$npx skillfedfor your agent

truststore

Verify certificates using native system trust stores

With conditionsPyPI CryptographyReleased Aug 202587.1M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — truststore-0.10.4-py3-none-any.whl
v0.10.4 · released 2025-08-12 · Python >=3.10

Yes, if you are on Python 3.10+ and want to leverage your system's certificate management instead of relying on a static bundle. The low install friction, permissive license, and production-stable status make it a straightforward upgrade. The 367-day gap since the last release is worth noting—check the repository for recent activity before adopting in security-critical applications—but the package has no known vulnerabilities.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; supports macOS 10.8+, Windows, and Linux with OpenSSL.
  • Low friction installation as a pure Python wheel.
  • Maintenance status is aging with the last release 367 days ago, though the repository remains active and the package is marked Production/Stable.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal restrictions, making it suitable for both open-source and proprietary projects.

last release 2025-08-12 (367 days) · last repo commit 2025-11-28 · 240 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 87,096,308 downloads/mo, #389 on PyPI

Verify before relying

pip install truststore

import truststore
ctx = truststore.SSLContext()

# Use with any HTTP library that accepts ssl_context parameter
  • Whether the 367-day release gap indicates active maintenance or dormancy despite the recent commit date.
  • Performance overhead compared to certifi when using system certificate stores.
  • Compatibility with all HTTP libraries beyond those mentioned in the description.
Same gist for agents: .md · .json

What it is and what it does

Truststore is a library that bridges Python's SSL certificate verification to the native certificate stores built into your operating system—macOS Security framework, Windows CryptoAPI, or Linux OpenSSL. Instead of bundling a static list of certificate authorities (as certifi does), it lets your application use the same trust decisions your OS makes, which means certificates update automatically when your system updates them, intermediate certificates can be fetched on demand, and certificate revocation lists are checked to prevent man-in-the-middle attacks.

You can inject it globally into Python's ssl module so that every HTTP library in your application automatically uses the system store, or you can create a truststore.SSLContext instance for fine-grained control in libraries and packages. The package is already integrated into pip 24.2+ as the default verification method, with a fallback to certifi when needed.

Use it for

  • Replace certifi in applications where system certificate management is preferred over bundled CA lists.
  • Ensure HTTPS requests automatically respect corporate or organizational certificate policies managed at the OS level.
  • Reduce certificate maintenance burden by delegating updates to the operating system instead of application deployments.
  • Verify certificates against revocation lists to detect and prevent compromised CAs from being used.
  • Use in libraries that need SSL context control without forcing a specific certificate bundle on downstream users.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are on Python 3.10+ and want to leverage your system's certificate management instead of relying on a static bundle.

The low install friction, permissive license, and production-stable status make it a straightforward upgrade. The 367-day gap since the last release is worth noting—check the repository for recent activity before adopting in security-critical applications—but the package has no known vulnerabilities.

Install

truststore on PyPI

Before you install

Low friction installation as a pure Python wheel. Maintenance status is aging with the last release 367 days ago, though the repository remains active and the package is marked Production/Stable.

Requires Python 3.10 or later; supports macOS 10.8+, Windows, and Linux with OpenSSL.

License in practice

MIT license permits unrestricted use, modification, and distribution with minimal restrictions, making it suitable for both open-source and proprietary projects.

Quickstart

pip install truststore

import truststore
ctx = truststore.SSLContext()

# Use with any HTTP library that accepts ssl_context parameter

Verify before relying

  • Whether the 367-day release gap indicates active maintenance or dormancy despite the recent commit date.
  • Performance overhead compared to certifi when using system certificate stores.
  • Compatibility with all HTTP libraries beyond those mentioned in the description.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceAging 367 days since the last release
Last repo commit
First released
Downloads87,096,308 / month, #389 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersOperating System :: MacOSOperating System :: MicrosoftProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy

Evidence: truststore-0.10.4-py3-none-any.whl

Tags

Capabilities
system certificate store pythonnative ssl context verificationreplace certifi with system certsos trust store integrationhttps certificate validation
Topics
ssl-tlscertificate-verificationsystem-integration

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “system certificate store python”

  • truststoreTruststore exposes native system certificate stores through an SSL…
  • wincertstoreAccesses Windows system certificate stores (CA and CRL) via ctypes…
  • wassimaWassima provides access to your operating system's root certificate…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also pip-system-certs · wassima · aia · certifi-linux · python-certifi-win32 · wincertstore · mscerts · requests-pkcs12 · pyjks