Skip to main content

dworshak-secret is a light-weight library for local credential access. By adding dworshak-secret as a dependency to your Python project, you enable your program or script to leverage secure credentials, typically added with the dworshak-prompt.Obtain().secret() function or managed directly with the dworshak CLI.

All secrets are stored Fernet-encrypted in a SQL database file. No opaque blobs — every entry is meaningful and decryptable via the library.

Example

Typical package inclusion. See below for guidance concerning Termux and iSH Alpine.

uv add "dworshak-secret[crypto]"
from dworshak_secret import DworshakSecret
from dworshak_prompt import Obtain

# Initialize the vault (create key and DB if missing)
client = DworshakSecret()
client.initialize_vault()

# Store and retrieve credentials by prompting the user on their local machine
obtain = Obtain()
username = obtain.secret("rjn_api", "username")
secret = obtain.secret("rjn_api", "password")

# ---

# Alternatively, store secrets with a script ....
## (NOT recommended to keep 'set' calls in your codebase or in system history)
client.set("rjn_api", "username", "davey.davidson")
client.set("rjn_api", "password", "s3cr3t")

## ...and then retrieve credentials in your codebase.
username = client.get("rjn_api", "username")
password = client.get("rjn_api", "password")

# ---

# List stored items
for service, item in client.list_contents():
    print(f"{service}/{item}")

Capture stdout environment variables for bash scripting by using the --emit flag

TESTSET=$(dworshak-secret set "myservice" "myitem" "myvalue" --emit)
echo $TESTSET

TESTGET=$(dworshak-secret get "myservice" "myitem" --emit)
echo $TESTGET

Running dworshak-secret set "myservice" "myitem", without including a value, will prompt the user for input, which will be hidden.

Alternatively, install the dworshak CLI and use:

TESTOBTAIN=$(dworshak prompt obtain secret "myservice" "myitem" --emit)
echo $TESTOBTAIN

This works because the multiplexer will skip the console input and route the user to the web interface or the GUI.


Include Cryptography Library

Here we cover using dworshak-secret as a dependency in your project.

The central question is how to properly include the cryptography package.

On a Termux system, cryptography can (B) be built from source or (A) the precompiled python-cryptography dedicated Termux package can be used.

Termux Installation

A. Use python-cryptography

This is faster but pollutes your local venv with other system site packages.

pkg install python-cryptography
uv venv --system-site-packages
uv add dworshak-secret

B. Allow cryptography to build from source (uv is better at this compared to using pip)

pkg install rust binutils
uv add "dworshak-secret[crypto]"

iSH Alpine installation

apk add py3-cryptography
uv venv --system-site-packages
uv add dworshak-secret

Why Dworshak Over keyring?

Keyring is the go-to for desktop Python apps thanks to native OS backends, but it breaks on Termux because there's no keyring daemon or secure fallback, leaving you with insecure plaintext or install headaches. Dworshak avoids that entirely with a portable, self-contained Fernet-encrypted SQLite vault that works the same on Linux, macOS, Windows, and Termux on Android tablets. You get reliable programmatic access via dworshak_secret.DworshakSecret().get() (or dworshak_prompt.Obtain().secret()). The Dworshak ecosystem is field-ready for real scripting workflows like API pipelines and skip-the-playstore localhost webapps. When keyring isn't viable, Dworshak just works.


CLI

dworshak is the intended CLI layer, but the dworshak-secret CLI can also be used directly.

pipx install "dworshak-secret[typer,crypto]"
dworshak-secret helptree

Screenshot of the Dworshak CLI helptree

helptree is utility function for Typer CLIs, imported from the typer-helptree library.


Sister Projects in the Dworshak Ecosystem

pipx install dworshak
pip install dworshak-secret
pip install dworshak-config
pip install dworshak-env
pip install dworshak-prompt

Metadata

Release files for dworshak-secret 1.3.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dworshak-secret 1.3.6
File Size Uploaded
dworshak_secret-1.3.6.tar.gz 24.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dworshak-secret 1.3.6
File Interpreter ABI Platform
dworshak_secret-1.3.6-py3-none-any.whl Python 3 none any Details

Total release size: 51.2 kB

Release files / dworshak_secret-1.3.6.tar.gz

Download URL dworshak_secret-1.3.6.tar.gz
Size 24.7 kB
Tags Source
SHA-256 checksum
How to use checksums
d7b58533a9f7de9b0bb1c459183cd6ac125f71e186debf3c64ad6dcab29712c0
BLAKE2b-256 checksum
How to use checksums
ddcac285c023cceadc3349ebc8405bce5a484bdbc09aff411db813ef74fc45fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 7, 2026.

Transparency log

Release files / dworshak_secret-1.3.6-py3-none-any.whl

Download URL dworshak_secret-1.3.6-py3-none-any.whl
Size 26.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c9422cdf11dc6f5474f674a14825c0cbecb05912bac17a1fb5541c635c3d3060
BLAKE2b-256 checksum
How to use checksums
1c185425409fc9744912a0f238742a5f267d4dde2e0ce2b97a21e71b7dac30d8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.3.6 This release

2 release files

1.3.5

2 release files

1.3.4

2 release files

1.3.3

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.2.20

2 release files

1.2.18

2 release files

1.2.17

2 release files

1.2.16

2 release files

1.2.11

2 release files

1.2.10

2 release files

1.2.9

2 release files

1.2.8

2 release files

1.2.7

2 release files

1.2.6

2 release files

1.2.5

2 release files

1.2.4

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page