$npx skillfedfor your agent

scrypt

Bindings for the scrypt key derivation function library

With conditionsPyPI LibrariesReleased Aug 2025314.2K downloads / mo2-clause BSDPlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — scrypt-0.9.4-cp310-cp310-macosx_14_0_arm64.whl · scrypt-0.9.4-cp310-cp310-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl · scrypt-0.9.4-cp310-cp310-musllinux_1_2_x86_64.whl
v0.9.4 · released 2025-08-05

Yes, if you need scrypt specifically and can tolerate medium install friction (compiled extension + OpenSSL dependency). The package is stable, permissively licensed, and has no known vulnerabilities. However, consider whether argon2 or PBKDF2 alternatives better suit your threat model—scrypt's time-cost model is effective but less commonly recommended for new projects than memory-hard functions like argon2. Install only if scrypt is your deliberate choice, not a default.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires OpenSSL development headers (libssl-dev on Debian/Ubuntu, openssl-devel on Fedora/RHEL, or precompiled wheels on macOS/Windows).
  • Building from source on Windows requires OpenSSL installed to C:\OpenSSL-Win64 or C:\Program Files\OpenSSL.
  • Medium install friction due to compiled C extensions requiring OpenSSL development headers.

License · maintenance · safety

2-clause BSD (permissive) — Licensed under 2-clause BSD (permissive), allowing commercial and private use with minimal restrictions beyond attribution and liability disclaimers.

last release 2025-08-05 (374 days) · last repo commit 2025-09-30 · 33 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 314,155 downloads/mo, #7,706 on PyPI

Verify before relying

import scrypt
import os

# Encrypt random data with a password
hashed = scrypt.encrypt(os.urandom(64), 'password', maxtime=0.1)

# Decrypt and verify
original = scrypt.decrypt(hashed, 'password', maxtime=0.1)
  • Whether the package is actively maintained beyond the aging status signal (last commit 2025-09-30 is recent, but release cadence is sparse).
  • Performance characteristics and memory overhead compared to alternatives like argon2 or PBKDF2.
Same gist for agents: .md · .json

What it is and what it does

Scrypt is a Python wrapper around the scrypt key derivation function, a cryptographic algorithm designed specifically for password hashing. Unlike fast hash functions such as MD5 or SHA, scrypt allows you to specify a minimum time cost for encryption and decryption operations—typically 0.05 to 0.5 seconds per operation. This makes brute-force password attacks computationally expensive: a user won't notice the delay when signing in, but an attacker trying billions of passwords will face hours or days of computation.

The package exports two main functions: `encrypt()` to hash a password with a time cost, and `decrypt()` to verify a password against a stored hash. It has no runtime dependencies and ships with precompiled wheels for modern Python versions on common platforms, though building from source requires OpenSSL headers. The library is stable but aging, with infrequent releases and modest maintenance activity.

Use it for

  • Secure password storage in web applications where you want to enforce a minimum verification time (e.g., 0.1 seconds per login attempt).
  • Building a password verifier that rejects guesses that decrypt too quickly, indicating a wrong password or corrupted hash.
  • Protecting against credential stuffing by making each password check computationally expensive without requiring external services.
  • Legacy systems already using scrypt that need Python bindings to migrate or maintain existing password databases.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need scrypt specifically and can tolerate medium install friction (compiled extension + OpenSSL dependency).

The package is stable, permissively licensed, and has no known vulnerabilities. However, consider whether argon2 or PBKDF2 alternatives better suit your threat model—scrypt's time-cost model is effective but less commonly recommended for new projects than memory-hard functions like argon2. Install only if scrypt is your deliberate choice, not a default.

Install

scrypt on PyPI

Before you install

Medium install friction due to compiled C extensions requiring OpenSSL development headers. Precompiled wheels available for Python 3.10–3.14 on macOS (ARM64), Linux (x86_64, aarch64, musllinux), and Windows. Last release 374 days ago; repository active but maintenance status is aging.

