$npx skillfedfor your agent

sspilib

SSPI API bindings for Python

With conditionsPyPI SecurityReleased Dec 20253.2M downloads / moMITPlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — sspilib-0.5.0-cp310-cp310-macosx_10_12_x86_64.whl · sspilib-0.5.0-cp310-cp310-macosx_11_0_arm64.whl · sspilib-0.5.0-cp310-cp310-manylinux_2_28_aarch64.whl
v0.5.0 · released 2025-12-03 · Python >=3.9

Yes, if you need Windows SSPI authentication in Python and are working in a Windows-centric environment. The pre-built wheels make installation painless, the MIT license is unrestricted, and there are no known vulnerabilities. However, the project is aging (254 days since last release, 8 stars), so adoption is limited and you should verify that the specific authentication protocols and scenarios you need are fully supported. For non-Windows platforms, the experimental sspi-rs backend is not recommended for production without thorough testing.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9+; SSPI is a Windows API, though experimental wheels exist for Linux and macOS using sspi-rs (glibc only, not musl/Alpine).
  • Medium install friction due to compiled extensions; wheels are pre-built for Python 3.9+ on Windows, macOS (x86_64 and ARM64), and Linux (x86_64 and aarch64), so binary installation is straightforward.
  • Repository shows active maintenance with a recent commit on 2025-12-03, though the project is aging and has limited adoption (8 stars).

License · maintenance · safety

MIT (permissive) — MIT license is permissive and imposes no restrictions on use, modification, or distribution in proprietary or open-source projects.

last release 2025-12-03 (254 days) · last repo commit 2025-12-03 · 8 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 3,221,910 downloads/mo, #2,695 on PyPI

Verify before relying

pip install sspilib

import sspilib

cred = sspilib.UserCredential("username@DOMAIN.COM", "password")
ctx = sspilib.ClientSecurityContext(
    credential=cred,
    target_name="host/server.domain.com",
)
while not ctx.complete:
    out_token = ctx.step(None)
    if out_token:
        in_token = exchange_with_server(out_token)
  • Whether the experimental non-Windows support (via sspi-rs) is production-ready or suitable for critical authentication workflows
  • Performance characteristics and overhead of the high-level vs. raw API interfaces
  • Completeness of SSPI API coverage and which specific authentication protocols are fully supported
Same gist for agents: .md · .json

What it is and what it does

sspilib is a Python wrapper around the Windows SSPI (Security Support Provider Interface) API, exposing both high-level and low-level interfaces for Kerberos, NTLM, and Negotiate authentication. It allows Python applications to perform Windows-native authentication, establish security contexts, and encrypt/decrypt messages using the same cryptographic mechanisms as Windows itself.

The library is designed for scenarios where your Python application needs to authenticate against Windows servers or services using domain credentials—such as HTTP clients connecting to servers with Negotiate authentication, LDAP clients, or custom protocols. It ships with pre-built wheels for Windows, macOS, and Linux (x86_64 and aarch64), eliminating the need to compile from source in most cases. The high-level API provides familiar Python classes like UserCredential and ClientSecurityContext; the low-level raw API exposes individual SSPI functions for fine-grained control.

Use it for

  • Authenticate Python HTTP clients against Windows servers using Negotiate or Kerberos (e.g., corporate intranet APIs)
  • Build LDAP clients that authenticate with Windows domain credentials
  • Implement custom protocols that require SSPI-based authentication and message encryption
  • Wrap sensitive data sent over untrusted channels using SSPI's message protection (wrap/unwrap)
  • Integrate Python services into Windows-centric enterprise environments requiring Kerberos or NTLM

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need Windows SSPI authentication in Python and are working in a Windows-centric environment.

The pre-built wheels make installation painless, the MIT license is unrestricted, and there are no known vulnerabilities. However, the project is aging (254 days since last release, 8 stars), so adoption is limited and you should verify that the specific authentication protocols and scenarios you need are fully supported. For non-Windows platforms, the experimental sspi-rs backend is not recommended for production without thorough testing.

