$npx skillfedfor your agent

spiffe

Python library for SPIFFE support

Worth itPyPI CryptographyReleased Aug 2026120.5K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — spiffe-0.3.1-py3-none-any.whl
v0.3.1 · released 2026-08-08 · Python >=3.10 · 7 runtime deps: grpcio, cryptography, pyjwt, pyasn1, pyasn1-modules, pem, protobuf

Yes. The package is actively maintained, has no known vulnerabilities, installs with low friction, and is essential for any Python application that needs to integrate with SPIFFE/SPIRE for workload identity. The Apache-2.0 license is permissive. Install it if your architecture relies on SPIFFE for service authentication; skip it if you are not using SPIFFE.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a running SPIFFE Workload API instance (e.g., SPIRE) and the SPIFFE_ENDPOINT_SOCKET environment variable set to the API socket address, or provided programmatically.
  • Low friction installation with a pure-Python wheel and seven standard dependencies (grpcio, cryptography, pyjwt, pyasn1, pyasn1-modules, pem, protobuf).
  • Actively maintained with a recent release.

License · maintenance · safety

Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing use in most commercial and open-source projects without significant restrictions.

last release 2026-08-08 (6 days) · last repo commit 2026-08-08 · 23 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 120,525 downloads/mo, #12,021 on PyPI

Verify before relying

from spiffe import WorkloadApiClient

with WorkloadApiClient() as client:
    x509_svid = client.fetch_x509_svid()
    print(f'SPIFFE ID: {x509_svid.spiffe_id}')
  • Performance characteristics and scalability limits for high-frequency SVID fetching or validation.
  • Compatibility with specific SPIRE versions or other SPIFFE Workload API implementations beyond what is documented.
  • Production deployment patterns and best practices for error handling and retry logic.
Same gist for agents: .md · .json

What it is and what it does

The spiffe package is a Python client library for the SPIFFE Workload API, enabling applications to fetch and manage SPIFFE identities (X.509 and JWT SVIDs) from a SPIRE instance or other SPIFFE-compliant workload API server. It abstracts the gRPC communication layer and provides high-level APIs for identity lifecycle management, including automatic renewal and validation of certificates and tokens.

The package is built on standard cryptographic and serialization libraries (cryptography, pyjwt, pyasn1, protobuf, grpcio) and is designed for integration into microservices and distributed systems that rely on SPIFFE for workload authentication. It requires Python 3.10 or later and a running SPIFFE Workload API endpoint, typically configured via the SPIFFE_ENDPOINT_SOCKET environment variable.

Use it for

  • Fetch X.509 SVIDs in microservices to establish mTLS connections with other SPIFFE-aware services.
  • Obtain JWT SVIDs for API authentication and authorization in service-to-service communication.
  • Automatically manage certificate lifecycle with continuous updates from SPIRE without manual renewal.
  • Validate SPIFFE identities and CA bundles in applications that need to verify peer credentials.
  • Integrate workload identity into Kubernetes or other orchestration platforms running SPIRE.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The package is actively maintained, has no known vulnerabilities, installs with low friction, and is essential for any Python application that needs to integrate with SPIFFE/SPIRE for workload identity. The Apache-2.0 license is permissive. Install it if your architecture relies on SPIFFE for service authentication; skip it if you are not using SPIFFE.

Install

spiffe on PyPI

Before you install

Low friction installation with a pure-Python wheel and seven standard dependencies (grpcio, cryptography, pyjwt, pyasn1, pyasn1-modules, pem, protobuf). Actively maintained with a recent release.

Requires a running SPIFFE Workload API instance (e.g., SPIRE) and the SPIFFE_ENDPOINT_SOCKET environment variable set to the API socket address, or provided programmatically.

License in practice

Licensed under Apache-2.0 (permissive), allowing use in most commercial and open-source projects without significant restrictions.

Quickstart

from spiffe import WorkloadApiClient

with WorkloadApiClient() as client:
    x509_svid = client.fetch_x509_svid()
    print(f'SPIFFE ID: {x509_svid.spiffe_id}')

Verify before relying

  • Performance characteristics and scalability limits for high-frequency SVID fetching or validation.
  • Compatibility with specific SPIRE versions or other SPIFFE Workload API implementations beyond what is documented.
  • Production deployment patterns and best practices for error handling and retry logic.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
7 packages
grpciocryptographypyjwtpyasn1pyasn1-modulespemprotobuf
MaintenanceActively maintained 6 days since the last release
Last repo commit
First released
Downloads120,525 / month, #12,021 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: spiffe-0.3.1-py3-none-any.whl

Tags

Capabilities
SPIFFE identity managementSPIRE workload API clientX.509 SVID fetchingJWT SVID validationworkload identity certificatesSPIFFE authenticationservice identity tokens
Topics
spiffe-spireworkload-identitymtls

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “SPIFFE identity management”

  • spiffeProvides Python bindings to the SPIFFE Workload API for fetching,…
  • pydantic-scimProvides Pydantic data models for SCIM (System for Cross-domain…
  • azure-mgmt-msiManages Azure Managed Service Identities through a Python client…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also gcloud-rest-auth · pyjwt-key-fetcher · python3-saml · fastapi-cognito · vercel-oidc · pyobjc-framework-Collaboration · igwn-auth-utils · flask-oidc · coze-workload-identity · gcloud-aio-auth