tink
A multi-language, cross-platform library that provides cryptographic APIs that are secure, easy to use correctly, and hard(er) to misuse.
Decision gist · record as of 2026-08-14
Yes. Tink is actively maintained, has no known vulnerabilities, supports current Python versions, and carries a permissive license. It is appropriate for any application requiring cryptography where ease of correct use and resistance to common pitfalls outweigh the need for lower-level control. The medium install friction is offset by prebuilt wheels and straightforward dependencies.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; depends on protobuf, absl-py, and bazel-runfiles at runtime.
- Medium install friction due to compiled wheels, but well-maintained with active development (release 1 day old as of fact sheet date).
- Supports Python 3.10 through 3.14 with prebuilt wheels for macOS, Linux (x86_64 and aarch64), and Windows.
License · maintenance · safety
Apache 2.0 (permissive) — Apache 2.0 permissive license allows commercial use, modification, and distribution with minimal restrictions—suitable for most projects without legal friction.
last release 2026-08-13 (1 days) · last repo commit 2026-08-12 · 78 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,761,034 downloads/mo, #3,584 on PyPI
Alternatives
Verify before relying
pip install tink
import tink
from tink import aead
# Initialize Tink
tink.Tink.init()
# Generate a new keyset for AEAD
keyset_handle = aead.new_keyset_handle(aead.aead_key_templates.AES_GCM)
cipher = keyset_handle.primitive(aead.Aead)- Whether KMS integration (mentioned in test matrix) is available in the pip-installed version or requires additional setup.
- Performance characteristics compared to other cryptography libraries for specific use cases.
- Availability and completeness of documentation beyond the Google Tink design goals page.
- Specific AEAD key template names and their availability in the Python binding.
What it is and what it does
Tink is Google's cryptography library designed to make secure crypto accessible without requiring deep cryptographic expertise. It provides high-level APIs for authenticated encryption, key management, and digital signatures that are resistant to common implementation mistakes. The library is built on lessons learned from Google's own product deployments and security research, emphasizing user-centered design and careful code review.
The Python binding wraps Tink's core functionality and is maintained actively with support for modern Python versions (3.10–3.14). It depends on protobuf, absl-py, and bazel-runfiles. Installation uses precompiled wheels for most platforms, reducing build friction. Tink is positioned as a standard crypto library within Google and has been deployed across hundreds of products, making it a production-grade choice for applications requiring strong cryptographic guarantees without the complexity of lower-level APIs.
Use it for
- Encrypting sensitive data at rest or in transit using authenticated encryption primitives without managing cipher modes manually.
- Implementing key rotation and key management policies through Tink's keyset abstraction and key versioning.
- Adding digital signatures to messages or documents for integrity and authenticity verification.
- Building applications that require compliance with cryptographic best practices without deep security expertise.
- Integrating with key management systems for envelope encryption and centralized key management.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Tink is actively maintained, has no known vulnerabilities, supports current Python versions, and carries a permissive license. It is appropriate for any application requiring cryptography where ease of correct use and resistance to common pitfalls outweigh the need for lower-level control. The medium install friction is offset by prebuilt wheels and straightforward dependencies.
Install
tink on PyPI
Before you install
Medium install friction due to compiled wheels, but well-maintained with active development (release 1 day old as of fact sheet date). Supports Python 3.10 through 3.14 with prebuilt wheels for macOS, Linux (x86_64 and aarch64), and Windows.
Requires Python 3.10 or later; depends on protobuf, absl-py, and bazel-runfiles at runtime.
License in practice
Apache 2.0 permissive license allows commercial use, modification, and distribution with minimal restrictions—suitable for most projects without legal friction.
Quickstart
pip install tink
import tink
from tink import aead
# Initialize Tink
tink.Tink.init()
# Generate a new keyset for AEAD
keyset_handle = aead.new_keyset_handle(aead.aead_key_templates.AES_GCM)
cipher = keyset_handle.primitive(aead.Aead)
Verify before relying
- Whether KMS integration (mentioned in test matrix) is available in the pip-installed version or requires additional setup.
- Performance characteristics compared to other cryptography libraries for specific use cases.
- Availability and completeness of documentation beyond the Google Tink design goals page.
- Specific AEAD key template names and their availability in the Python binding.
Package facts
| License | Apache 2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 3 packagesabsl-pyprotobufbazel-runfiles |
| Maintenance | Actively maintained 1 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,761,034 / month, #3,584 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Programming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software Development :: Libraries |
Evidence: tink-1.16.1-cp310-cp310-macosx_11_0_universal2.whl; tink-1.16.1-cp310-cp310-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; tink-1.16.1-cp310-cp310-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl; tink-1.16.1-cp310-cp310-win_amd64.whl; tink-1.16.1-cp311-cp311-macosx_11_0_universal2.whl; tink-1.16.1-cp311-cp311-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; tink-1.16.1-cp311-cp311-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl; tink-1.16.1-cp311-cp311-win_amd64.whl; tink-1.16.1-cp312-cp312-macosx_11_0_universal2.whl; tink-1.16.1-cp312-cp312-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; tink-1.16.1-cp312-cp312-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl; tink-1.16.1-cp312-cp312-win_amd64.whl; tink-1.16.1-cp313-cp313-macosx_11_0_universal2.whl; tink-1.16.1-cp313-cp313-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; tink-1.16.1-cp313-cp313-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl; tink-1.16.1-cp313-cp313-win_amd64.whl; tink-1.16.1-cp314-cp314-macosx_11_0_universal2.whl; tink-1.16.1-cp314-cp314-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; tink-1.16.1-cp314-cp314-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl; tink-1.16.1-cp314-cp314-win_amd64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “cryptography library easy to use”
- tinkTink provides cryptographic APIs designed to be secure by default and…
- lighteccLightECC provides elliptic curve arithmetic operations (addition,…
- ed25519-blake2b-forkProvides Python bindings to Ed25519 digital signatures using BLAKE2b…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also crypto · google-cloud-kms · cryptography · oscrypto · miscreant · aws-encryption-sdk · securesystemslib · cursive · tacacs_plus · libthumbor