environ-config: Application Configuration With Env Variables
environ-config allows you to load your application's configuration from environment variables – as recommended in The Twelve-Factor App methodology – with elegant, boilerplate-free, and declarative code:
>>> import environ
>>> # Extracts secrets from Vault-via-envconsul: 'secret/your-app':
>>> vault = environ.secrets.VaultEnvSecrets(vault_prefix="SECRET_YOUR_APP")
>>> @environ.config(prefix="APP")
... class AppConfig:
... @environ.config
... class DB:
... name = environ.var("default_db")
... host = environ.var("default.host")
... port = environ.var(5432, converter=int) # Use attrs's converters and validators!
... user = environ.var("default_user")
... password = vault.secret()
...
... env = environ.var()
... lang = environ.var(name="LANG") # It's possible to overwrite the names of variables.
... db = environ.group(DB)
... awesome = environ.bool_var()
>>> cfg = environ.to_config(
... AppConfig,
... environ={
... "APP_ENV": "dev",
... "APP_DB_HOST": "localhost",
... "LANG": "C",
... "APP_AWESOME": "yes", # true and 1 work too, everything else is False
... # Vault-via-envconsul-style var name:
... "SECRET_YOUR_APP_DB_PASSWORD": "s3kr3t",
... }) # Uses os.environ by default.
>>> cfg
AppConfig(env='dev', lang='C', db=AppConfig.DB(name='default_db', host='localhost', port=5432, user='default_user', password=<SECRET>), awesome=True)
>>> cfg.db.password
's3kr3t'
AppConfig.from_environ({...}) is equivalent to the code above, depending on your taste.
Features
-
Declarative & boilerplate-free.
-
Nested configuration from flat environment variable names.
-
Default & mandatory values: enforce configuration structure without writing a line of code.
-
Built on top of attrs which gives you data validation and conversion for free.
-
Pluggable secrets extraction. Ships with:
- HashiCorp Vault support via envconsul.
- AWS Secrets Manager (needs boto3)
- INI files, because secrets in env variables are icky.
-
Helpful debug logging that will tell you which variables are present and what environ-config is looking for.
-
Built-in dynamic help documentation generation.
You can find the full documentation including a step-by-step tutorial on Read the Docs.
Project Information
environ-config is maintained by Hynek Schlawack and is released under the Apache License 2.0 license. Development takes place on GitHub.
The development is kindly supported by Variomedia AG and all my amazing GitHub Sponsors.
environ-config wouldn't be possible without the attrs project.
environ-config for Enterprise
Available as part of the Tidelift Subscription.
The maintainers of environ-config and thousands of other packages are working with Tidelift to deliver commercial support and maintenance for the open source packages you use to build your applications. Save time, reduce risk, and improve code health, while paying the maintainers of the exact packages you use.
Release Information
Removed
-
Support for Python 3.8 and 3.9. #134
-
Support for attrs older than 21.3.0 (the one that introduced the
attrsnamespace). #134
Added
- Support for Python 3.14 and 3.15. #134
Changed
-
environ-config now uses
@attrs.defineet al instead of@attr.sto help with typing support. This should not make any difference in practice, but people doing weird things (I know y'all are out there!) might run into paper cuts. #134 -
Secrets are now handled like environment variables in optional groups, so that if all secrets (and environment variables) are missing, the group becomes
None. This change also causes theMissingSecretErrorexceptions to include all missing secrets, not just the first one. #100
Fixed
- Type hints for
environ.group()now respects theoptionalargument. #98
Release files for environ-config 26.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| environ_config-26.1.0.tar.gz | 49.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| environ_config-26.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 73.2 kB
Release files / environ_config-26.1.0.tar.gz
| Download URL | environ_config-26.1.0.tar.gz |
|---|---|
| Size | 49.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7fe80885d22dd50218664c1e4e2c098429129387ddbb6e51318a3883639ae8b4
|
|
BLAKE2b-256 checksum How to use checksums |
ee893522cca1a75b061e2d92ffbaf285beaf9866ee452ac78c0c6de84c7ff118
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 22, 2026.
Transparency logRelease files / environ_config-26.1.0-py3-none-any.whl
| Download URL | environ_config-26.1.0-py3-none-any.whl |
|---|---|
| Size | 23.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e5920e1c25f301c252f2e7eff0d64538b78a668311d730492664ee39f746b7dc
|
|
BLAKE2b-256 checksum How to use checksums |
7ad82c7722de2e8719d0aed0e4b5380258ea0df3ee2b29aaef7baf1d5e79a7b0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 22, 2026.
Transparency log