Install

sspilib on PyPI

Before you install

Medium install friction due to compiled extensions; wheels are pre-built for Python 3.9+ on Windows, macOS (x86_64 and ARM64), and Linux (x86_64 and aarch64), so binary installation is straightforward. Repository shows active maintenance with a recent commit on 2025-12-03, though the project is aging and has limited adoption (8 stars).

Requires Python 3.9+; SSPI is a Windows API, though experimental wheels exist for Linux and macOS using sspi-rs (glibc only, not musl/Alpine).

License in practice

MIT license is permissive and imposes no restrictions on use, modification, or distribution in proprietary or open-source projects.

Quickstart

pip install sspilib

import sspilib

cred = sspilib.UserCredential("username@DOMAIN.COM", "password")
ctx = sspilib.ClientSecurityContext(
    credential=cred,
    target_name="host/server.domain.com",
)
while not ctx.complete:
    out_token = ctx.step(None)
    if out_token:
        in_token = exchange_with_server(out_token)

Verify before relying

  • Whether the experimental non-Windows support (via sspi-rs) is production-ready or suitable for critical authentication workflows
  • Performance characteristics and overhead of the high-level vs. raw API interfaces
  • Completeness of SSPI API coverage and which specific authentication protocols are fully supported

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionMedium. Platform-specific wheel
Runtime dependenciesNone
MaintenanceAging 254 days since the last release
Last repo commit
First released
Downloads3,221,910 / month, #2,695 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Programming Language :: Python :: Free Threading :: 2 - Beta

Evidence: sspilib-0.5.0-cp310-cp310-macosx_10_12_x86_64.whl; sspilib-0.5.0-cp310-cp310-macosx_11_0_arm64.whl; sspilib-0.5.0-cp310-cp310-manylinux_2_28_aarch64.whl; sspilib-0.5.0-cp310-cp310-manylinux_2_28_x86_64.whl; sspilib-0.5.0-cp310-cp310-win32.whl; sspilib-0.5.0-cp310-cp310-win_amd64.whl; sspilib-0.5.0-cp310-cp310-win_arm64.whl; sspilib-0.5.0-cp311-abi3-macosx_10_12_x86_64.whl; sspilib-0.5.0-cp311-abi3-macosx_11_0_arm64.whl; sspilib-0.5.0-cp311-abi3-manylinux_2_28_aarch64.whl; sspilib-0.5.0-cp311-abi3-manylinux_2_28_x86_64.whl; sspilib-0.5.0-cp311-abi3-win32.whl; sspilib-0.5.0-cp311-abi3-win_amd64.whl; sspilib-0.5.0-cp311-abi3-win_arm64.whl; sspilib-0.5.0-cp314-cp314t-macosx_10_15_x86_64.whl; sspilib-0.5.0-cp314-cp314t-macosx_11_0_arm64.whl; sspilib-0.5.0-cp314-cp314t-manylinux_2_28_aarch64.whl; sspilib-0.5.0-cp314-cp314t-manylinux_2_28_x86_64.whl; sspilib-0.5.0-cp314-cp314t-win32.whl; sspilib-0.5.0-cp314-cp314t-win_amd64.whl

Tags

Capabilities
windows sspi authenticationkerberos negotiate pythonwindows security contextsspi client authenticationwindows credential handlingmessage encryption wrappingspn authentication
Topics
windows-authenticationkerberossspi
PyPI keywords
sspikerberosnegotiate

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “windows sspi authentication”

  • sspilibProvides Python bindings to the Windows SSPI API for authentication…
  • winkerberosProvides native Kerberos client authentication on Windows by wrapping…
  • requests-negotiate-sspiAdds HTTP Negotiate authentication (Kerberos/NTLM single-sign-on) to…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also p4python · requests-negotiate-sspi · gssapi · krb5 · winkerberos · pyspnego · requests-kerberos · requests-gssapi · pypsrp · oslex