$npx skillfedfor your agent

srptools

Tools to implement Secure Remote Password (SRP) authentication

With conditionsPyPI CryptographyReleased Sep 2020473.7K downloads / moBSD 3-Clause LicensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — srptools-1.0.1-py2.py3-none-any.whl
v1.0.1 · released 2020-09-12

Yes, if you need SRP authentication. The package is stable, has no runtime dependencies, and is actively maintained. However, note that the latest release was in 2020 and Python 2 support is included; verify that the supported Python versions and any cryptographic assumptions align with your security requirements before production use.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • CLI usage requires the click package to be installed separately; API usage has no external dependencies.
  • Low install friction with no runtime dependencies.
  • Package is actively maintained with recent commits, though the latest release was in 2020; the repository remains active and unarchived.

License · maintenance · safety

BSD 3-Clause License (permissive) — BSD 3-Clause License is permissive, allowing commercial and private use with minimal restrictions; you may use and modify the code freely provided you include the license notice.

last release 2020-09-12 (2162 days) · last repo commit 2026-07-16 · 32 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 473,669 downloads/mo, #6,460 on PyPI

Verify before relying

from srptools import SRPContext, SRPServerSession, SRPClientSession

context = SRPContext('alice', 'password123')
username, password_verifier, salt = context.get_user_data_triplet()

server_session = SRPServerSession(SRPContext(username, prime=context.prime, generator=context.generator), password_verifier)
client_session = SRPClientSession(SRPContext('alice', 'password123', prime=context.prime, generator=context.generator))
client_session.process(server_session.public, salt)
server_session.process(client_session.public, salt)
assert server_session.key == client_session.key
  • Whether the package's Python 2.7 and 3.5-3.7 support claims remain accurate for modern environments.
  • Current security audit status or any known cryptographic implementation concerns beyond OSV records.
Same gist for agents: .md · .json

What it is and what it does

srptools provides a complete implementation of the Secure Remote Password (SRP) protocol, a password-authenticated key agreement (PAKE) mechanism that allows two parties to authenticate each other and establish a shared session key without ever transmitting the password over the network. The package supports both Python 2 and 3 and offers two interfaces: a programmatic API via SRPContext, SRPServerSession, and SRPClientSession classes, and a command-line utility for testing and integration.

The library handles the cryptographic details of SRP authentication, including user data triplet generation (username, password verifier, and salt), session key derivation, and optional proof verification for mutual authentication. It supports both hex and base64 encoding of values, allows session restoration via private key storage, and can raise SRPException to signal authentication failures that should halt the process. The package has no external runtime dependencies for API use, making it lightweight for embedding in applications.

Use it for

  • Implement password-based authentication in web applications or APIs where you want to avoid transmitting passwords over the network.
  • Build peer-to-peer or distributed systems requiring mutual authentication without relying on a central certificate authority.
  • Add SRP-based authentication to IoT or embedded systems where password security and key exchange are critical.
  • Test or prototype SRP protocol implementations using the command-line utility for debugging authentication flows.
  • Replace basic password authentication in legacy systems with a cryptographically stronger PAKE mechanism.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need SRP authentication.

The package is stable, has no runtime dependencies, and is actively maintained. However, note that the latest release was in 2020 and Python 2 support is included; verify that the supported Python versions and any cryptographic assumptions align with your security requirements before production use.

Install

srptools on PyPI

Before you install

Low install friction with no runtime dependencies. Package is actively maintained with recent commits, though the latest release was in 2020; the repository remains active and unarchived.

CLI usage requires the click package to be installed separately; API usage has no external dependencies.

License in practice

BSD 3-Clause License is permissive, allowing commercial and private use with minimal restrictions; you may use and modify the code freely provided you include the license notice.

Quickstart

from srptools import SRPContext, SRPServerSession, SRPClientSession

context = SRPContext('alice', 'password123')
username, password_verifier, salt = context.get_user_data_triplet()

server_session = SRPServerSession(SRPContext(username, prime=context.prime, generator=context.generator), password_verifier)
client_session = SRPClientSession(SRPContext('alice', 'password123', prime=context.prime, generator=context.generator))
client_session.process(server_session.public, salt)
server_session.process(client_session.public, salt)
assert server_session.key == client_session.key

Verify before relying

  • Whether the package's Python 2.7 and 3.5-3.7 support claims remain accurate for modern environments.
  • Current security audit status or any known cryptographic implementation concerns beyond OSV records.

Package facts

LicenseBSD 3-Clause License permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 2,162 days since the last release
Last repo commit
First released
Downloads473,669 / month, #6,460 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7

Evidence: srptools-1.0.1-py2.py3-none-any.whl

Tags

Capabilities
SRP authentication protocolpassword-authenticated key exchangesecure remote passwordPAKE implementationpassword authentication without transmissioncryptographic key agreementclient-server authentication
Topics
authenticationcryptographypake

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “password-authenticated key exchange”

  • srptoolsImplements Secure Remote Password (SRP) protocol for…
  • pure25519Pure-Python implementation of Curve25519 and Ed25519 cryptographic…
  • spake2Implements SPAKE2, a password-authenticated key exchange (PAKE)…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also srp · spake2 · scramp · python-irodsclient · PyOTP · pkce · prime-tunnel · pwdlib · bcrypt · secure-smtplib