Skip to main content

fnox-py

fnox-py is a thin Python wrapper around the fnox secrets management tool.

It does not reimplement fnox behavior in Python. Instead, it:

  • locates a real fnox binary
  • builds argv for common commands
  • runs the binary
  • returns parsed results or typed errors

Python requirement: >=3.12

[!NOTE] Official fnox project links:

Installation

uv

uv tool install fnox-py

pip

pip install fnox-py

Bundled binary vs source install

Platform wheels are intended to bundle the fnox binary.

If you install from source instead of a platform wheel, fnox-py requires a real fnox executable to be available via:

  • PATH, or
  • FNOX_PY_BINARY=/absolute/path/to/fnox

Examples:

pip install --no-binary fnox-py fnox-py
FNOX_PY_BINARY=/usr/local/bin/fnox python -c "import fnox_py; print(fnox_py.version())"

Binary Resolution

At runtime, fnox-py resolves the fnox binary in this order:

  1. FNOX_PY_BINARY
  2. bundled/installed locations in the current environment
  3. bundled/installed fallback locations associated with the base or target install
  4. user scheme script location
  5. PATH

If FNOX_PY_BINARY is set but points to a missing file, fnox-py raises FnoxNotFoundError.

Python API

from fnox_py import (
    config_files,
    export_json,
    get,
    lease_create,
    profiles,
    providers,
    schema,
    version,
)

value = get("MY_SECRET")
all_values = export_json()
schema_doc = schema()
profile_names = profiles()
provider_names = providers()
config_paths = config_files()
lease = lease_create("vault", duration="1h", label="local-dev")
fnox_version = version()

Common examples

Get a single value:

from fnox_py import get

token = get("API_TOKEN")

Get a value from a specific profile:

from fnox_py import get

token = get("API_TOKEN", profile="prod")

Decode base64 output:

from fnox_py import get

decoded = get("TLS_CERT", base64_decode=True)

Export all secrets as JSON:

from fnox_py import export_json

data = export_json(profile="dev")

Inspect schema, profiles, providers, and config files:

from fnox_py import config_files, profiles, providers, schema

print(schema())
print(profiles())
print(providers())
print(config_files())

Create a lease:

from fnox_py import lease_create

lease = lease_create("vault", duration="30m", label="ci-job")

Get the underlying fnox version:

from fnox_py import version

print(version())

CLI

The package installs the fnox-py console script.

Built-in subcommands

Locate the resolved binary:

fnox-py which

Show the wrapper version and attempt to print the underlying fnox version:

fnox-py version

Print basic environment diagnostics:

fnox-py doctor

Passthrough behavior

Any arguments other than which, version, and doctor are passed directly through to fnox.

For example:

fnox-py get MY_SECRET
fnox-py profiles
fnox-py export --format json

With no arguments, fnox-py runs fnox with no extra argv.

Public API

fnox-py currently exports:

  • config_files
  • export_json
  • get
  • lease_create
  • profiles
  • providers
  • schema
  • version
  • find_fnox_bin
  • run
  • FnoxResult
  • FnoxCommandError
  • FnoxError
  • FnoxNotFoundError
  • FnoxTimeoutError

Errors

Library calls raise typed exceptions:

  • FnoxNotFoundError when the binary cannot be found
  • FnoxCommandError when fnox exits non-zero
  • FnoxTimeoutError on subprocess timeout
  • FnoxError as the base exception type

Development

This project uses uv, pytest, ruff, and mypy.

Install dependencies:

uv sync

Run tests:

uv run pytest -v

Run a single test:

uv run pytest tests/test_api.py::test_get -q

Lint:

uv run ruff check src tests scripts

Type-check:

uv run mypy src

Build distributions:

uv build

Release / Platform Wheel Build

scripts/build_platform_wheel.py builds platform-specific wheels by:

  1. building a pure Python wheel
  2. downloading upstream fnox release binaries
  3. injecting the binary into the wheel
  4. rewriting wheel metadata
  5. building an sdist

The upstream fnox version to bundle is read from FNOX_VERSION.txt at the repo root by default. To override it, pass --fnox-version:

uv run python scripts/build_platform_wheel.py --fnox-version 1.0.0 --output dist/

Expected upstream archive and extracted binary SHA256 values are pinned in FNOX_HASHES.json and verified during release builds.

To bump the bundled version, update FNOX_VERSION.txt, refresh FNOX_HASHES.json, and commit both changes.

Notes

  • fnox-py is intentionally small and wrapper-focused.
  • For behavior, flags, and command semantics, prefer the upstream fnox documentation.
  • If you need lower-level control, use run() directly and inspect FnoxResult.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

fnox_py-1.30.0.tar.gz (6.6 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

fnox_py-1.30.0-py3-none-win_arm64.whl (15.8 MB view details)

Uploaded Python 3Windows ARM64

fnox_py-1.30.0-py3-none-win_amd64.whl (16.7 MB view details)

Uploaded Python 3Windows x86-64

fnox_py-1.30.0-py3-none-manylinux_2_17_x86_64.whl (24.5 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

fnox_py-1.30.0-py3-none-manylinux_2_17_aarch64.whl (23.7 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

fnox_py-1.30.0-py3-none-macosx_11_0_arm64.whl (18.8 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

fnox_py-1.30.0-py3-none-macosx_10_12_x86_64.whl (20.3 MB view details)

Uploaded Python 3macOS 10.12+ x86-64

File details

Details for the file fnox_py-1.30.0.tar.gz.

