$npx skillfedfor your agent

winkerberos

High level interface to SSPI for Kerberos client auth

With conditionsPyPI Authentication/DirectoryReleased Dec 20254.3M downloads / mopermissive licensePlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — winkerberos-0.13.0-cp310-cp310-win32.whl · winkerberos-0.13.0-cp310-cp310-win_amd64.whl · winkerberos-0.13.0-cp311-cp311-win32.whl
v0.13.0 · released 2025-12-03 · Python >=3.10

Yes, if you are on Windows and need Kerberos authentication. The package is actively maintained, has no external dependencies, carries a permissive license, and provides a straightforward API. Install friction is moderate due to compiled wheels, but prebuilt binaries are available for modern Python versions. Not applicable on non-Windows platforms.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Windows 7 / Windows Server 2008 R2 or newer required; Python 3.10+; requires SSPI support on the system.
  • Medium friction due to compiled binary wheels required for Windows.
  • Prebuilt wheels available for Python 3.10–3.14 on both 32-bit and 64-bit Windows.

License · maintenance · safety

permissive license (permissive) — Licensed under Apache License 2.0 (permissive). You may use, modify, and distribute the package freely in commercial and private projects, provided you include a copy of the license and document any changes you make.

last release 2025-12-03 (254 days) · last repo commit 2026-08-14 · 57 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 4,326,411 downloads/mo, #2,328 on PyPI

Verify before relying

import winkerberos as kerberos

status, ctx = kerberos.authGSSClientInit('service@host')
status = kerberos.authGSSClientStep(ctx, '')
response = kerberos.authGSSClientResponse(ctx)
  • Whether the package works on non-domain-joined Windows systems or requires Active Directory integration.
  • Support status for Python 3.14 (wheels are present but release notes do not explicitly confirm support).
  • Performance characteristics or known limitations when handling large authentication payloads.
Same gist for agents: .md · .json

What it is and what it does

WinKerberos is a native Kerberos client library for Windows that implements GSSAPI authentication using Microsoft's Security Support Provider Interface (SSPI). It mimics the API of pykerberos to provide a familiar interface for developers, but uses Windows' built-in Kerberos support rather than a separate implementation. The package handles the full SASL authentication handshake—initialization, challenge-response loops, wrapping/unwrapping of encrypted data, and channel binding for TLS—making it suitable for applications that need to authenticate against Kerberos-protected services from Windows.

The package is actively maintained and supports Python 3.10 through 3.14 on both 32-bit and 64-bit Windows. It has no external runtime dependencies beyond the Windows operating system itself. Installation is straightforward via pip when prebuilt wheels are available; building from source requires Visual Studio 2015 or newer. The API is documented through docstrings and examples in the repository, and the package is used in production by MongoDB and other projects requiring Windows-based Kerberos authentication.

Use it for

  • Authenticate Python applications against Active Directory or Kerberos-protected services on Windows without external Kerberos libraries.
  • Integrate Kerberos authentication into Windows-based microservices or database drivers that need SASL/GSSAPI support.
  • Implement single sign-on (SSO) flows in Windows desktop or server applications using the user's existing Kerberos credentials.
  • Add channel binding support to TLS connections for enhanced security in Windows environments.
  • Replace or supplement pykerberos in Windows-only deployments where native SSPI integration is preferred.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are on Windows and need Kerberos authentication.

The package is actively maintained, has no external dependencies, carries a permissive license, and provides a straightforward API. Install friction is moderate due to compiled wheels, but prebuilt binaries are available for modern Python versions. Not applicable on non-Windows platforms.

Install

winkerberos on PyPI

Before you install

Medium friction due to compiled binary wheels required for Windows. Prebuilt wheels available for Python 3.10–3.14 on both 32-bit and 64-bit Windows. If building from source, Visual Studio 2015 or newer is required. Package is actively maintained with recent releases.

Windows 7 / Windows Server 2008 R2 or newer required; Python 3.10+; requires SSPI support on the system.

License in practice

Licensed under Apache License 2.0 (permissive). You may use, modify, and distribute the package freely in commercial and private projects, provided you include a copy of the license and document any changes you make.

