xmlsec
Python bindings for the XML Security Library
Decision gist · record as of 2026-08-14
Yes, if you need XML cryptographic operations. The package is production-stable, actively maintained, and has no known vulnerabilities. Install friction is moderate due to native library dependencies, but prebuilt wheels for common platforms ease deployment. Permissive MIT license poses no legal friction. Verify that libxml2 >= 2.9.1 and libxmlsec1 >= 1.2.33 are available on your target systems before committing.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires libxml2 >= 2.9.1 and libxmlsec1 >= 1.2.33 installed on the system before pip install
- Medium install friction due to compiled C extension requiring native libraries (libxml2 >= 2.9.1, libxmlsec1 >= 1.2.33).
- Prebuilt wheels available for Python 3.9–3.14 on macOS, Linux, and Windows reduce friction on common platforms.
License · maintenance · safety
MIT (permissive) — MIT license permits commercial and private use with minimal restrictions; no copyleft obligations or patent concerns.
last release 2025-11-11 (276 days) · last repo commit 2026-08-10 · 105 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 11,978,017 downloads/mo, #1,350 on PyPI
Alternatives
Verify before relying
pip install xmlsec
import xmlsec
# See xmlsec.readthedocs.io/en/latest/examples.html for signing and verification examples- Whether prebuilt wheels cover all target deployment architectures (riscv64 wheels present but platform adoption unclear)
- Performance characteristics for large-scale XML document signing or verification workflows
- Compatibility with specific XML Security Library versions beyond the stated minimum
What it is and what it does
xmlsec is a Python wrapper around the XML Security Library, a C library for cryptographic operations on XML documents. It lets you sign XML documents with digital certificates, verify signatures, and perform related cryptographic tasks. The package depends on lxml and requires system-level installation of libxml2 and libxmlsec1 before use.
The library is production-stable and actively maintained. It supports Python 3.9 through 3.14 and provides prebuilt wheels for most common platforms, though building from source on less common architectures may require manual compilation. Use it when you need to add XML signature or verification capabilities to applications handling XML-based security protocols.
Use it for
- Sign and verify XML documents in enterprise messaging systems
- Validate digitally signed XML in protocol implementations
- Implement XML encryption and decryption for sensitive data transport
- Verify XML signatures in web service communications
- Build systems requiring cryptographic proof of XML document authenticity
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need XML cryptographic operations.
The package is production-stable, actively maintained, and has no known vulnerabilities. Install friction is moderate due to native library dependencies, but prebuilt wheels for common platforms ease deployment. Permissive MIT license poses no legal friction. Verify that libxml2 >= 2.9.1 and libxmlsec1 >= 1.2.33 are available on your target systems before committing.
Install
xmlsec on PyPI
Before you install
Medium install friction due to compiled C extension requiring native libraries (libxml2 >= 2.9.1, libxmlsec1 >= 1.2.33). Prebuilt wheels available for Python 3.9–3.14 on macOS, Linux, and Windows reduce friction on common platforms. Repository is active with recent commits.
Requires libxml2 >= 2.9.1 and libxmlsec1 >= 1.2.33 installed on the system before pip install
License in practice
MIT license permits commercial and private use with minimal restrictions; no copyleft obligations or patent concerns.
Quickstart
pip install xmlsec
import xmlsec
# See xmlsec.readthedocs.io/en/latest/examples.html for signing and verification examples
Verify before relying
- Whether prebuilt wheels cover all target deployment architectures (riscv64 wheels present but platform adoption unclear)
- Performance characteristics for large-scale XML document signing or verification workflows
- Compatibility with specific XML Security Library versions beyond the stated minimum
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 1 packagelxml |
| Maintenance | Actively maintained 276 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 11,978,017 / month, #1,350 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: CProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: Text Processing :: Markup :: XMLTyping :: Typed |
Evidence: xmlsec-1.3.17-cp310-cp310-macosx_10_9_x86_64.whl; xmlsec-1.3.17-cp310-cp310-macosx_11_0_arm64.whl; xmlsec-1.3.17-cp310-cp310-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; xmlsec-1.3.17-cp310-cp310-manylinux_2_26_x86_64.manylinux_2_28_x86_64.whl; xmlsec-1.3.17-cp310-cp310-manylinux_2_38_riscv64.manylinux_2_39_riscv64.whl; xmlsec-1.3.17-cp310-cp310-musllinux_1_2_aarch64.whl; xmlsec-1.3.17-cp310-cp310-musllinux_1_2_x86_64.whl; xmlsec-1.3.17-cp310-cp310-win_amd64.whl; xmlsec-1.3.17-cp310-cp310-win_arm64.whl; xmlsec-1.3.17-cp311-cp311-macosx_10_9_x86_64.whl; xmlsec-1.3.17-cp311-cp311-macosx_11_0_arm64.whl; xmlsec-1.3.17-cp311-cp311-manylinux_2_26_aarch64.manylinux_2_28_aarch64.whl; xmlsec-1.3.17-cp311-cp311-manylinux_2_26_x86_64.manylinux_2_28_x86_64.whl; xmlsec-1.3.17-cp311-cp311-manylinux_2_38_riscv64.manylinux_2_39_riscv64.whl; xmlsec-1.3.17-cp311-cp311-musllinux_1_2_aarch64.whl; xmlsec-1.3.17-cp311-cp311-musllinux_1_2_x86_64.whl; xmlsec-1.3.17-cp311-cp311-win_amd64.whl; xmlsec-1.3.17-cp311-cp311-win_arm64.whl; xmlsec-1.3.17-cp312-cp312-macosx_10_13_x86_64.whl; xmlsec-1.3.17-cp312-cp312-macosx_11_0_arm64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “xml signing verification”
- xmlsecPython bindings for XML Security Library, enabling cryptographic…
- endesiveEndesive signs and verifies digital signatures in PDF, S/MIME email,…
- signxmlSignXML implements W3C XML Signature (XMLDSig) standard for signing…
Give your agent the search over MCP, or paste the wish link into any chat.
More XML packages
Beautiful Soup parses HTML and XML documents into a navigable tree, providing Pythonic methods to search, iterate, and modify the parsed content.
Install it if you need to parse or extract data from markup documents.
lxml provides Python bindings to libxml2 and libxslt, enabling parsing, validation, and transformation of XML and HTML documents through an ElementTree-compatible API with support for XPath, XSLT, and schema validation.
Install it if you need robust XML/HTML parsing, validation, or transformation; avoid it only if you must stay pure-Python and can accept slower performance.
Defusedxml hardens Python's standard XML libraries against XML bomb attacks and entity expansion exploits by providing drop-in replacements that disable dangerous parsing features by default.
Install it if your application parses any XML from untrusted sources.
Docutils converts plaintext documentation in reStructuredText format into multiple output formats including HTML, XML, and LaTeX using a modular processing system.
Converts XML to Python dictionaries and back, treating XML parsing and generation like working with JSON.
Sphinx generates professional documentation from reStructuredText source files, producing HTML, PDF, EPUB, and other formats with automatic cross-references, code highlighting, and hierarchical navigation.
See also endesive · securesystemslib · signxml · pysaml2 · python3-saml · python-gnupg · rsa · standardwebhooks