requests-credssp
HTTPS CredSSP authentication with the requests library.
Decision gist · record as of 2026-08-14
No—the package is abandoned (last release February 2022, last commit May 2023) with no active maintenance or security updates. While it has low install friction and permissive licensing, the lack of ongoing support poses a risk for production use, especially for security-sensitive authentication. Consider only if you are maintaining legacy code with no alternative and can accept the security and compatibility risks.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.6+.
- Kerberos support on Unix requires system Kerberos headers and python-gssapi; install with requests-credssp[kerberos].
- Low install friction with three straightforward dependencies.
License · maintenance · safety
MIT (permissive) — MIT license is permissive, allowing commercial and private use with minimal restrictions.
last release 2022-02-21 (1635 days) · last repo commit 2023-05-31 · 23 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 314,921 downloads/mo, #7,692 on PyPI
Alternatives
Verify before relying
pip install requests-credssp
import requests
from requests_credssp import HttpCredSSPAuth
credssp_auth = HttpCredSSPAuth('domain\\user', 'password')
r = requests.get('https://server:5986/wsman', auth=credssp_auth)- Whether the package remains compatible with current versions of cryptography, pyspnego, and requests given its abandoned status.
- Whether CredSSP protocol versions 5 and 6 (CVE-2018-0886 mitigations) remain secure against current threat models.
- Real-world compatibility with modern Windows Server versions and whether TLSv1.2 disabling is still necessary.
What it is and what it does
requests-credssp extends the requests library to authenticate against Windows servers using the CredSSP protocol, which combines TLS encryption with SPNEGO-negotiated credentials (NTLM or Kerberos). It enables double-hop authentication, allowing your credentials to be delegated to a remote server. The package supports CredSSP protocol versions 2 through 6 and provides message encryption via wrap/unwrap functions for secure token exchange.
Out of the box, it handles NTLM authentication on any platform. Kerberos support requires optional system dependencies and additional configuration on Unix-like systems. The library exposes configuration options for authentication mechanism selection, TLS version constraints, and minimum CredSSP protocol version enforcement—useful for working around compatibility issues with older Windows hosts or enforcing security patches.
Use it for
- Authenticate requests to WinRM endpoints on Windows servers using domain credentials.
- Build Python tools that interact with Windows-only APIs or services requiring CredSSP.
- Implement credential delegation for multi-hop scenarios where a server must forward credentials to another system.
- Encrypt messages sent over CredSSP-authenticated TLS channels for additional protocol-level security.
- Enforce minimum CredSSP protocol versions to reject unpatched servers vulnerable to CVE-2018-0886.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No—the package is abandoned (last release February 2022, last commit May 2023) with no active maintenance or security updates.
While it has low install friction and permissive licensing, the lack of ongoing support poses a risk for production use, especially for security-sensitive authentication. Consider only if you are maintaining legacy code with no alternative and can accept the security and compatibility risks.
Install
requests-credssp on PyPI
Before you install
Low install friction with three straightforward dependencies. However, the package is abandoned—last release was 2022-02-21 and last commit 2023-05-31—so no active maintenance or security updates are forthcoming.
Requires Python 3.6+. Kerberos support on Unix requires system Kerberos headers and python-gssapi; install with requests-credssp[kerberos].
License in practice
MIT license is permissive, allowing commercial and private use with minimal restrictions.
Quickstart
pip install requests-credssp
import requests
from requests_credssp import HttpCredSSPAuth
credssp_auth = HttpCredSSPAuth('domain\\user', 'password')
r = requests.get('https://server:5986/wsman', auth=credssp_auth)
Verify before relying
- Whether the package remains compatible with current versions of cryptography, pyspnego, and requests given its abandoned status.
- Whether CredSSP protocol versions 5 and 6 (CVE-2018-0886 mitigations) remain secure against current threat models.
- Real-world compatibility with modern Windows Server versions and whether TLSv1.2 disabling is still necessary.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagescryptographypyspnegorequests |
| Maintenance | Abandoned 1,635 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 314,921 / month, #7,692 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaLicense :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: requests_credssp-2.0.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “credssp authentication requests”
- requests-credsspAdds CredSSP authentication support to the requests library, enabling…
- pyspnegoHandles SPNEGO, NTLM, Kerberos, and CredSSP authentication protocols;…
- pywinrmpywinrm is a Python client for Windows Remote Management (WinRM) that…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also pyspnego · requests-negotiate-sspi · requests-gssapi · requests-kerberos · requests-ntlm · smbprotocol · pypsrp · gssapi · httpx-ntlm · msldap