$npx skillfedfor your agent

scramp

An implementation of the SCRAM protocol.

Worth itPyPI CryptographyReleased Aug 202666.8M downloads / moMIT No AttributionPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — scramp-1.4.17-py3-none-any.whl
v1.4.17 · released 2026-08-07 · Python >=3.10 · 1 runtime deps: asn1crypto

Yes. Scramp is actively maintained, has no known vulnerabilities, installs cleanly with minimal dependencies, and is the standard Python implementation of SCRAM. Install it if you need to authenticate against a SCRAM-capable service or build SCRAM authentication into your application. The permissive MIT-0 license poses no restrictions.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Low install friction with a single runtime dependency (asn1crypto).
  • Active maintenance with a release 7 days ago.

License · maintenance · safety

MIT No Attribution (permissive) — MIT No Attribution (MIT-0) is a permissive license with minimal restrictions—you can use, modify, and distribute the package freely with no attribution requirement.

last release 2026-08-07 (7 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 66,810,516 downloads/mo, #483 on PyPI

Verify before relying

pip install scramp

from scramp import ScramClient

c = ScramClient(['SCRAM-SHA-256'], 'user', 'password')
cfirst = c.get_client_first()
# Send cfirst to server, receive server response, continue handshake
  • Whether the package handles all edge cases in SCRAM-SHA3-512 and channel binding flows reliably in production.
  • Performance characteristics when handling many concurrent authentication sessions.
  • Compatibility with specific SASL server implementations beyond the documented standards.
Same gist for agents: .md · .json

What it is and what it does

Scramp is a Python library that implements the Salted Challenge Response Authentication Mechanism (SCRAM), a family of SASL authentication protocols. It provides both client and server implementations, allowing you to authenticate users over untrusted channels without transmitting passwords in the clear. The library supports multiple hash algorithms (SHA-1, SHA-256, SHA-512, SHA3-512) and optional channel binding for additional security.

The package is designed for applications that need to integrate SCRAM authentication—such as database clients, messaging systems, or custom authentication services. You instantiate either a ScramClient or ScramServer, exchange protocol messages through a series of method calls, and the library handles the cryptographic operations and validation. It depends only on asn1crypto for ASN.1 encoding, keeping the dependency footprint minimal.

Use it for

  • Authenticate users to a database or message broker that requires SCRAM (e.g., MongoDB, RabbitMQ).
  • Build a custom authentication service that uses SCRAM for client-server credential exchange.
  • Implement SASL authentication in a custom protocol or application layer.
  • Add channel-binding-aware authentication to protect against man-in-the-middle attacks.
  • Test SCRAM server implementations by writing a client that exercises the protocol.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Scramp is actively maintained, has no known vulnerabilities, installs cleanly with minimal dependencies, and is the standard Python implementation of SCRAM. Install it if you need to authenticate against a SCRAM-capable service or build SCRAM authentication into your application. The permissive MIT-0 license poses no restrictions.

Install

scramp on PyPI

Before you install

Low install friction with a single runtime dependency (asn1crypto). Active maintenance with a release 7 days ago. Requires Python 3.10 or later.

Requires Python 3.10 or later.

License in practice

MIT No Attribution (MIT-0) is a permissive license with minimal restrictions—you can use, modify, and distribute the package freely with no attribution requirement.

Quickstart

pip install scramp

from scramp import ScramClient

c = ScramClient(['SCRAM-SHA-256'], 'user', 'password')
cfirst = c.get_client_first()
# Send cfirst to server, receive server response, continue handshake

Verify before relying

  • Whether the package handles all edge cases in SCRAM-SHA3-512 and channel binding flows reliably in production.
  • Performance characteristics when handling many concurrent authentication sessions.
  • Compatibility with specific SASL server implementations beyond the documented standards.

Package facts

LicenseMIT No Attribution permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
asn1crypto
MaintenanceActively maintained 7 days since the last release
First released
Downloads66,810,516 / month, #483 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT No Attribution License (MIT-0)Operating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: ImplementationProgramming Language :: Python :: Implementation :: CPython

Evidence: scramp-1.4.17-py3-none-any.whl

Tags

Capabilities
SCRAM authentication protocolSASL authentication Pythonchallenge response authenticationSCRAM-SHA-256 implementationclient server authenticationpassword authentication mechanismSCRAM channel binding
Topics
authenticationcryptographysasl
PyPI keywords
SASLSCRAMauthentication

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “SCRAM authentication protocol”

  • scrampScramp implements the SCRAM authentication protocol in Python,…
  • pg8000pg8000 is a pure-Python PostgreSQL driver that implements the DB-API…
  • pyradpyrad implements RADIUS client and server functionality per RFC2865,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also kerberos · pure-sasl · pykerberos · srptools · tlslite-ng · pyscrypt · python-binary-memcached · pysodium · gssapi · requests-negotiate-sspi