SecretStorage
Python bindings to FreeDesktop.org Secret Service API
Decision gist · record as of 2026-08-14
Yes, if you are building Python applications on Linux/POSIX systems that need to store credentials securely. The library is stable, has no known vulnerabilities, and integrates cleanly with widely-used system keyrings. Not suitable for Windows or macOS without additional setup, and requires a running Secret Service daemon and D-Bus session.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a running D-Bus session and Secret Service daemon (e.g., GNOME Keyring); will fail on Windows/macOS or headless systems without D-Bus.
- Python >= 3.10 required.
- Low friction installation with two straightforward dependencies (cryptography and jeepney).
License · maintenance · safety
BSD-3-Clause (permissive) — BSD-3-Clause (permissive) license allows use in most projects without significant restrictions, though you should review the full license text if incorporating into proprietary software.
last release 2025-11-23 (264 days) · last repo commit 2026-01-31 · 145 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 226,889,415 downloads/mo, #182 on PyPI
Alternatives
Verify before relying
pip install secretstorage
import secretstorage
# Open the default collection
collection = secretstorage.get_default_collection()
# Store a secret
collection.create_item('my-password', b'secret-value', {'app': 'myapp'})
# Retrieve a secret
items = collection.search_items({'app': 'myapp'})
for item in items:
print(item.get_secret())- Whether the package works reliably with all three supported backends (GNOME Keyring, KWallet 5.97+, KeePassXC) in current versions
- Performance characteristics when storing or retrieving large numbers of secrets
- Whether D-Bus session availability is a hard requirement or gracefully degrades on headless systems
What it is and what it does
SecretStorage is a Python library that wraps the FreeDesktop.org Secret Service API, allowing your code to store and retrieve passwords and other secrets through the system's native credential management services. It works with GNOME Keyring, KWallet, and KeePassXC, providing a unified interface to create, edit, and delete secret items organized into collections. The library handles the D-Bus communication and cryptographic operations needed to interact with these services securely.
You would use this when you need your Python application to store sensitive data (API keys, database passwords, OAuth tokens) in the user's system keyring rather than in plaintext config files or environment variables. It requires Python 3.10 or later and depends on cryptography for encryption and jeepney for D-Bus communication. The package is stable and actively maintained, though it is Linux/POSIX-focused and requires a running Secret Service daemon.
Use it for
- Store API credentials in GNOME Keyring so a Python CLI tool can retrieve them securely without hardcoding
- Build a password manager or credential sync tool that integrates with the system's native secret storage
- Manage OAuth tokens in KWallet for a desktop application that needs to authenticate with external services
- Organize application secrets into collections for better credential lifecycle management
- Retrieve stored secrets programmatically in a headless service that has D-Bus access to a keyring daemon
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building Python applications on Linux/POSIX systems that need to store credentials securely.
The library is stable, has no known vulnerabilities, and integrates cleanly with widely-used system keyrings. Not suitable for Windows or macOS without additional setup, and requires a running Secret Service daemon and D-Bus session.
Install
secretstorage on PyPI
Before you install
Low friction installation with two straightforward dependencies (cryptography and jeepney). Package is in production/stable status with recent activity (last commit 2026-01-31) and no known vulnerabilities, though maintenance is aging.
Requires a running D-Bus session and Secret Service daemon (e.g., GNOME Keyring); will fail on Windows/macOS or headless systems without D-Bus. Python >= 3.10 required.
License in practice
BSD-3-Clause (permissive) license allows use in most projects without significant restrictions, though you should review the full license text if incorporating into proprietary software.
Quickstart
pip install secretstorage
import secretstorage
# Open the default collection
collection = secretstorage.get_default_collection()
# Store a secret
collection.create_item('my-password', b'secret-value', {'app': 'myapp'})
# Retrieve a secret
items = collection.search_items({'app': 'myapp'})
for item in items:
print(item.get_secret())
Verify before relying
- Whether the package works reliably with all three supported backends (GNOME Keyring, KWallet 5.97+, KeePassXC) in current versions
- Performance characteristics when storing or retrieving large numbers of secrets
- Whether D-Bus session availability is a hard requirement or gracefully degrades on headless systems
Package facts
| License | BSD-3-Clause permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagescryptographyjeepney |
| Maintenance | Aging 264 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 226,889,415 / month, #182 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableOperating System :: POSIXProgramming Language :: PythonProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: SecurityTopic :: Software Development :: Libraries :: Python Modules |
Evidence: secretstorage-3.5.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “secret service api python”
- SecretStorageProvides Python bindings to the FreeDesktop.org Secret Service API…
- onepassword-sdkProgrammatic Python interface to read and manage secrets, items, and…
- google-cloud-secret-managerPython client library for Google Cloud Secret Manager, enabling…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also keyring · keyrings.cryptfile · azure-keyvault-secrets · google-cloud-secret-manager · keyrings.alt · onepassword-sdk · credstash · robocorp-vault · aws-encryption-sdk · pqcrypto