siwe
A Python implementation of Sign-In with Ethereum (EIP-4361).
Decision gist · record as of 2026-08-14
Yes. SIWE is actively maintained, has no known vulnerabilities, low install friction, and is the standard Python implementation of EIP-4361. Install it if you need Ethereum-based authentication in a Python application. The disclaimer notes it has not undergone formal security audit, so review its use in high-security contexts accordingly.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires web3 and eth-account dependencies; verification requires a valid EIP-191 signature from the claimed signer address.
- Low install friction with a pure-Python wheel.
- Active maintenance with recent commits and no known vulnerabilities.
License · maintenance · safety
MIT OR Apache-2.0 (permissive) — Dual-licensed under MIT or Apache-2.0, both permissive licenses allowing commercial and private use with minimal restrictions.
last release 2024-10-11 (672 days) · last repo commit 2026-08-14 · 13,951 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 111,944 downloads/mo, #12,389 on PyPI
Alternatives
Verify before relying
pip install siwe
from siwe import SiweMessage
message = SiweMessage.from_message(message=eip_4361_string)
message.verify(signature="0x...")- Whether the package has undergone formal security audit since the disclaimer in the description was written.
- Real-world adoption rate beyond the monthly download count.
What it is and what it does
SIWE is a Python library that implements the EIP-4361 standard for Ethereum-based authentication. It provides a `SiweMessage` class that handles the full lifecycle of Sign-In with Ethereum messages: parsing EIP-4361 formatted strings, verifying signatures using EIP-191, and serializing messages back to their canonical form. The library depends on web3, eth-account, eth-typing, eth-utils, and pydantic to handle cryptographic operations and message validation.
Typical usage involves creating a `SiweMessage` from a user-provided string, calling `verify()` with a signature to confirm the message was signed by the claimed address, and handling specific exceptions like `ExpiredMessage`, `DomainMismatch`, or `InvalidSignature` to reject invalid authentication attempts. The package is actively maintained and supports current Python versions.
Use it for
- Build a web application login flow where users authenticate with their Ethereum wallet instead of a password.
- Verify that a message claiming to be from a specific Ethereum address was actually signed by that address's private key.
- Implement time-based and domain-based message validation to prevent replay attacks in authentication workflows.
- Parse and validate SIWE messages from external sources to confirm their structural integrity and signature validity.
- Serialize authentication messages into EIP-4361 format for transmission to users' wallet applications.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
SIWE is actively maintained, has no known vulnerabilities, low install friction, and is the standard Python implementation of EIP-4361. Install it if you need Ethereum-based authentication in a Python application. The disclaimer notes it has not undergone formal security audit, so review its use in high-security contexts accordingly.
Install
siwe on PyPI
Before you install
Low install friction with a pure-Python wheel. Active maintenance with recent commits and no known vulnerabilities. Supports Python 3.8 through 3.12.
Requires web3 and eth-account dependencies; verification requires a valid EIP-191 signature from the claimed signer address.
License in practice
Dual-licensed under MIT or Apache-2.0, both permissive licenses allowing commercial and private use with minimal restrictions.
Quickstart
pip install siwe
from siwe import SiweMessage
message = SiweMessage.from_message(message=eip_4361_string)
message.verify(signature="0x...")
Verify before relying
- Whether the package has undergone formal security audit since the disclaimer in the description was written.
- Real-world adoption rate beyond the monthly download count.
Package facts
| License | MIT OR Apache-2.0 permissive |
| Python support | Supports the current Python release <4.0,>=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 8 packagesabnfweb3eth-accounteth-typingeth-utilspydanticpydantic-coretyping-extensions |
| Maintenance | Actively maintained 672 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 111,944 / month, #12,389 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: Other/Proprietary LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: siwe-4.4.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “ethereum authentication”
- siweImplements EIP-4361 Sign-In with Ethereum for parsing, verifying, and…
- eth-accounteth-account signs Ethereum transactions and messages using local…
- py-builder-relayer-clientA Python client library for submitting transactions and interacting…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also eip712 · ckzg · signxml · poly-eip712-structs · eth-account · eth-keys · standardwebhooks · vonage-jwt · ed25519-blake2b-fork · sigstore