Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

idaas-python-akless-tencent-adapter

Python Version License Development Status Version

English | 简体中文

Python SDK for the IDaaS (Identity as a Service) AKless Adapter — obtain STS temporary credentials through IDaaS PAM (Privileged Access Management) to access Tencent Cloud services without SecretKey.

Features

  • AK-Free Authentication: No long-term SecretKey required. Uses OIDC Token to obtain STS temporary credentials via IDaaS PAM, reducing the risk of credential leakage
  • Multi-SDK Adaptation: Provides credential provider adapters for multiple Tencent Cloud official SDKs, including Tencent Cloud SDK and COS SDK
  • Auto Credential Refresh: Built-in credential caching and expiration-based auto-refresh mechanism to ensure seamless credential rotation
  • Easy Integration: Factory class provides one-line credential provider creation, minimizing integration cost

Requirements

  • Python >= 3.9
  • Dependencies:
    • cloud-idaas-core >= 0.0.5-beta

Installation

pip install cloud-idaas-akless-tencent-adapter

Prerequisites

This SDK depends on cloud-idaas-core. You need to complete the IDaaS Core SDK initialization before using this adapter.

  1. Install and configure cloud-idaas-core. See cloud-idaas-core README for details.

  2. In the configuration file, set the scope to the IDaaS PAM built-in scope:

    {
        "scope": "urn:cloud:idaas:pam|cloud_account_role:obtain_access_credential"
    }
    
  3. Complete the IDaaS Core SDK initialization:

    from cloud_idaas.core import IDaaSCredentialProviderFactory
    
    IDaaSCredentialProviderFactory.init()
    

Quick Start

The simplest way to use this SDK is through the IDaaSPamAklessCredentialFactory factory class:

from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.tencentcloud.pam import IDaaSPamAklessCredentialFactory

# 1. Initialize IDaaS Core SDK
IDaaSCredentialProviderFactory.init()

# 2. Create Tencent Cloud credentials provider
credentials_provider = IDaaSPamAklessCredentialFactory.get_tencent_cloud_credentials_provider(
    role_arn="your-role-arn"
)

# 3. Get credentials
credential = credentials_provider.get_credentials()
print(credential.secretId)
print(credential.secretKey)
print(credential.token)

Usage Examples

Tencent Cloud SDK (tencentcloud-sdk-python)

from tencentcloud.cvm.v20170312 import cvm_client
from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.tencentcloud.pam import IDaaSPamAklessCredentialFactory

# Initialize
IDaaSCredentialProviderFactory.init()

# Create Tencent Cloud credentials provider
credentials_provider = IDaaSPamAklessCredentialFactory.get_tencent_cloud_credentials_provider(
    role_arn="your-role-arn"
)

# Get credentials and use with Tencent Cloud SDK
credential = credentials_provider.get_credentials()
client = cvm_client.CvmClient(credential, "ap-guangzhou")

COS (cos-python-sdk-v5)

from qcloud_cos import CosS3Client
from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.tencentcloud.pam import IDaaSPamAklessCredentialFactory

# Initialize
IDaaSCredentialProviderFactory.init()

# Create COS credentials provider
cos_provider = IDaaSPamAklessCredentialFactory.get_cos_credential_provider(
    role_arn="your-role-arn"
)

# Use with COS SDK
cos_config = cos_provider.get_cos_config(region="ap-guangzhou")
cos_client = CosS3Client(cos_config)

API Reference

IDaaSPamAklessCredentialFactory

Factory class providing static methods to create credential providers.

Method Return Type Description
get_tencent_cloud_credentials_provider(role_arn) IDaaSPamTencentCloudCredentialsProvider Create a Tencent Cloud credentials provider
get_cos_credential_provider(role_arn) IDaaSPamTencentCloudCOSCredentialsProvider Create a COS SDK credentials provider

Environment Variables

Variable Description
CLOUD_IDAAS_CONFIG_PATH IDaaS configuration file path
TENCENT_CLOUD_ROLE_ARN Fallback for the cloud-account role ARN
TENCENT_CLOUD_OIDC_TOKEN_FILE Path to an OIDC token file (used when no oidc_token_provider is given)

Support & Feedback

License

This project is licensed under the Apache License 2.0.

Release files for cloud-idaas-akless-tencent-adapter 0.0.1b0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cloud-idaas-akless-tencent-adapter 0.0.1b0
File Size Uploaded
cloud_idaas_akless_tencent_adapter-0.0.1b0.tar.gz 17.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cloud-idaas-akless-tencent-adapter 0.0.1b0
File Interpreter ABI Platform
cloud_idaas_akless_tencent_adapter-0.0.1b0-py3-none-any.whl Python 3 none any Details

Total release size: 32.0 kB

Release files / cloud_idaas_akless_tencent_adapter-0.0.1b0.tar.gz

Download URL cloud_idaas_akless_tencent_adapter-0.0.1b0.tar.gz
Size 17.2 kB
Tags Source
SHA-256 checksum
How to use checksums
14ecb5f767ee533ccaaee25260a5e0475ecc89c80c791a31ad734af2013a8037
BLAKE2b-256 checksum
How to use checksums
f72e661b511ed173a9ff54003f197f64c9bd92b178024d85f56120c496321b30
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 22, 2026.

Transparency log

Release files / cloud_idaas_akless_tencent_adapter-0.0.1b0-py3-none-any.whl

Download URL cloud_idaas_akless_tencent_adapter-0.0.1b0-py3-none-any.whl
Size 14.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
34d687c52a1c567cf67027fea1b5c467b89db455494c5cffd558bc793886ee8e
BLAKE2b-256 checksum
How to use checksums
e78e7b106f30a6fef0bd195649e46a3f3cff5d9120904fedd85c1075e0b4692a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 22, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.1b0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page