Requires OpenSSL development headers (libssl-dev on Debian/Ubuntu, openssl-devel on Fedora/RHEL, or precompiled wheels on macOS/Windows). Building from source on Windows requires OpenSSL installed to C:\OpenSSL-Win64 or C:\Program Files\OpenSSL.

License in practice

Licensed under 2-clause BSD (permissive), allowing commercial and private use with minimal restrictions beyond attribution and liability disclaimers.

Quickstart

import scrypt
import os

# Encrypt random data with a password
hashed = scrypt.encrypt(os.urandom(64), 'password', maxtime=0.1)

# Decrypt and verify
original = scrypt.decrypt(hashed, 'password', maxtime=0.1)

Verify before relying

  • Whether the package is actively maintained beyond the aging status signal (last commit 2025-09-30 is recent, but release cadence is sparse).
  • Performance characteristics and memory overhead compared to alternatives like argon2 or PBKDF2.

Package facts

License2-clause BSD permissive
Python supportNot specified
Install frictionMedium. Platform-specific wheel
Runtime dependenciesNone
MaintenanceAging 374 days since the last release
Last repo commit
First released
Downloads314,155 / month, #7,706 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Topic :: Security :: CryptographyTopic :: Software Development :: Libraries

Evidence: scrypt-0.9.4-cp310-cp310-macosx_14_0_arm64.whl; scrypt-0.9.4-cp310-cp310-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; scrypt-0.9.4-cp310-cp310-musllinux_1_2_x86_64.whl; scrypt-0.9.4-cp310-cp310-win_amd64.whl; scrypt-0.9.4-cp311-cp311-macosx_14_0_arm64.whl; scrypt-0.9.4-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; scrypt-0.9.4-cp311-cp311-musllinux_1_2_x86_64.whl; scrypt-0.9.4-cp311-cp311-win_amd64.whl; scrypt-0.9.4-cp312-cp312-macosx_14_0_arm64.whl; scrypt-0.9.4-cp312-cp312-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl; scrypt-0.9.4-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; scrypt-0.9.4-cp312-cp312-musllinux_1_2_x86_64.whl; scrypt-0.9.4-cp312-cp312-win_amd64.whl; scrypt-0.9.4-cp313-cp313-macosx_14_0_arm64.whl; scrypt-0.9.4-cp313-cp313-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; scrypt-0.9.4-cp313-cp313-musllinux_1_2_x86_64.whl; scrypt-0.9.4-cp313-cp313-win_amd64.whl; scrypt-0.9.4-cp314-cp314-macosx_14_0_arm64.whl; scrypt-0.9.4-cp314-cp314-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; scrypt-0.9.4-cp314-cp314-musllinux_1_2_x86_64.whl

Tags

Capabilities
scrypt password hashingkey derivation functionpassword encryption pythonbrute force resistant hashingscrypt bindingstime-cost password verificationsecure password storage
Topics
password-hashingkey-derivationcompiled-extension

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “scrypt password hashing”

  • scryptPython bindings for the scrypt key derivation function, enabling…
  • pyscryptA pure-Python implementation of the scrypt password-based key…
  • pysodiumPysodium is a Python wrapper around libsodium that provides access to…

Give your agent the search over MCP, or paste the wish link into any chat.

More Libraries packages

urllib3 Worth it
PyPI · Libraries · released May 2026

urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.

MITpure Python · 3.10+
1.8Bdownloads / mo
requests Worth it
PyPI · Libraries · released May 2026

Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.

Apache-2.0pure Python · 3.10+
1.8Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
python-dateutil Worth it
PyPI · Libraries · released Mar 2024

Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.

Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.

Apache-2.0pure Python
1.2Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo
pytest Worth it
PyPI · Libraries · released Jun 2026

pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.

MITpure Python · 3.10+
1.1Bdownloads / mo

See also pyscrypt · pyrage · hkdf · altcha · kasa-crypt · python-gnupg · bcrypt · Flask-Bcrypt · PyNaCl · pwdlib