signxml
Python XML Signature and XAdES library
Decision gist · record as of 2026-08-14
Yes. SignXML is actively maintained, has no known vulnerabilities, low install friction, and implements a critical security standard for enterprise XML protocols. It is appropriate for production use in SAML, XAdES, EBICS, and WS-Security integrations where XML signature verification is required.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires lxml (libxml2-based XML parser) and valid X.509 certificate/key pair in PEM format; openssl needed to generate test certificates.
- Low friction: pure Python wheel with three stable, widely-used dependencies (lxml, cryptography, certifi).
- Active maintenance with a release 40 days ago and continuous integration.
License · maintenance · safety
Apache Software License (permissive) — Apache Software License (permissive): you can use, modify, and distribute signxml freely in commercial and private projects, with minimal restrictions beyond attribution.
last release 2026-07-05 (40 days) · last repo commit 2026-07-05 · 154 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 3,188,123 downloads/mo, #2,707 on PyPI
Alternatives
Verify before relying
from lxml import etree
from signxml import XMLSigner, XMLVerifier
root = etree.fromstring(data_to_sign)
signed_root = XMLSigner().sign(root, key=key, cert=cert)
verified_data = XMLVerifier().verify(signed_root).signed_xml- Whether XPath and XSLT transform support is available or intentionally excluded for security
- Specific XAdES profile coverage beyond the excerpt's mention of XAdES support
What it is and what it does
SignXML is a Python implementation of the W3C XML Signature standard, used to cryptographically sign and verify XML documents in enterprise protocols like SAML 2.0, XAdES, EBICS, and WS-Security. It wraps lxml and cryptography to provide both standard XMLDSig operations and extensions for X.509 certificate chain validation, hostname/CN verification, and XAdES support.
The library is designed with security-first defaults: it uses a libxml2-based parser hardened against common XML attacks, disables network calls and unsafe transforms by default, and emphasizes the "see what is signed" principle to prevent signature-wrapping attacks. It supports exclusive XML canonicalization with inclusive prefixes, certificate validity checks at a specific point in time, and flexible trust establishment via pre-shared certificates, CA files, or subject name matching.
Use it for
- Verify SAML 2.0 assertions from identity providers by extracting and validating X.509 certificates from SAML metadata.
- Sign and verify XAdES digital signatures for long-term archival and legal compliance in document workflows.
- Validate XML signatures in EBICS banking protocols to ensure message authenticity and non-repudiation.
- Establish trust in XML-based web services by verifying WS-Security signatures with certificate chain validation.
- Prevent SAML signature-wrapping attacks by configuring expected signature location and verifying only the returned signed_xml data.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
SignXML is actively maintained, has no known vulnerabilities, low install friction, and implements a critical security standard for enterprise XML protocols. It is appropriate for production use in SAML, XAdES, EBICS, and WS-Security integrations where XML signature verification is required.
Install
signxml on PyPI
Before you install
Low friction: pure Python wheel with three stable, widely-used dependencies (lxml, cryptography, certifi). Active maintenance with a release 40 days ago and continuous integration.
Requires lxml (libxml2-based XML parser) and valid X.509 certificate/key pair in PEM format; openssl needed to generate test certificates.
License in practice
Apache Software License (permissive): you can use, modify, and distribute signxml freely in commercial and private projects, with minimal restrictions beyond attribution.
Quickstart
from lxml import etree
from signxml import XMLSigner, XMLVerifier
root = etree.fromstring(data_to_sign)
signed_root = XMLSigner().sign(root, key=key, cert=cert)
verified_data = XMLVerifier().verify(signed_root).signed_xml
Verify before relying
- Whether XPath and XSLT transform support is available or intentionally excluded for security
- Specific XAdES profile coverage beyond the excerpt's mention of XAdES support
Package facts
| License | Apache Software License permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagescertificryptographylxml |
| Maintenance | Actively maintained 40 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 3,188,123 / month, #2,707 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: MacOS :: MacOS XOperating System :: POSIXProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Software DevelopmentTopic :: Software Development :: Libraries :: Python Modules |
Evidence: signxml-5.1.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “xml signature verification”
- signxmlSignXML implements W3C XML Signature (XMLDSig) standard for signing…
- endesiveEndesive signs and verifies digital signatures in PDF, S/MIME email,…
- xmlsecPython bindings for XML Security Library, enabling cryptographic…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also endesive · python3-saml · siwe · securesystemslib · xmlsec · signify · pysaml2 · sigstore · pysequoia · dkimpy