taxii2-client
TAXII 2 Client Library
Decision gist · record as of 2026-08-14
Yes, if you need to integrate with a TAXII 2.X server and can tolerate dormancy. The package is stable, has no known vulnerabilities, and low install friction. However, verify that your target TAXII server version is compatible and that you don't require Python versions beyond 3.9. Consider it a read-only dependency unless you actively maintain a fork or the upstream project resumes maintenance.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a live TAXII 2.X server endpoint; authentication credentials may be needed depending on server configuration.
- Low install friction with only three common runtime dependencies.
- However, the package is dormant—last release was 2021-03-12, over 1981 days ago—so expect no active maintenance or security updates.
License · maintenance · safety
BSD (permissive) — BSD permissive license allows commercial and private use with minimal restrictions, making it suitable for most integration scenarios.
last release 2021-03-12 (1981 days) · last repo commit 2024-04-15 · 127 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 318,193 downloads/mo, #7,656 on PyPI
Alternatives
Verify before relying
pip install taxii2-client
from taxii2client.v21 import Server
server = Server('https://example.com/taxii2/', user='user_id', password='user_password')
api_root = server.api_roots[0]
collection = api_root.collections[0]
objects = collection.get_objects()- Whether the package remains compatible with current TAXII 2.X server implementations despite dormancy
- Support status for Python versions beyond 3.9 (classifiers list only through 3.9)
What it is and what it does
taxii2-client is a Python library that implements a minimal client for TAXII 2.X servers, the standard protocol for sharing cyber threat intelligence. It provides four main classes—Server, ApiRoot, Collection, and Status—that let you connect to a TAXII server, browse its structure, and retrieve or submit threat intelligence objects (STIX bundles). The library handles authentication, lazy-loads server metadata, and supports both TAXII 2.0 and 2.1 API variants with pagination helpers.
You instantiate a Server object with a URL and optional credentials, then navigate through api_roots to collections and individual objects. The library caches metadata in instances to avoid repeated requests. It depends only on requests, six, and pytz, making it lightweight. However, the project is dormant—no updates since March 2021—so it may not support the latest TAXII server features or Python versions.
Use it for
- Retrieve threat indicators and malware samples from a TAXII 2.X server for local analysis
- Automate bulk collection of STIX objects from a threat intelligence platform using pagination
- Submit your organization's threat data (STIX bundles) to a shared TAXII collection
- Integrate threat intelligence feeds into a security monitoring or incident response workflow
- Query server metadata and collection capabilities to discover available threat data sources
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to integrate with a TAXII 2.X server and can tolerate dormancy.
The package is stable, has no known vulnerabilities, and low install friction. However, verify that your target TAXII server version is compatible and that you don't require Python versions beyond 3.9. Consider it a read-only dependency unless you actively maintain a fork or the upstream project resumes maintenance.
Install
taxii2-client on PyPI
Before you install
Low install friction with only three common runtime dependencies. However, the package is dormant—last release was 2021-03-12, over 1981 days ago—so expect no active maintenance or security updates.
Requires a live TAXII 2.X server endpoint; authentication credentials may be needed depending on server configuration.
License in practice
BSD permissive license allows commercial and private use with minimal restrictions, making it suitable for most integration scenarios.
Quickstart
pip install taxii2-client
from taxii2client.v21 import Server
server = Server('https://example.com/taxii2/', user='user_id', password='user_password')
api_root = server.api_roots[0]
collection = api_root.collections[0]
objects = collection.get_objects()
Verify before relying
- Whether the package remains compatible with current TAXII 2.X server implementations despite dormancy
- Support status for Python versions beyond 3.9 (classifiers list only through 3.9)
Package facts
| License | BSD permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesrequestssixpytz |
| Maintenance | Dormant 1,981 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 318,193 / month, #7,656 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Security |
Evidence: taxii2_client-2.3.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “taxii client library”
- taxii2-clientA minimal client library for querying and managing TAXII 2.X threat…
- conjure-python-clientA lightweight HTTP client library built on requests that handles RPC…
- paypalhttpPayPalHttp is a generic HTTP client library designed to work with…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also pycti · stix2 · stix2-patterns · stix · stix2-validator · OTXv2 · domaintools-api · mixbox · ansible-navigator · pagerduty