SLH-DSA
Pure Python implementation of the SLH-DSA algorithm (based on FIPS 205).
Decision gist · record as of 2026-08-14
Yes, if you need FIPS 205 digital signatures and want a dependency-free pure Python implementation. The package is actively maintained, well-typed, and supports current Python versions. However, verify whether the implementation has undergone formal security audit and whether performance meets your requirements before using in production systems with high-assurance security needs.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later.
- Low friction: pure Python wheel with zero runtime dependencies.
- Actively maintained with recent release (14 days old) and current Python version support (3.9–3.14).
License · maintenance · safety
LGPL-3.0-or-later (copyleft) — Licensed under LGPL-3.0-or-later (copyleft). You may use and modify the package freely, but any derivative work must also be licensed under LGPL-3.0-or-later and source code must be made available to recipients.
last release 2026-07-31 (14 days) · last repo commit 2026-07-31 · 16 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 161,616 downloads/mo, #10,627 on PyPI
Alternatives
Verify before relying
pip install slh-dsa
from slhdsa import KeyPair, shake_256f
kp = KeyPair.gen(shake_256f)
sig = kp.sign_pure(b"Hello World!", randomize=False)
kp.verify_pure(b"Hello World!", sig) # -> True- Whether the implementation has undergone formal security audit or FIPS 205 certification beyond the specification alignment claimed.
- Performance characteristics (signature size, key generation time, verification speed) relative to other FIPS 205 implementations.
- Whether randomization modes and low-level APIs are suitable for production use or primarily for experimentation.
What it is and what it does
SLH-DSA is a pure Python cryptographic library that implements the Stateless Hash-Based Digital Signature Algorithm as defined in FIPS 205. It provides a straightforward API for generating keypairs, signing messages, and verifying signatures, with support for both deterministic and randomized signing modes. The package has zero external dependencies, full type hints, and supports Python 3.9 through 3.14.
The library is designed for developers who need post-quantum-resistant digital signatures or want to experiment with hash-based cryptography. It offers both high-level convenience methods (like `sign_pure` and `verify_pure`) and low-level APIs for advanced use cases. Keypairs and secret keys can be exported and imported using standard PKCS formats, making it practical for integration into larger systems.
Use it for
- Implementing post-quantum-resistant digital signatures in applications where FIPS 205 compliance is required or desired.
- Signing and verifying messages in cryptographic protocols that need stateless, hash-based signatures.
- Exporting and restoring cryptographic keys in PKCS format for cross-system key management.
- Experimenting with SPHINCS+-derived signature schemes in research or proof-of-concept projects.
- Building cryptographic systems where deterministic or randomized signing modes must be selectable.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need FIPS 205 digital signatures and want a dependency-free pure Python implementation.
The package is actively maintained, well-typed, and supports current Python versions. However, verify whether the implementation has undergone formal security audit and whether performance meets your requirements before using in production systems with high-assurance security needs.
Install
slh-dsa on PyPI
Before you install
Low friction: pure Python wheel with zero runtime dependencies. Actively maintained with recent release (14 days old) and current Python version support (3.9–3.14). Repository shows recent activity and is not archived.
Requires Python 3.9 or later.
License in practice
Licensed under LGPL-3.0-or-later (copyleft). You may use and modify the package freely, but any derivative work must also be licensed under LGPL-3.0-or-later and source code must be made available to recipients.
Quickstart
pip install slh-dsa
from slhdsa import KeyPair, shake_256f
kp = KeyPair.gen(shake_256f)
sig = kp.sign_pure(b"Hello World!", randomize=False)
kp.verify_pure(b"Hello World!", sig) # -> True
Verify before relying
- Whether the implementation has undergone formal security audit or FIPS 205 certification beyond the specification alignment claimed.
- Performance characteristics (signature size, key generation time, verification speed) relative to other FIPS 205 implementations.
- Whether randomization modes and low-level APIs are suitable for production use or primarily for experimentation.
Package facts
| License | LGPL-3.0-or-later copyleft |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 14 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 161,616 / month, #10,627 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: GNU Lesser General Public License v3 or later (LGPLv3+)Operating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Security :: CryptographyTopic :: Software DevelopmentTopic :: Software Development :: LibrariesTyping :: Typed |
Evidence: slh_dsa-0.2.4-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “FIPS 205 digital signatures”
- SLH-DSAPure Python implementation of the SLH-DSA stateless hash-based…
- dilithium-pyA pure-Python implementation of ML-DSA (FIPS 204) and…
- ed25519-blake2b-forkProvides Python bindings to Ed25519 digital signatures using BLAKE2b…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also dilithium-py · lightdsa · fastecdsa · pqcrypto · starkbank-ecdsa · pyDes · x25519 · ed25519-blake2b-fork · PGPy · pure25519