Skip to main content

django-root-secret

Tests

django-root-secret is a Django package for managing one root encryption key per environment and decrypting encrypted literals at runtime.

django-root-secret reduces the number of plaintext secrets you need to manage and tries to minimize the number of environment variables your project depends on. Large .env files are a common source of configuration errors because variables can be missing, misnamed, outdated, or inconsistent across environments. This package keeps the env file minimal by storing only ROOT_ENCRYPTION_KEY there and encrypting the rest.

Installation

Install the package:

pip install django-root-secret

Add the app to INSTALLED_APPS:

INSTALLED_APPS = [
    ...,
    "django_root_secret",
]

Commands

Generate a root key file:

python manage.py generate_root_encryption_key --env development

This creates development.env in the current working directory with only:

# This file must only contain ROOT_ENCRYPTION_KEY.
# Encrypt every other secret with this key and keep the file private.
ROOT_ENCRYPTION_KEY=...

If development.env is not already ignored by Git, the command also adds it to .gitignore.

Encrypt a plaintext secret using that file and bring up a prompt to paste the secret:

python manage.py encrypt_secret --env development
# Value to encrypt: [hidden input]

At runtime, make ROOT_ENCRYPTION_KEY available through your environment or deployment secret manager:

export ROOT_ENCRYPTION_KEY="..."

Then use the encrypted output in code:

from django_root_secret import get_secret

DATABASE_PASSWORD = get_secret("gAAAAAB...")

Note

This package started as an internal tool at Hipo, and it brings back memories of a team I still appreciate deeply. 🦛

Metadata

Release files for django-root-secret 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for django-root-secret 0.2.1
File Size Uploaded
django_root_secret-0.2.1.tar.gz 7.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for django-root-secret 0.2.1
File Interpreter ABI Platform
django_root_secret-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 17.4 kB

Release files / django_root_secret-0.2.1.tar.gz

Download URL django_root_secret-0.2.1.tar.gz
Size 7.6 kB
Tags Source
SHA-256 checksum
How to use checksums
01ee308bf04b03f1f48d799abb010ef4c1b64caa14d2693f6f63e2a74673d3e1
BLAKE2b-256 checksum
How to use checksums
b947526c23df72edc0b6a28ad28deded1f50e8cd2d15b6705fc02ac43a7bd6ba
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 6, 2026.

Transparency log

Release files / django_root_secret-0.2.1-py3-none-any.whl

Download URL django_root_secret-0.2.1-py3-none-any.whl
Size 9.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
35955731557d017fa6aaa82807ae2e1875436584c667b8a8223683cedde72490
BLAKE2b-256 checksum
How to use checksums
6fa700c37126e40d28b0781d26f1499c80bb035d7fe179d868435aea978fe6c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 6, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page