Skip to main content

artifacts-keyring-nofuss

CI

⚠️ This is an unsupported Microsoft sample. Unlike artifacts-keyring, this project is a best-effort alternative focused on convenience (more auth auto-detection, reuse of existing az CLI logins) and debuggability (pure Python — no opaque .NET binary). It is not covered by any Microsoft support program — use at your own risk.

Minimal, pure-Python keyring backend for Azure DevOps Artifacts feeds. Replaces the official artifacts-keyring (which wraps a ~100 MB .NET binary) with a no-fuss, pure-Python implementation — no .NET required.

📖 Documentation

Full docs: https://microsoft.github.io/artifacts-keyring-nofuss/

Page What's inside
Home Install and a scenario picker.
Local development Install packages locally with an az login.
pip & uv setup Turn on the keyring provider once.
GitHub Actions OIDC installs and the Docker composite action.
Docker builds BuildKit secrets and minting a token without az.
GitHub Codespaces The artifacts-helper devcontainer feature.
Managed identity & service principals MI, service principals, and workload identity.
Pre-minted tokens Supply a bearer token via env var or file.
How it works Auth flows, priority order, security model.
Reference Install options, CLI, env vars, feed URLs, troubleshooting.

Quickstart

Install keyring plus this backend as an isolated standalone tool:

uv tool install keyring --with artifacts-keyring-nofuss

Then point your package manager at your private feed — the backend discovers the tenant and obtains credentials automatically:

# pip
pip install --keyring-provider=subprocess \
    --index-url https://pkgs.dev.azure.com/{org}/_packaging/{feed}/pypi/simple/ \
    my-package

# uv
uv pip install my-package \
    --index-url https://__token__@pkgs.dev.azure.com/{org}/_packaging/{feed}/pypi/simple/

See the documentation site for CI, Docker, service principal, and Codespaces setups.

Development

pip install -e ".[dev]"

License

Licensed under the MIT License.

Security

See SECURITY.md for how to report security issues.

Metadata

Release files for artifacts-keyring-nofuss 1.3.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for artifacts-keyring-nofuss 1.3.3
File Size Uploaded
artifacts_keyring_nofuss-1.3.3.tar.gz 58.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for artifacts-keyring-nofuss 1.3.3
File Interpreter ABI Platform
artifacts_keyring_nofuss-1.3.3-py3-none-any.whl Python 3 none any Details

Total release size: 95.2 kB

Release files / artifacts_keyring_nofuss-1.3.3.tar.gz

Download URL artifacts_keyring_nofuss-1.3.3.tar.gz
Size 58.2 kB
Tags Source
SHA-256 checksum
How to use checksums
cf365050ac67bbdb16693cf8de4036c977ffaaba660cf8283fed2f56ed1458f3
BLAKE2b-256 checksum
How to use checksums
4818eb5cab686fbe2a0a2cb2a3c80f7bd7585fb7de8b62c12ebadd404ba06b98
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / artifacts_keyring_nofuss-1.3.3-py3-none-any.whl

Download URL artifacts_keyring_nofuss-1.3.3-py3-none-any.whl
Size 37.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4f2648504a9432e2a11ab3d91a5f57ef995bf37431f1c2c9db012e2509ce90ba
BLAKE2b-256 checksum
How to use checksums
e47721dc35c666a9089b3de64d4b6f9f670971822dfa3bbeea7a6d1126e37ebe
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.3.3 This release

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.4

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.1

2 release files

1.0.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page