$npx skillfedfor your agent

signedjson

Sign JSON with Ed25519 signatures

SkipPyPI CryptographyReleased Mar 2022100.9K downloads / moPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — signedjson-1.1.4-py3-none-any.whl
v1.1.4 · released 2022-03-29 · 6 runtime deps: canonicaljson, unpaddedbase64, pynacl, typing, typing-extensions, importlib-metadata

No, not recommended for new projects. The package is abandoned (last release 2022-03-29) with no active maintenance, an unclear license, and unspecified Python version support. While it has low install friction and no known vulnerabilities, the lack of updates and missing license metadata create legal and maintenance risks. Consider a maintained alternative if you need JSON signing.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low install friction with a pure-Python wheel and modest dependencies.
  • However, the package is abandoned—last release was 2022-03-29, over 1599 days ago—so no active maintenance or security updates should be expected.

License · maintenance · safety

(unclear) — License treatment is unclear; the package metadata contains no license declaration. Before use in production or distribution, verify the actual license terms in the repository or source.

last release 2022-03-29 (1599 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 100,886 downloads/mo, #12,969 on PyPI

Verify before relying

pip install signedjson

from signedjson.key import generate_signing_key, get_verify_key
from signedjson.sign import sign_json, verify_signed_json

signing_key = generate_signing_key('zxcvb')
signed_json = sign_json({'my_key': 'my_data'}, 'Alice', signing_key)
verify_key = get_verify_key(signing_key)
verify_signed_json(signed_json, 'Alice', verify_key)
  • Whether the package's Python version support is truly unspecified or if there are implicit constraints from its dependencies.
  • The actual license under which signedjson is distributed, since metadata is absent.
  • Whether the abandoned status and lack of recent updates pose security or compatibility risks for current Python versions.
Same gist for agents: .md · .json

What it is and what it does

Signedjson is a library for cryptographically signing JSON objects using ED25519 signatures. It allows multiple entities to sign the same object, supports key rotation by permitting each entity to use multiple keys, and stores signatures in a standard format alongside optional unprotected metadata. The core workflow is to generate a signing key, sign a JSON object with an entity name, then verify the signature using the corresponding verification key.

The package depends on canonicaljson for deterministic JSON serialization, unpaddedbase64 for signature encoding, pynacl for cryptographic operations, and typing utilities. It is designed for scenarios where JSON data needs cryptographic authentication—such as federation protocols, message signing, or tamper detection—but it has been abandoned since 2022 with no active maintenance.

Use it for

  • Sign configuration or state objects in distributed systems where multiple parties need to verify authenticity.
  • Implement message signing in federation protocols or peer-to-peer systems using ED25519.
  • Add cryptographic proof-of-origin to JSON API responses or data exports.
  • Rotate signing keys without invalidating previously signed objects by supporting multiple key IDs per entity.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No, not recommended for new projects.

The package is abandoned (last release 2022-03-29) with no active maintenance, an unclear license, and unspecified Python version support. While it has low install friction and no known vulnerabilities, the lack of updates and missing license metadata create legal and maintenance risks. Consider a maintained alternative if you need JSON signing.

Install

signedjson on PyPI

Before you install

Low install friction with a pure-Python wheel and modest dependencies. However, the package is abandoned—last release was 2022-03-29, over 1599 days ago—so no active maintenance or security updates should be expected.

License in practice

License treatment is unclear; the package metadata contains no license declaration. Before use in production or distribution, verify the actual license terms in the repository or source.

Quickstart

pip install signedjson

from signedjson.key import generate_signing_key, get_verify_key
from signedjson.sign import sign_json, verify_signed_json

signing_key = generate_signing_key('zxcvb')
signed_json = sign_json({'my_key': 'my_data'}, 'Alice', signing_key)
verify_key = get_verify_key(signing_key)
verify_signed_json(signed_json, 'Alice', verify_key)

Verify before relying

  • Whether the package's Python version support is truly unspecified or if there are implicit constraints from its dependencies.
  • The actual license under which signedjson is distributed, since metadata is absent.
  • Whether the abandoned status and lack of recent updates pose security or compatibility risks for current Python versions.

Package facts

LicenseNot declared unclear
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
6 packages
canonicaljsonunpaddedbase64pynacltypingtyping-extensionsimportlib-metadata
MaintenanceAbandoned 1,599 days since the last release
First released
Downloads100,886 / month, #12,969 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: signedjson-1.1.4-py3-none-any.whl

Tags

Capabilities
json signing verificationed25519 signaturescryptographic jsonsign json objectsjson authenticationdigital signatures jsonkey rotation signing
Topics
ed25519json-signingabandoned
PyPI keywords
json

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “json signing verification”

  • signedjsonSigns and verifies JSON objects using ED25519 cryptographic…
  • jwskateImplements the JOSE family of IETF standards (JWS, JWK, JWA, JWT,…
  • python-joseImplements JOSE (JSON Object Signing and Encryption) standards to…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also ed25519-blake2b-fork · endesive · josepy · eth-account · pure25519 · nkeys · jcs · itsdangerous · securesystemslib · mastercard-oauth1-signer