Skip to main content

artifacts-keyring-nofuss

CI

⚠️ This is an unsupported Microsoft sample. Unlike artifacts-keyring, this project is a best-effort alternative focused on convenience (more auth auto-detection, reuse of existing az CLI logins) and debuggability (pure Python — no opaque .NET binary). It is not covered by any Microsoft support program — use at your own risk.

Minimal, pure-Python keyring backend for Azure DevOps Artifacts feeds. Replaces the official artifacts-keyring (which wraps a ~100 MB .NET binary) with a no-fuss, pure-Python implementation — no .NET required.

📖 Documentation

Full docs: https://microsoft.github.io/artifacts-keyring-nofuss/

Page What's inside
Home Install and a scenario picker.
Local development Install packages locally with an az login.
pip & uv setup Turn on the keyring provider once.
GitHub Actions OIDC installs and the Docker composite action.
Docker builds BuildKit secrets and minting a token without az.
GitHub Codespaces The artifacts-helper devcontainer feature.
Managed identity & service principals MI, service principals, and workload identity.
Pre-minted tokens Supply a bearer token via env var or file.
How it works Auth flows, priority order, security model.
Reference Install options, CLI, env vars, feed URLs, troubleshooting.

Quickstart

Install keyring plus this backend as an isolated standalone tool:

uv tool install keyring --with artifacts-keyring-nofuss

Then point your package manager at your private feed — the backend discovers the tenant and obtains credentials automatically:

# pip
pip install --keyring-provider=subprocess \
    --index-url https://pkgs.dev.azure.com/{org}/_packaging/{feed}/pypi/simple/ \
    my-package

# uv
uv pip install my-package \
    --index-url https://__token__@pkgs.dev.azure.com/{org}/_packaging/{feed}/pypi/simple/

See the documentation site for CI, Docker, service principal, and Codespaces setups.

Development

pip install -e ".[dev]"

License

Licensed under the MIT License.

Security

See SECURITY.md for how to report security issues.

Metadata

Release files for artifacts-keyring-nofuss 1.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for artifacts-keyring-nofuss 1.3.1
File Size Uploaded
artifacts_keyring_nofuss-1.3.1.tar.gz 58.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for artifacts-keyring-nofuss 1.3.1
File Interpreter ABI Platform
artifacts_keyring_nofuss-1.3.1-py3-none-any.whl Python 3 none any Details

Total release size: 95.1 kB

Release files / artifacts_keyring_nofuss-1.3.1.tar.gz

Download URL artifacts_keyring_nofuss-1.3.1.tar.gz
Size 58.2 kB
Tags Source
SHA-256 checksum
How to use checksums
98a31caab8327f963d0adda37d8eb0ce93dc84587a31aaae0be096216215933d
BLAKE2b-256 checksum
How to use checksums
1d5072a81735322a7007325cf14bef32e129129590a3b20ceb6ff2c0e7298ca9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / artifacts_keyring_nofuss-1.3.1-py3-none-any.whl

Download URL artifacts_keyring_nofuss-1.3.1-py3-none-any.whl
Size 37.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5dcf2aed513813c06a8f1fc023c7d63487bba9caab4e864a8b402c9dc4351e20
BLAKE2b-256 checksum
How to use checksums
582e07e37db6d91e0de835508d002545c2a04cf26100bd9d06b503b826671b96
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release history Release notifications | RSS feed

1.3.3

2 release files

1.3.2

2 release files

This release

1.3.1 This release

2 release files

1.3.0

2 release files

1.2.4

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.1

2 release files

1.0.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page