socketdev
Socket Security Python SDK
Decision gist · record as of 2026-08-14
Yes. The SDK is actively maintained, has no known vulnerabilities, installs with minimal friction, and is licensed permissively under MIT. Install it if you need programmatic access to Socket.dev's package security API from Python; skip it if you only need one-off lookups via the web UI.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a valid Socket.dev API token; unauthenticated calls will fail.
- Low friction: pure Python wheel with only two runtime dependencies (requests and typing-extensions).
- Active maintenance with a release 8 days ago; repo shows recent commits and is not archived.
License · maintenance · safety
permissive license (permissive) — MIT License permits free use, modification, and distribution with minimal restrictions—suitable for commercial and open-source projects alike.
last release 2026-08-06 (8 days) · last repo commit 2026-08-11 · 13 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 238,203 downloads/mo, #8,944 on PyPI
Alternatives
Verify before relying
pip install socketdev
from socketdev import socketdev
socket = socketdev(token="YOUR_API_KEY")
result = socket.purl.post("true", [{"purl": "pkg:pypi/requests"}])- Whether the SDK supports all current Socket.dev API endpoints or only a subset of v0.
- Rate limiting behavior and retry logic when making API calls.
- Whether SSL verification can be disabled safely in production contexts beyond testing.
What it is and what it does
The Socket.dev Python SDK is a lightweight wrapper around the Socket.dev REST API that lets you query package metadata, security scores, and license information directly from Python. It handles authentication, request formatting, and response parsing so you don't have to build HTTP calls manually. The SDK supports querying packages by PURL (Package URL), running full scans on manifest files, and exporting SBOMs in multiple formats (CycloneDX, SPDX, OpenVEX).
You initialize it with an API token and optional timeout, then call methods like `purl.post()` to look up package details, `fullscans.post()` to analyze a set of manifest files, or `export.cdx_bom()` to convert scan results into standard SBOM formats. It depends only on requests for HTTP calls and typing-extensions for type hints, making it straightforward to integrate into existing Python projects.
Use it for
- Query package metadata and security scores for dependencies in your codebase by PURL.
- Automate full scans of manifest files (package.json, requirements.txt, etc.) as part of CI/CD pipelines.
- Export SBOMs in CycloneDX or SPDX format for compliance and supply-chain visibility.
- Retrieve vulnerability and license alerts for a set of components to inform security decisions.
- Integrate Socket.dev security checks into custom tooling or dashboards.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The SDK is actively maintained, has no known vulnerabilities, installs with minimal friction, and is licensed permissively under MIT. Install it if you need programmatic access to Socket.dev's package security API from Python; skip it if you only need one-off lookups via the web UI.
Install
socketdev on PyPI
Before you install
Low friction: pure Python wheel with only two runtime dependencies (requests and typing-extensions). Active maintenance with a release 8 days ago; repo shows recent commits and is not archived.
Requires a valid Socket.dev API token; unauthenticated calls will fail.
License in practice
MIT License permits free use, modification, and distribution with minimal restrictions—suitable for commercial and open-source projects alike.
Quickstart
pip install socketdev
from socketdev import socketdev
socket = socketdev(token="YOUR_API_KEY")
result = socket.purl.post("true", [{"purl": "pkg:pypi/requests"}])
Verify before relying
- Whether the SDK supports all current Socket.dev API endpoints or only a subset of v0.
- Rate limiting behavior and retry logic when making API calls.
- Whether SSL verification can be disabled safely in production contexts beyond testing.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesrequeststyping-extensions |
| Maintenance | Actively maintained 8 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 238,203 / month, #8,944 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: socketdev-3.5.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “socket.dev api client”
- socketdevA Python SDK that wraps the Socket.dev REST API, enabling…
- socketsecuritySocket Security CLI scans Python projects for supply-chain security…
- codewords-clientA Python client library for the Codewords API with built-in FastAPI…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also socketsecurity · hiddenlayer-sdk · distro2sbom · lib4sbom · cyclonedx-py · harborapi · python-http-client · safety · cyclonedx-bom · pysnyk