factor) security keys over USB. It uses ctypes to call system USB HID APIs directly, avoiding the need for platform-specific compiled libraries. The library implements a U2F stack for signing authentication challenges and supports pluggable authenticators via the SK_SIGNING_PLUGIN environment variable.
The package is no longer maintained; its repository is archived and the authors explicitly recommend migrating to python-fido2, which supports the newer FIDO2 standard and provides backward-compatible U2F support. U2F itself is considered an outdated FIDO specification. If you are starting a new project, this library should not be your first choice.
Use it for
- Authenticate users with legacy U2F security keys in existing Python applications on Windows, macOS, or Linux.
- Integrate U2F device support into a Python authentication system without requiring compiled platform-specific libraries.
- Offload U2F signing operations to an external command-line tool via the SK_SIGNING_PLUGIN mechanism.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is abandoned, its repository archived, and the maintainers explicitly recommend python-fido2 instead. U2F is an outdated FIDO spec. Install only if you must maintain legacy code already using pyu2f; for new projects, use python-fido2.
Install
pyu2f on PyPI
Before you install
High install friction due to source distribution only. Maintenance is abandoned as of 2020-10-30; the repository is archived and the maintainers recommend migrating to python-fido2 for FIDO2 support and ongoing security updates.
Requires a U2F-compatible USB device connected to the system; SK_SIGNING_PLUGIN environment variable can optionally redirect signing to an external tool.
License in practice
Apache 2.0 is permissive; you may use, modify, and distribute this code freely provided you retain license notices and do not hold the authors liable.
Quickstart
from pyu2f import model
from pyu2f.convenience import authenticator
registered_key = model.RegisteredKey(b64_encoded_key)
challenge_data = [{'key': registered_key, 'challenge': raw_challenge_data}]
api = authenticator.CreateCompositeAuthenticator(origin)
response = api.Authenticate(app_id, challenge_data)
Verify before relying
- Whether the ctypes-based USB HID calls work reliably on modern versions of Windows, macOS, and Linux kernels.
- Current compatibility with modern U2F devices and whether deprecated U2F protocol support poses a security risk in production use.
Package facts
| License | Apache 2.0 permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Abandoned 2,114 days since the last release |
| Last repo commit | repository archived |
| First released | |
| Downloads | 442,599 / month, #6,634 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.6Topic :: Software Development :: LibrariesTopic :: Software Development :: Libraries :: Python Modules |
Evidence: pyu2f-0.1.5.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “U2F authentication library”
- pyu2fpyu2f provides U2F (Universal 2nd Factor) device authentication over…
- fido2Implements FIDO2 and WebAuthn protocols for communicating with USB…
- google-reauthProvides two-factor authentication reauth support for Google's Python…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also fido2 · PyOTP · yubico-client · authy · django-allauth-2fa · pyusb · hidapi · django-otp · soft-webauthn · pycdlib