Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

kmip-python

CI Security License

KMIP client for Python -- connect to any KMIP-compliant key management server.

Supports Thales CipherTrust, IBM SKLM, Entrust KeyControl, Fortanix, HashiCorp Vault Enterprise, and any KMIP 1.4 server.

pip install cyphera-kmip

Quick Start

from cyphera_kmip import KmipClient

client = KmipClient(
    host="kmip-server.corp.internal",
    client_cert="/path/to/client.pem",
    client_key="/path/to/client-key.pem",
    ca_cert="/path/to/ca.pem",
)

# Fetch a key by name (locate + get in one call)
key = client.fetch_key("my-encryption-key")
# key is bytes of raw key material (e.g., 32 bytes for AES-256)

# Or step by step:
ids = client.locate("my-key")
result = client.get(ids[0])
print(result["key_material"])  # bytes

# Create a new AES-256 key on the server
created = client.create("new-key-name", "AES", 256)
print(created["unique_identifier"])

client.close()

Operations

Operation Method Description
Locate client.locate(name) Find keys by name, returns unique IDs
Get client.get(id) Fetch key material by unique ID
Create client.create(name, algo, length) Create a new symmetric key
Fetch client.fetch_key(name) Locate + Get in one call

Authentication

KMIP uses mutual TLS (mTLS). Provide:

  • Client certificate -- identifies your application to the KMS
  • Client private key -- proves ownership of the certificate
  • CA certificate -- validates the KMS server's certificate
client = KmipClient(
    host="kmip.corp.internal",
    port=5696,                          # default KMIP port
    client_cert="/etc/kmip/client.pem",
    client_key="/etc/kmip/client-key.pem",
    ca_cert="/etc/kmip/ca.pem",
    timeout=10,                         # connection timeout (seconds)
)

TTLV Codec

The low-level TTLV (Tag-Type-Length-Value) encoder/decoder is also exported for advanced use:

from cyphera_kmip import encode_structure, encode_text_string, decode_ttlv, Tag, Type

# Build custom KMIP messages
msg = encode_structure(Tag.RequestMessage, [...])

# Parse raw KMIP responses
parsed = decode_ttlv(response_bytes)

Supported KMS Servers

Server KMIP Version Tested
Thales CipherTrust Manager 1.x, 2.0 Planned
IBM SKLM 1.x, 2.0 Planned
Entrust KeyControl 1.x, 2.0 Planned
Fortanix DSM 2.0 Planned
HashiCorp Vault Enterprise 1.4 Planned
PyKMIP (test server) 1.0-2.0 CI

Zero Dependencies

This library uses only Python standard library (ssl, socket, struct). No external dependencies.

Status

Alpha. KMIP 1.4 operations: Locate, Get, Create.

License

Apache 2.0 -- Copyright 2026 Horizon Digital Engineering LLC

Metadata

Release files for cyphera-kmip 0.0.1a1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cyphera-kmip 0.0.1a1
File Size Uploaded
cyphera_kmip-0.0.1a1.tar.gz 28.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cyphera-kmip 0.0.1a1
File Interpreter ABI Platform
cyphera_kmip-0.0.1a1-py3-none-any.whl Python 3 none any Details

Total release size: 46.9 kB

Release files / cyphera_kmip-0.0.1a1.tar.gz

Download URL cyphera_kmip-0.0.1a1.tar.gz
Size 28.2 kB
Tags Source
SHA-256 checksum
How to use checksums
2e1546848c351fdc9298772dda29087d82aac8a122cb16aff643bd122c5314c0
BLAKE2b-256 checksum
How to use checksums
6a58cf4b11d74111164a6d60a4c10dbb3a43a8c2648731f6b82c3eaee71f5f85
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 22, 2026.

Transparency log

Release files / cyphera_kmip-0.0.1a1-py3-none-any.whl

Download URL cyphera_kmip-0.0.1a1-py3-none-any.whl
Size 18.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2eabca74a58379e923ad8620b568ed916fc4f92b6841773ad946e116bfbab49b
BLAKE2b-256 checksum
How to use checksums
49ef8e70e1bb7ab1b0c448adeccb2b544868beca5e5a38a5bd958d1ecc704cf1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 22, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.1a1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page