File metadata

  • Download URL: fnox_py-1.30.0.tar.gz
  • Upload date:
  • Size: 6.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for fnox_py-1.30.0.tar.gz
Algorithm Hash digest
SHA256 25f7d95388c89a25915624678293dd418077fee2eba83e430650610fbc9d31f2
MD5 765b7e4f01ccc11057f2184c019d5829
BLAKE2b-256 b379bedf7b7c0a605493c2ddc06752d6b1ead47652e6e5be4f1c5ab68bb107de

See more details on using hashes here.

Provenance

The following attestation bundles were made for fnox_py-1.30.0.tar.gz:

Publisher: release.yml on fullerzz/fnox-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file fnox_py-1.30.0-py3-none-win_arm64.whl.

File metadata

  • Download URL: fnox_py-1.30.0-py3-none-win_arm64.whl
  • Upload date:
  • Size: 15.8 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for fnox_py-1.30.0-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 2f4099789dc6661bc6e008da7d0ea036aec924e98e16dd51bbb9cedee5b13849
MD5 8582d789afae9976ad21906fec993d45
BLAKE2b-256 a52d0229d58fb119907edae731039d3a656e6e3ea7fa2f3c22a1346d0feeb975

See more details on using hashes here.

Provenance

The following attestation bundles were made for fnox_py-1.30.0-py3-none-win_arm64.whl:

Publisher: release.yml on fullerzz/fnox-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file fnox_py-1.30.0-py3-none-win_amd64.whl.

File metadata

  • Download URL: fnox_py-1.30.0-py3-none-win_amd64.whl
  • Upload date:
  • Size: 16.7 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for fnox_py-1.30.0-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 cc274bb94b8ce922d0eecbae76c44b7cca92566b41277246e2cb6b09d363001d
MD5 ccdfd86e4050667b90e8b0ff781a3a55
BLAKE2b-256 deb5ace791b4586812740079b6e58523a259aee774d5857c16c5fbd9e9605f91

See more details on using hashes here.

Provenance

The following attestation bundles were made for fnox_py-1.30.0-py3-none-win_amd64.whl:

Publisher: release.yml on fullerzz/fnox-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file fnox_py-1.30.0-py3-none-manylinux_2_17_x86_64.whl.

File metadata

File hashes

Hashes for fnox_py-1.30.0-py3-none-manylinux_2_17_x86_64.whl
Algorithm Hash digest
SHA256 c58dc52df896ee88d773191e133a5dc98684f2ebc09c15dec3e437df2412b6a7
MD5 5cd1deab67ef2dbe4ee3af3f0cd87dc8
BLAKE2b-256 7211b9f60a248ea6d751678853ced48a0a51454331a486e93d054aa92ec52d26

See more details on using hashes here.

Provenance

The following attestation bundles were made for fnox_py-1.30.0-py3-none-manylinux_2_17_x86_64.whl:

Publisher: release.yml on fullerzz/fnox-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file fnox_py-1.30.0-py3-none-manylinux_2_17_aarch64.whl.

File metadata

File hashes

Hashes for fnox_py-1.30.0-py3-none-manylinux_2_17_aarch64.whl
Algorithm Hash digest
SHA256 44f5bcc165217a4d66e068ba6455c1be56b58fa822740675cd03e1c7ba9225fb
MD5 c5623399cc1dbb04c4bcb69a47651cfd
BLAKE2b-256 a91160ed1c8e5e7d748d75ee09bdc946fdb048981df1d8882f56899439df8cd0

See more details on using hashes here.

Provenance

The following attestation bundles were made for fnox_py-1.30.0-py3-none-manylinux_2_17_aarch64.whl:

Publisher: release.yml on fullerzz/fnox-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file fnox_py-1.30.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for fnox_py-1.30.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 001e145541684e54a41fe7d3380bfd3966f57a625a09a023b0bfbcc1e521d130
MD5 9f02f80a83168cb7abaeb2a738732fe3
BLAKE2b-256 4e0fd6fae228bc4b328141c4a8f9ca43b78a029fe91aff9fe87be4e87e473300

See more details on using hashes here.

Provenance

The following attestation bundles were made for fnox_py-1.30.0-py3-none-macosx_11_0_arm64.whl:

Publisher: release.yml on fullerzz/fnox-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file fnox_py-1.30.0-py3-none-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for fnox_py-1.30.0-py3-none-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 49a90cd16454720e46f1ce9220bf56c7e7e5fe0acd140c65dfa687fbc7ab3627
MD5 dbcad28dcc4e72b84edb9c859f08eb76
BLAKE2b-256 2ca3fa354b0d37e37502cf1c912b68e410811532d627294d5cde3baca4e8cffe

See more details on using hashes here.

Provenance

The following attestation bundles were made for fnox_py-1.30.0-py3-none-macosx_10_12_x86_64.whl:

Publisher: release.yml on fullerzz/fnox-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

1.31.0

7 files

This release

1.30.0 This release

7 files

1.25.1

7 files

1.24.1

7 files

1.24.0

7 files

1.23.1

7 files

1.23.0

7 files

1.22.0

7 files

1.20.0

7 files

1.19.0

7 files

1.0.3

7 files

1.0.2

7 files

0.1.0

7 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page