Skip to main content

flask-enciphers

Encrypted session interface for Flask using enciphers.

Replaces Flask's default signed cookie session with a fully encrypted one.

Version 3.0 note: requires enciphers>=3,<4, including its fix for nonce reuse across forked workers. Existing 2.x session cookies remain readable with the same key and backend. See Upgrading from 2.x and CHANGELOG.md.

Installation

pip install flask-enciphers

Usage

from flask import Flask, session
from flask_enciphers import EnciphersSession

app = Flask(__name__)
EnciphersSession(app)

@app.route("/login")
def login():
    session["user_id"] = 1
    return "logged in"

Application Factory Pattern

from flask_enciphers import EnciphersSession

es = EnciphersSession()

def create_app():
    app = Flask(__name__)
    es.init_app(app)
    return app

Configuration

Key Type Default Description
ENCIPHERS_BACKEND str "AES256_GCM" "AES256_GCM" or "XCHACHA20_POLY1305"
ENCIPHERS_KEY int random Secret key, from 0 to 2**128 - 1
ENCIPHERS_KEY_ENV str None Name of an environment variable containing the key as a decimal integer

Configure only one key source. A random 128-bit key is generated only when both settings are absent or None. An explicit integer 0 is preserved; it is not treated as missing. Invalid key types or values, invalid environment settings, and conflicting key sources raise an exception during initialization instead of being silently replaced.

If no ENCIPHERS_KEY/ENCIPHERS_KEY_ENV is provided, a random key is generated at startup — fine for local development, but every process in a real deployment needs to share the same key, or sessions won't be portable between them.

Session expiry

If session.permanent is set (giving the cookie an Expires attribute), the same expiry is also bound inside the encrypted token itself — a copy of the cookie can't be replayed past that point even if a client ignores the cookie's own expiration. A non-permanent session cookie (the default) carries no expires_at either, unchanged from before.

Upgrading from 2.x

python -m pip install --upgrade "flask-enciphers>=3,<4"

Keep your existing ENCIPHERS_KEY or ENCIPHERS_KEY_ENV and ENCIPHERS_BACKEND configuration. The token format is unchanged, so existing 2.x sessions, including non-expiring tokens created with expires_at=0, remain valid until their original expiry. For correctly configured keys, no key rotation or session reset is required. Upgrade every worker to pick up the upstream nonce-generation fix.

The key configuration check now distinguishes None from 0. Earlier versions silently generated a random key when ENCIPHERS_KEY=0 was set without ENCIPHERS_KEY_ENV; those cookies cannot be read using the now-correctly configured zero key. This exception affects deployments that relied on that erroneous fallback, not cookies actually encrypted with key zero (for example, using an environment variable containing "0").

enciphers 3 rejects encrypt(..., expires_at=0); use None for no expiry and a positive Unix timestamp for an expiry. This session interface already passes None for non-permanent sessions and the cookie's expiration timestamp for permanent sessions, so application session code needs no change. If you call encrypt directly, update any zero expiry arguments. Oversized purposes still raise ValueError, but the error message has changed; this interface uses the default "session" purpose and does not match error messages.

See the upstream migration guide for details. Cookies from flask-enciphers 0.1.x remain incompatible; see CHANGELOG.md.

Development

Install the package and run the session tests against the installed version:

python -m pip install -e .
python -m unittest discover -s tests -v

License

Apache-2.0 — Copyright 2026 Mejlad Alsubaie

Metadata

Release files for flask-enciphers 3.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for flask-enciphers 3.0.0
File Size Uploaded
flask_enciphers-3.0.0.tar.gz 13.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for flask-enciphers 3.0.0
File Interpreter ABI Platform
flask_enciphers-3.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 22.1 kB

Release files / flask_enciphers-3.0.0.tar.gz

Download URL flask_enciphers-3.0.0.tar.gz
Size 13.7 kB
Tags Source
SHA-256 checksum
How to use checksums
3798f60120026726881e5675d74d7bbc2f539fb4cac36d14abe6360f80a0c374
BLAKE2b-256 checksum
How to use checksums
80af2ba0234870e056972a5cb57634d9c1f322c19ae404ae1ec001be5e795c4b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / flask_enciphers-3.0.0-py3-none-any.whl

Download URL flask_enciphers-3.0.0-py3-none-any.whl
Size 8.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4b84efd2e48761c7553a88988b70416ff606af4c33ed1a572addd000239f4d31
BLAKE2b-256 checksum
How to use checksums
057d7145b1cf52e6d1736e6ffa42963d26408ac784c8a233f9128be3918b4d6d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

3.0.0 This release

2 release files

2.0.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page