requests-kerberos
A Kerberos authentication handler for python-requests
Decision gist · record as of 2026-08-14
Yes, if you need Kerberos authentication for HTTP requests in an enterprise environment. The package is stable and permissively licensed, but install friction is moderate on Linux (system libraries required) and maintenance is dormant—verify compatibility with your Kerberos infrastructure before relying on it for new projects. No known vulnerabilities as of the query date.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- On Linux: gcc, Python development headers, and libkrb5-dev (Debian) or krb5-devel (EL) must be installed before pip install.
- A valid Kerberos credential cache (via kinit) or explicit principal/password is required at runtime.
- Low install friction with a pure-Python wheel distribution.
License · maintenance · safety
ISC License (permissive) — ISC License is permissive and imposes minimal restrictions; you may use, modify, and redistribute this package freely in commercial or private projects with only attribution required.
last release 2024-06-03 (802 days) · last repo commit 2024-06-03 · 306 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,585,191 downloads/mo, #2,067 on PyPI
Alternatives
Verify before relying
pip install requests-kerberos
import requests
from requests_kerberos import HTTPKerberosAuth
r = requests.get("http://example.org", auth=HTTPKerberosAuth())- Current compatibility with modern Kerberos implementations and whether the 802-day gap since last release affects support for recent Kerberos protocol changes.
- Whether pyspnego dependency fully replaces or supplements the underlying Kerberos C library requirements on all platforms.
What it is and what it does
requests-kerberos is a handler that plugs Kerberos/GSSAPI authentication into the requests HTTP library. It allows you to make HTTP requests to Kerberos-protected servers (typically in enterprise Windows/Active Directory environments) by transparently handling the Kerberos authentication handshake. The package wraps requests' auth parameter and manages ticket acquisition, mutual authentication verification, and credential delegation.
You use it by instantiating HTTPKerberosAuth() and passing it to any requests method. It supports multiple authentication modes (REQUIRED, OPTIONAL, DISABLED mutual authentication), preemptive ticket presentation for persistent connections, hostname override for load-balanced services, explicit principal/password authentication, and credential delegation. The package depends on requests, cryptography, and pyspnego, and requires system-level Kerberos libraries on Linux.
Use it for
- Authenticate HTTP requests against Windows domain controllers or Kerberos-protected corporate APIs without embedding passwords in code.
- Automate WinRM or other Windows service interactions from Python scripts in Active Directory environments.
- Build integration tools that need to respect mutual authentication requirements from enterprise Kerberos realms.
- Delegate credentials to downstream services while maintaining audit trails in Kerberos-managed networks.
- Override hostname resolution for Kerberos authentication when connecting through load balancers or proxies with mismatched DNS names.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need Kerberos authentication for HTTP requests in an enterprise environment.
The package is stable and permissively licensed, but install friction is moderate on Linux (system libraries required) and maintenance is dormant—verify compatibility with your Kerberos infrastructure before relying on it for new projects. No known vulnerabilities as of the query date.
Install
requests-kerberos on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Dormant maintenance (last release 802 days ago) but no recent vulnerabilities; on Linux you must pre-install system Kerberos libraries (libkrb5-dev or krb5-devel) and Python development headers before installing this package.
On Linux: gcc, Python development headers, and libkrb5-dev (Debian) or krb5-devel (EL) must be installed before pip install. A valid Kerberos credential cache (via kinit) or explicit principal/password is required at runtime.
License in practice
ISC License is permissive and imposes minimal restrictions; you may use, modify, and redistribute this package freely in commercial or private projects with only attribution required.
Quickstart
pip install requests-kerberos
import requests
from requests_kerberos import HTTPKerberosAuth
r = requests.get("http://example.org", auth=HTTPKerberosAuth())
Verify before relying
- Current compatibility with modern Kerberos implementations and whether the 802-day gap since last release affects support for recent Kerberos protocol changes.
- Whether pyspnego dependency fully replaces or supplements the underlying Kerberos C library requirements on all platforms.
Package facts
| License | ISC License permissive |
| Python support | Supports the current Python release >=3.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesrequestscryptographypyspnego |
| Maintenance | Dormant 802 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 5,585,191 / month, #2,067 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: ISC License (ISCL) |
Evidence: requests_kerberos-0.15.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “kerberos authentication requests”
- requests-kerberosAdds Kerberos/GSSAPI authentication support to the requests HTTP…
- requests-gssapiAdds GSSAPI/Kerberos authentication support to the requests HTTP…
- requests-credsspAdds CredSSP authentication support to the requests library, enabling…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also minikerberos · requests-gssapi · requests-negotiate-sspi · requests-credssp · asyauth · pykerberos · winkerberos · kerberos · sspilib · k5test