spake2
SPAKE2 password-authenticated key exchange (pure python)
Decision gist · record as of 2026-08-14
Yes, if you need PAKE for password-based key exchange. The implementation is stable (no known vulnerabilities, low install friction), MIT-licensed, and suitable for production use in pairing and login protocols. Dormant maintenance is acceptable for a mature cryptographic algorithm. Verify that the implementation meets your security audit requirements and interoperability needs before deployment.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Both parties must agree on their roles (A or B) before the exchange; use SPAKE2_Symmetric for symmetric peer scenarios.
- Low install friction with a single cryptography dependency; dormant maintenance status (last commit 2024-09-25, no releases in 688 days) suggests stability over active development.
License · maintenance · safety
MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and proprietary projects.
last release 2024-09-25 (688 days) · last repo commit 2024-09-25 · 89 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 708,346 downloads/mo, #5,264 on PyPI
Alternatives
Verify before relying
from spake2 import SPAKE2_A, SPAKE2_B
# Client side
s = SPAKE2_A(b"shared_password")
msg_out = s.start()
# send msg_out to server
msg_in = receive_from_server()
key = s.finish(msg_in)
# Server side
q = SPAKE2_B(b"shared_password")
msg_out = q.start()
# send msg_out to client
msg_in = receive_from_client()
key = q.finish(msg_in)- Whether the implementation has undergone formal cryptographic audit or review
- Performance characteristics and suitability for high-throughput scenarios
- Interoperability guarantees with other SPAKE2 implementations across languages
What it is and what it does
SPAKE2 is a pure-Python implementation of the SPAKE2 password-authenticated key exchange protocol. It solves the problem of two parties who only share a weak password needing to establish a strong shared secret for encrypted communication without prior key exchange infrastructure. The protocol resists both passive eavesdropping and active man-in-the-middle attacks: a passive attacker learns nothing about the password or derived key, while an active attacker gets only one guess per protocol execution with no offline dictionary attack possible.
The library provides three main classes: SPAKE2_A and SPAKE2_B for asymmetric roles (typically client and server), and SPAKE2_Symmetric for peer-to-peer scenarios where roles cannot be predetermined. The protocol requires only one message round trip to establish the session key, with an optional second round trip for key confirmation. All messages are bytestrings, and the default security level (Ed25519) produces 33-byte messages. The derived key can be used directly for HMAC or authenticated encryption, or fed into HKDF for deriving additional session keys.
Use it for
- Device pairing protocols where one device generates a code and both devices use it as a one-time password to establish trust
- Login systems where you want to avoid sending plaintext passwords over TLS by having both client and server derive a shared key from the password
- Peer-to-peer applications needing symmetric key agreement without pre-established infrastructure or certificate authorities
- Establishing encrypted channels between parties who have only memorized or shared a weak password out-of-band
- Building key confirmation mechanisms to verify both parties derived the same key before using it for data encryption
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need PAKE for password-based key exchange.
The implementation is stable (no known vulnerabilities, low install friction), MIT-licensed, and suitable for production use in pairing and login protocols. Dormant maintenance is acceptable for a mature cryptographic algorithm. Verify that the implementation meets your security audit requirements and interoperability needs before deployment.
Install
spake2 on PyPI
Before you install
Low install friction with a single cryptography dependency; dormant maintenance status (last commit 2024-09-25, no releases in 688 days) suggests stability over active development.
Both parties must agree on their roles (A or B) before the exchange; use SPAKE2_Symmetric for symmetric peer scenarios.
License in practice
MIT license permits free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and proprietary projects.
Quickstart
from spake2 import SPAKE2_A, SPAKE2_B
# Client side
s = SPAKE2_A(b"shared_password")
msg_out = s.start()
# send msg_out to server
msg_in = receive_from_server()
key = s.finish(msg_in)
# Server side
q = SPAKE2_B(b"shared_password")
msg_out = q.start()
# send msg_out to client
msg_in = receive_from_client()
key = q.finish(msg_in)
Verify before relying
- Whether the implementation has undergone formal cryptographic audit or review
- Performance characteristics and suitability for high-throughput scenarios
- Interoperability guarantees with other SPAKE2 implementations across languages
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagecryptography |
| Maintenance | Dormant 688 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 708,346 / month, #5,264 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Intended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Topic :: Security :: Cryptography |
Evidence: spake2-0.9-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “password authenticated key exchange”
- spake2Implements SPAKE2, a password-authenticated key exchange (PAKE)…
- pysodiumPysodium is a Python wrapper around libsodium that provides access to…
- pure25519Pure-Python implementation of Curve25519 and Ed25519 cryptographic…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also pure25519 · srptools · pyDes · keyrings.cryptfile · fernet · django-fernet-fields-v2 · diffiehellmanlib · pkce · srp