django-root-secret
django-root-secret is a Django package for managing one root encryption key per environment and decrypting encrypted literals at runtime.
django-root-secret reduces the number of plaintext secrets you need to manage and tries to minimize the number of environment variables your project depends on. Large .env files are a common source of configuration errors because variables can be missing, misnamed, outdated, or inconsistent across environments. This package keeps the env file minimal by storing only ROOT_ENCRYPTION_KEY there and encrypting the rest.
Installation
Install the package:
pip install django-root-secret
Add the app to INSTALLED_APPS:
INSTALLED_APPS = [
...,
"django_root_secret",
]
Commands
Generate a root key file:
python manage.py generate_root_encryption_key --env development
This creates development.env in the current working directory with only:
# This file must only contain ROOT_ENCRYPTION_KEY.
# Encrypt every other secret with this key and keep the file private.
ROOT_ENCRYPTION_KEY=...
If development.env is not already ignored by Git, the command also adds it to .gitignore.
Encrypt a plaintext secret using that file and bring up a prompt to paste the secret:
python manage.py encrypt_secret --env development
# Value to encrypt: [hidden input]
At runtime, make ROOT_ENCRYPTION_KEY available through your environment or deployment secret manager:
export ROOT_ENCRYPTION_KEY="..."
Then use the encrypted output in code:
from django_root_secret import get_secret
DATABASE_PASSWORD = get_secret("gAAAAAB...")
Note
This package started as an internal tool at Hipo, and it brings back memories of a team I still appreciate deeply. 🦛
Metadata
Release files for django-root-secret 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| django_root_secret-0.2.1.tar.gz | 7.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| django_root_secret-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 17.4 kB
Release files / django_root_secret-0.2.1.tar.gz
| Download URL | django_root_secret-0.2.1.tar.gz |
|---|---|
| Size | 7.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
01ee308bf04b03f1f48d799abb010ef4c1b64caa14d2693f6f63e2a74673d3e1
|
|
BLAKE2b-256 checksum How to use checksums |
b947526c23df72edc0b6a28ad28deded1f50e8cd2d15b6705fc02ac43a7bd6ba
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 6, 2026.
Transparency logRelease files / django_root_secret-0.2.1-py3-none-any.whl
| Download URL | django_root_secret-0.2.1-py3-none-any.whl |
|---|---|
| Size | 9.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
35955731557d017fa6aaa82807ae2e1875436584c667b8a8223683cedde72490
|
|
BLAKE2b-256 checksum How to use checksums |
6fa700c37126e40d28b0781d26f1499c80bb035d7fe179d868435aea978fe6c1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 6, 2026.
Transparency log