truelayer-signing
Produce & verify TrueLayer API requests signatures
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has no known vulnerabilities, low install friction, and a permissive license. Install it if you are integrating with TrueLayer's API and need to sign requests or verify webhooks; it is the standard tool for this task in Python.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; cryptography must be installed.
- Low friction: pure Python wheel with a single runtime dependency on cryptography.
- Active maintenance with a recent release 57 days ago and commits through August 2026.
License · maintenance · safety
Apache-2.0 or MIT (permissive) — Licensed under Apache-2.0 or MIT (permissive), allowing use in most commercial and open-source projects without significant restrictions.
last release 2026-06-18 (57 days) · last repo commit 2026-08-10 · 23 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 191,606 downloads/mo, #9,879 on PyPI
Alternatives
Verify before relying
pip install truelayer-signing
from truelayer_signing import sign_with_pem, HttpMethod
tl_signature = sign_with_pem(KID, PRIVATE_KEY) \
.set_method(HttpMethod.POST) \
.set_path(path) \
.add_header("Idempotency-Key", key) \
.set_body(body) \
.sign()- Whether the package handles key rotation or certificate expiry scenarios automatically.
- Performance characteristics when signing or verifying large request bodies.
- Whether webhook verification supports custom header validation beyond the standard Tl-Signature.
What it is and what it does
truelayer-signing is a Python library for cryptographic signing and verification of TrueLayer API requests and webhooks. It provides a fluent builder API to construct signed requests using PEM-encoded private keys and to verify incoming webhook signatures using JWKS (JSON Web Key Sets). The library depends only on cryptography and supports Python 3.10 through 3.14.
The package is designed for developers integrating with TrueLayer's API who need to authenticate outbound requests or validate inbound webhook payloads. It handles the low-level cryptographic operations (signing with private keys, verifying with public keys from JWKS) while exposing a straightforward method-chaining interface for building and verifying signed HTTP requests.
Use it for
- Sign outbound POST requests to TrueLayer API endpoints using a private key and key ID.
- Verify incoming webhook signatures from TrueLayer by extracting and validating the Tl-Signature header.
- Add idempotency keys and custom headers to signed API requests to prevent duplicate processing.
- Validate webhook JWS headers and ensure the key source (jku) is from an allowed TrueLayer domain.
- Integrate TrueLayer payment or open banking flows into a Python backend with request authentication.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has no known vulnerabilities, low install friction, and a permissive license. Install it if you are integrating with TrueLayer's API and need to sign requests or verify webhooks; it is the standard tool for this task in Python.
Install
truelayer-signing on PyPI
Before you install
Low friction: pure Python wheel with a single runtime dependency on cryptography. Active maintenance with a recent release 57 days ago and commits through August 2026.
Requires Python 3.10 or later; cryptography must be installed.
License in practice
Licensed under Apache-2.0 or MIT (permissive), allowing use in most commercial and open-source projects without significant restrictions.
Quickstart
pip install truelayer-signing
from truelayer_signing import sign_with_pem, HttpMethod
tl_signature = sign_with_pem(KID, PRIVATE_KEY) \
.set_method(HttpMethod.POST) \
.set_path(path) \
.add_header("Idempotency-Key", key) \
.set_body(body) \
.sign()
Verify before relying
- Whether the package handles key rotation or certificate expiry scenarios automatically.
- Performance characteristics when signing or verifying large request bodies.
- Whether webhook verification supports custom header validation beyond the standard Tl-Signature.
Package facts
| License | Apache-2.0 or MIT permissive |
| Python support | Supports the current Python release <4.0,>=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagecryptography |
| Maintenance | Actively maintained 57 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 191,606 / month, #9,879 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: Other/Proprietary LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: truelayer_signing-0.4.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “truelayer api signature”
- truelayer-signingProduces and verifies cryptographic signatures for TrueLayer API…
- hellosign-python-sdkA Python wrapper for the HelloSign API that lets you send signature…
- dropbox-signPython client library for the Dropbox Sign v3 API, enabling…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also standardwebhooks · signify · paytmchecksum · apimatic-core-interfaces · aws-request-signer · dkimpy · jwskate · py-builder-signing-sdk · veracode-api-signing · vkbottle-types