Skip to main content

artifacts-keyring-nofuss

CI

⚠️ This is an unsupported Microsoft sample. Unlike artifacts-keyring, this project is a best-effort alternative focused on convenience (more auth auto-detection, reuse of existing az CLI logins) and debuggability (pure Python — no opaque .NET binary). It is not covered by any Microsoft support program — use at your own risk.

Minimal, pure-Python keyring backend for Azure DevOps Artifacts feeds. Replaces the official artifacts-keyring (which wraps a ~100 MB .NET binary) with a no-fuss, pure-Python implementation — no .NET required.

📖 Documentation

Full docs: https://microsoft.github.io/artifacts-keyring-nofuss/

Page What's inside
Home Install and a scenario picker.
Local development Install packages locally with an az login.
pip & uv setup Turn on the keyring provider once.
GitHub Actions OIDC installs and the Docker composite action.
Docker builds BuildKit secrets and minting a token without az.
GitHub Codespaces The artifacts-helper devcontainer feature.
Managed identity & service principals MI, service principals, and workload identity.
Pre-minted tokens Supply a bearer token via env var or file.
How it works Auth flows, priority order, security model.
Reference Install options, CLI, env vars, feed URLs, troubleshooting.

Quickstart

Install keyring plus this backend as an isolated standalone tool:

uv tool install keyring --with artifacts-keyring-nofuss

Then point your package manager at your private feed — the backend discovers the tenant and obtains credentials automatically:

# pip
pip install --keyring-provider=subprocess \
    --index-url https://pkgs.dev.azure.com/{org}/_packaging/{feed}/pypi/simple/ \
    my-package

# uv
uv pip install my-package \
    --index-url https://__token__@pkgs.dev.azure.com/{org}/_packaging/{feed}/pypi/simple/

See the documentation site for CI, Docker, service principal, and Codespaces setups.

Development

pip install -e ".[dev]"

License

Licensed under the MIT License.

Security

See SECURITY.md for how to report security issues.

Metadata

Release files for artifacts-keyring-nofuss 1.3.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for artifacts-keyring-nofuss 1.3.2
File Size Uploaded
artifacts_keyring_nofuss-1.3.2.tar.gz 58.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for artifacts-keyring-nofuss 1.3.2
File Interpreter ABI Platform
artifacts_keyring_nofuss-1.3.2-py3-none-any.whl Python 3 none any Details

Total release size: 95.2 kB

Release files / artifacts_keyring_nofuss-1.3.2.tar.gz

Download URL artifacts_keyring_nofuss-1.3.2.tar.gz
Size 58.2 kB
Tags Source
SHA-256 checksum
How to use checksums
efc6bfd0aa5978c4219d0b5798ef64c16369a75d2edb130fb6bc132ce26087b8
BLAKE2b-256 checksum
How to use checksums
28d15ff338bad9f5ff77fa02e100a8557b3aeb0045799cf394931fb9ae6e3be3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / artifacts_keyring_nofuss-1.3.2-py3-none-any.whl

Download URL artifacts_keyring_nofuss-1.3.2-py3-none-any.whl
Size 37.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9eab176364188633ce1cf1841ab9484a40f85c31e6e18a69a516b7e53d78cddd
BLAKE2b-256 checksum
How to use checksums
e2f3a9f9b2ab43d09d591ed4ab718889a97691f92399ba3f1438bbfcb4696efb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

1.3.3

2 release files

This release

1.3.2 This release

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.4

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.1

2 release files

1.0.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page