Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

bella-baxter

Python SDK for the Bella Baxter secrets management platform. Includes built-in end-to-end encryption and webhook signature verification.

When to use bella-baxter directly

Most applications should use a framework integration instead:

Framework Package
Django bella-baxter-django
FastAPI bella-baxter-fastapi
Flask bella-baxter-flask
Scripts, tools, custom integrations bella-baxter (this package)

Installation

pip install bella-baxter

Quickstart

from bella_baxter import BaxterClient, BaxterClientOptions

client = BaxterClient(BaxterClientOptions(
    baxter_url="https://api.bella-baxter.io",
    api_key="bax-...",
))

# Fetch all secrets (sync — works in Django, Flask, scripts)
secrets = client.get_all_secrets()
db_url = secrets.secrets["DATABASE_URL"]

# Async (FastAPI, asyncio)
secrets = await client.get_all_secrets_async()

Authentication

API key (recommended for apps and CI/CD)

# Generate a key via the CLI
bella api-keys create --env production --name "MyApp Production"
# Returns: bax-<keyId>-<secret>
import os
from bella_baxter import BaxterClient, BaxterClientOptions

client = BaxterClient(BaxterClientOptions(
    baxter_url=os.environ["BELLA_BAXTER_URL"],
    api_key=os.environ["BELLA_BAXTER_API_KEY"],
))

API keys encode the project and environment slug — no config file needed. Generate via bella api-keys create or the Bella WebApp.

OAuth (local dev)

bella login           # opens browser, stores token in .bella file
bella exec -- python app.py   # injects BELLA_BAXTER_API_KEY + BELLA_BAXTER_URL automatically

End-to-end encryption

Secret values are encrypted client-side using ECIES (Elliptic Curve Integrated Encryption Scheme) before being sent to the Baxter API. Decryption happens transparently in the SDK.

E2EE is included — no extra install needed (cryptography>=41 is a core dependency).

Lightweight version polling

For long-running processes that need to detect secret rotations:

# Check if secrets have changed without fetching values
version = client.get_secrets_version()
if version.version != last_known_version:
    secrets = client.get_all_secrets()
    last_known_version = version.version

Webhook signature verification

from bella_baxter import verify_webhook_signature

is_valid = verify_webhook_signature(
    payload=request.body,
    signature_header=request.headers["X-Bella-Signature"],
    secret="whsec-...",
)

Full API access (Kiota client)

# Access the underlying Kiota client for full API coverage
kiota = client.client

# List projects
projects = await kiota.api.v1.projects.get()

# Manage environments, providers, users, API keys, etc.

Regenerating the generated client

bella-baxter embeds a Kiota-generated HTTP client. To regenerate after an API change:

cd apps/sdk
./generate.sh

Release files for bella-baxter 0.1.1rc101

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bella-baxter 0.1.1rc101
File Size Uploaded
bella_baxter-0.1.1rc101.tar.gz 173.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for bella-baxter 0.1.1rc101
File Interpreter ABI Platform
bella_baxter-0.1.1rc101-py3-none-any.whl Python 3 none any Details

Total release size: 967.3 kB

Release files / bella_baxter-0.1.1rc101.tar.gz

Download URL bella_baxter-0.1.1rc101.tar.gz
Size 173.3 kB
Tags Source
SHA-256 checksum
How to use checksums
7e527e171b44847fa95b716b8b7316e321e9e29b2a78f6f6ad86a9767d9a45f0
BLAKE2b-256 checksum
How to use checksums
40588dff5ee8c7a2081c0a0fc2435dc298a765f672ef72641c3bd97be0bfe042
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.

Transparency log

Release files / bella_baxter-0.1.1rc101-py3-none-any.whl

Download URL bella_baxter-0.1.1rc101-py3-none-any.whl
Size 794.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8acc08fcea2fd754f30871f8d8f253f7f6eaac356a2b0d7097906e166a351891
BLAKE2b-256 checksum
How to use checksums
052da106053d6261183b829ec9e45d4d62db99dc3adeb79c58450a1519329431
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1rc101 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page