Quickstart

import winkerberos as kerberos

status, ctx = kerberos.authGSSClientInit('service@host')
status = kerberos.authGSSClientStep(ctx, '')
response = kerberos.authGSSClientResponse(ctx)

Verify before relying

  • Whether the package works on non-domain-joined Windows systems or requires Active Directory integration.
  • Support status for Python 3.14 (wheels are present but release notes do not explicitly confirm support).
  • Performance characteristics or known limitations when handling large authentication payloads.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.10
Install frictionMedium. Platform-specific wheel
Runtime dependenciesNone
MaintenanceActively maintained 254 days since the last release
Last repo commit
First released
Downloads4,326,411 / month, #2,328 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: Microsoft :: WindowsProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonTopic :: System :: Systems Administration :: Authentication/Directory

Evidence: winkerberos-0.13.0-cp310-cp310-win32.whl; winkerberos-0.13.0-cp310-cp310-win_amd64.whl; winkerberos-0.13.0-cp311-cp311-win32.whl; winkerberos-0.13.0-cp311-cp311-win_amd64.whl; winkerberos-0.13.0-cp312-cp312-win32.whl; winkerberos-0.13.0-cp312-cp312-win_amd64.whl; winkerberos-0.13.0-cp313-cp313-win32.whl; winkerberos-0.13.0-cp313-cp313-win_amd64.whl; winkerberos-0.13.0-cp314-cp314t-win32.whl; winkerberos-0.13.0-cp314-cp314t-win_amd64.whl; winkerberos-0.13.0-cp314-cp314-win32.whl; winkerberos-0.13.0-cp314-cp314-win_amd64.whl

Tags

Capabilities
windows kerberos authenticationsspi gssapi clientkerberos windows pythonwindows active directory authkerberos client sspigssapi windows implementationkerberos sasl windows
Topics
windows-onlyauthenticationkerberos
PyPI keywords
GSSAPIKerberosSSPI

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “windows kerberos authentication”

  • winkerberosProvides native Kerberos client authentication on Windows by wrapping…
  • pyspnegoHandles SPNEGO, NTLM, Kerberos, and CredSSP authentication protocols;…
  • requests-kerberosAdds Kerberos/GSSAPI authentication support to the requests HTTP…

Give your agent the search over MCP, or paste the wish link into any chat.

More Authentication/Directory packages

ldap3 Worth it
PyPI · Python Modules · released Jul 2021

ldap3 is a pure Python LDAP V3 client library that implements RFC 4510, providing both low-level LDAP operations and a high-level abstraction layer for directory queries and authentication.

Install it if you need to authenticate against or query LDAP directories.

LGPL-3.0-onlypure Python
18.9Mdownloads / mo
python3-openid With conditions
PyPI · Python Modules · released Jun 2020

Implements OpenID authentication protocol support for Python 3 servers and clients, allowing applications to delegate user authentication to OpenID providers.

However, be aware that active development stopped in 2020; if you require ongoing security patches or feature development, consider whether OpenID remains the right…

Apache-2.0pure Pythondormant
8.3Mdownloads / mo
ndg-httpsclient With conditions
PyPI · Scientific/Engineering · released Jul 2018

Provides enhanced HTTPS support for Python's httplib and urllib2 (or http.client and urllib in Python 3) by wrapping PyOpenSSL to enable full SSL peer verification using certificate validation.

BSD-3-Clausepure Python
6.5Mdownloads / mo
python-ldap With conditions
PyPI · Python Modules · released May 2026

Provides an object-oriented Python API to connect to and query LDAP directory servers, wrapping OpenLDAP client libraries and offering utilities for LDIF processing, LDAP URLs, and schema handling.

permissive licensebuilds from source · 3.6+
4.4Mdownloads / mo
django-two-factor-auth Worth it
PyPI · Security · released Sep 2025

Adds complete two-factor authentication to Django projects, supporting authentication via one-time passwords, SMS, call, token generator apps, and hardware tokens like YubiKey.

MITpure Python · 3.9+
3.1Mdownloads / mo
kerberos Skip
PyPI · Python Modules · released Jan 2021

Provides a high-level Python wrapper for Kerberos (GSSAPI) authentication operations, enabling client and server Kerberos authentication based on RFC 4559.

Apache-2.0compiled wheelabandoned1 known vulnerabilities
2.6Mdownloads / mo

See also pykerberos · sspilib · msldap · requests-kerberos · requests-gssapi · pyspnego · gssapi · pure-sasl · python-kadmin-rs