This release is a pre-release and may not be stable for production use.
bella-baxter
Python SDK for the Bella Baxter secrets management platform. Includes built-in end-to-end encryption and webhook signature verification.
When to use bella-baxter directly
Most applications should use a framework integration instead:
| Framework | Package |
|---|---|
| Django | bella-baxter-django |
| FastAPI | bella-baxter-fastapi |
| Flask | bella-baxter-flask |
| Scripts, tools, custom integrations | bella-baxter (this package) |
Installation
pip install bella-baxter
Quickstart
from bella_baxter import BaxterClient, BaxterClientOptions
client = BaxterClient(BaxterClientOptions(
baxter_url="https://api.bella-baxter.io",
api_key="bax-...",
))
# Fetch all secrets (sync — works in Django, Flask, scripts)
secrets = client.get_all_secrets()
db_url = secrets.secrets["DATABASE_URL"]
# Async (FastAPI, asyncio)
secrets = await client.get_all_secrets_async()
Authentication
API key (recommended for apps and CI/CD)
# Generate a key via the CLI
bella api-keys create --env production --name "MyApp Production"
# Returns: bax-<keyId>-<secret>
import os
from bella_baxter import BaxterClient, BaxterClientOptions
client = BaxterClient(BaxterClientOptions(
baxter_url=os.environ["BELLA_BAXTER_URL"],
api_key=os.environ["BELLA_BAXTER_API_KEY"],
))
API keys encode the project and environment slug — no config file needed.
Generate via bella api-keys create or the Bella WebApp.
OAuth (local dev)
bella login # opens browser, stores token in .bella file
bella exec -- python app.py # injects BELLA_BAXTER_API_KEY + BELLA_BAXTER_URL automatically
End-to-end encryption
Secret values are encrypted client-side using ECIES (Elliptic Curve Integrated Encryption Scheme) before being sent to the Baxter API. Decryption happens transparently in the SDK.
E2EE is included — no extra install needed (cryptography>=41 is a core dependency).
Lightweight version polling
For long-running processes that need to detect secret rotations:
# Check if secrets have changed without fetching values
version = client.get_secrets_version()
if version.version != last_known_version:
secrets = client.get_all_secrets()
last_known_version = version.version
Webhook signature verification
from bella_baxter import verify_webhook_signature
is_valid = verify_webhook_signature(
payload=request.body,
signature_header=request.headers["X-Bella-Signature"],
secret="whsec-...",
)
Full API access (Kiota client)
# Access the underlying Kiota client for full API coverage
kiota = client.client
# List projects
projects = await kiota.api.v1.projects.get()
# Manage environments, providers, users, API keys, etc.
Regenerating the generated client
bella-baxter embeds a Kiota-generated HTTP client. To regenerate after an API change:
cd apps/sdk
./generate.sh
Release files for bella-baxter 0.1.1rc101
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| bella_baxter-0.1.1rc101.tar.gz | 173.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| bella_baxter-0.1.1rc101-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 967.3 kB
Release files / bella_baxter-0.1.1rc101.tar.gz
| Download URL | bella_baxter-0.1.1rc101.tar.gz |
|---|---|
| Size | 173.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7e527e171b44847fa95b716b8b7316e321e9e29b2a78f6f6ad86a9767d9a45f0
|
|
BLAKE2b-256 checksum How to use checksums |
40588dff5ee8c7a2081c0a0fc2435dc298a765f672ef72641c3bd97be0bfe042
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.
Transparency logRelease files / bella_baxter-0.1.1rc101-py3-none-any.whl
| Download URL | bella_baxter-0.1.1rc101-py3-none-any.whl |
|---|---|
| Size | 794.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8acc08fcea2fd754f30871f8d8f253f7f6eaac356a2b0d7097906e166a351891
|
|
BLAKE2b-256 checksum How to use checksums |
052da106053d6261183b829ec9e45d4d62db99dc3adeb79c58450a1519329431
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.
Transparency log