This release is a pre-release and may not be stable for production use.
idaas-python-akless-tencent-adapter
English | 简体中文
Python SDK for the IDaaS (Identity as a Service) AKless Adapter — obtain STS temporary credentials through IDaaS PAM (Privileged Access Management) to access Tencent Cloud services without SecretKey.
Features
- AK-Free Authentication: No long-term SecretKey required. Uses OIDC Token to obtain STS temporary credentials via IDaaS PAM, reducing the risk of credential leakage
- Multi-SDK Adaptation: Provides credential provider adapters for multiple Tencent Cloud official SDKs, including Tencent Cloud SDK and COS SDK
- Auto Credential Refresh: Built-in credential caching and expiration-based auto-refresh mechanism to ensure seamless credential rotation
- Easy Integration: Factory class provides one-line credential provider creation, minimizing integration cost
Requirements
- Python >= 3.9
- Dependencies:
- cloud-idaas-core >= 0.0.5-beta
Installation
pip install cloud-idaas-akless-tencent-adapter
Prerequisites
This SDK depends on cloud-idaas-core. You need to complete the IDaaS Core SDK initialization before using this adapter.
-
Install and configure
cloud-idaas-core. See cloud-idaas-core README for details. -
In the configuration file, set the
scopeto the IDaaS PAM built-in scope:{ "scope": "urn:cloud:idaas:pam|cloud_account_role:obtain_access_credential" }
-
Complete the IDaaS Core SDK initialization:
from cloud_idaas.core import IDaaSCredentialProviderFactory IDaaSCredentialProviderFactory.init()
Quick Start
The simplest way to use this SDK is through the IDaaSPamAklessCredentialFactory factory class:
from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.tencentcloud.pam import IDaaSPamAklessCredentialFactory
# 1. Initialize IDaaS Core SDK
IDaaSCredentialProviderFactory.init()
# 2. Create Tencent Cloud credentials provider
credentials_provider = IDaaSPamAklessCredentialFactory.get_tencent_cloud_credentials_provider(
role_arn="your-role-arn"
)
# 3. Get credentials
credential = credentials_provider.get_credentials()
print(credential.secretId)
print(credential.secretKey)
print(credential.token)
Usage Examples
Tencent Cloud SDK (tencentcloud-sdk-python)
from tencentcloud.cvm.v20170312 import cvm_client
from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.tencentcloud.pam import IDaaSPamAklessCredentialFactory
# Initialize
IDaaSCredentialProviderFactory.init()
# Create Tencent Cloud credentials provider
credentials_provider = IDaaSPamAklessCredentialFactory.get_tencent_cloud_credentials_provider(
role_arn="your-role-arn"
)
# Get credentials and use with Tencent Cloud SDK
credential = credentials_provider.get_credentials()
client = cvm_client.CvmClient(credential, "ap-guangzhou")
COS (cos-python-sdk-v5)
from qcloud_cos import CosS3Client
from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.tencentcloud.pam import IDaaSPamAklessCredentialFactory
# Initialize
IDaaSCredentialProviderFactory.init()
# Create COS credentials provider
cos_provider = IDaaSPamAklessCredentialFactory.get_cos_credential_provider(
role_arn="your-role-arn"
)
# Use with COS SDK
cos_config = cos_provider.get_cos_config(region="ap-guangzhou")
cos_client = CosS3Client(cos_config)
API Reference
IDaaSPamAklessCredentialFactory
Factory class providing static methods to create credential providers.
| Method | Return Type | Description |
|---|---|---|
get_tencent_cloud_credentials_provider(role_arn) |
IDaaSPamTencentCloudCredentialsProvider |
Create a Tencent Cloud credentials provider |
get_cos_credential_provider(role_arn) |
IDaaSPamTencentCloudCOSCredentialsProvider |
Create a COS SDK credentials provider |
Environment Variables
| Variable | Description |
|---|---|
CLOUD_IDAAS_CONFIG_PATH |
IDaaS configuration file path |
TENCENT_CLOUD_ROLE_ARN |
Fallback for the cloud-account role ARN |
TENCENT_CLOUD_OIDC_TOKEN_FILE |
Path to an OIDC token file (used when no oidc_token_provider is given) |
Support & Feedback
- Email: cloudidaas@list.alibaba-inc.com
- Issues: For questions or suggestions, please submit an Issue
License
This project is licensed under the Apache License 2.0.
Release files for cloud-idaas-akless-tencent-adapter 0.0.1b0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cloud_idaas_akless_tencent_adapter-0.0.1b0.tar.gz | 17.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cloud_idaas_akless_tencent_adapter-0.0.1b0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 32.0 kB
Release files / cloud_idaas_akless_tencent_adapter-0.0.1b0.tar.gz
| Download URL | cloud_idaas_akless_tencent_adapter-0.0.1b0.tar.gz |
|---|---|
| Size | 17.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
14ecb5f767ee533ccaaee25260a5e0475ecc89c80c791a31ad734af2013a8037
|
|
BLAKE2b-256 checksum How to use checksums |
f72e661b511ed173a9ff54003f197f64c9bd92b178024d85f56120c496321b30
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 22, 2026.
Transparency logRelease files / cloud_idaas_akless_tencent_adapter-0.0.1b0-py3-none-any.whl
| Download URL | cloud_idaas_akless_tencent_adapter-0.0.1b0-py3-none-any.whl |
|---|---|
| Size | 14.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
34d687c52a1c567cf67027fea1b5c467b89db455494c5cffd558bc793886ee8e
|
|
BLAKE2b-256 checksum How to use checksums |
e78e7b106f30a6fef0bd195649e46a3f3cff5d9120904fedd85c1075e0b4692a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 22, 2026.
Transparency log