Skip to main content

keylet -- Client library for Tillitis TKey

keylet on GitHub keylet on PyPI keylet documentation

Keylet is a Python client library and CLI tool for the Tillitis TKey security token, and implements a ML-DSA / Ed25519 signer application for TKey.

TKeys unique feature is that it has no long-term memory: signing keys are always generated from a seed at runtime. This seed is built by combining a Unique Device Secret, a Device Application hash and an optional User Supplied Secret. Both the Device Application and User Supplied Secret are provided at runtime by keylet.

The unique design leads to some API peculiarities:

  • User Supplied Secret (passphrase) is not directly validated by keylet: a "wrong" passphrase will just lead to using a different signing key. In practice the calling application should look at TKeySign.get_pubkey(): if the key is unexpected, then potentially the wrong passphrase was used.
  • In long-term use (where the same signing key is expected to be used over a period of time) the calling application is responsible for always selecting the same Device Application: keylet provides a mechanism for this, see examples.
  • The only way to change the device application or passphrase after initialization is to unplug the device and start over.
  • Signer initialization has an optimization where the initialization succeeds if the TKey has already been initialized with matching device application name and version. Unfortunately keylet cannot confirm that the exact device binary is the expected one or that the passphrase is still the same one (but again, the calling application can compare TKeySign.get_pubkey() to the expected key)

Installation

pip install keylet

CLI Usage

The package installs a keylet command-line tool for signing and verification. This is primarily a test/demo application for the library.

# Sign without a passphrase, then verify
$ keylet sign README.md
$ keylet verify README.md

# Get public key, sign, and verify using the saved public key
$ keylet pubkey --output pub.key
$ keylet sign README.md
$ keylet verify --pubkey pub.key README.md

# When using keylet long-term, remember to specify device app digest (keylet default
# app version may change, but you will need a specific application to keep using the
# same key)
$ keylet --digest 2cd8741 sign README.md

Library Usage

from keylet import TKeySign, SignApp

# Load the default embedded ML-DSA signer
app = SignApp.load_mldsa()
digest = app.digest

# Initialize the signer with a passphrase, sign a payload
with TKeySign(app=app, secret="hunter2") as signer:
    pubkey = signer.get_pubkey()
    signature = signer.sign(b"my payload")

In long-term use, the device app digest should be used to ensure the same application is always used for a specific key:

# Load application with a digest stored earlier
app = SignApp.load_mldsa(digest=digest)

# Initialize the signer with a passphrase, sign a payload
with TKeySign(app=app, secret="hunter2") as signer:
    if signer.get_pubkey() != pubkey:
        exit("Unexpected signing key: maybe incorrect password?")
    signature = signer.sign(b"my payload")

See API Reference in documentation for more details.

Development

uv is a required development tool.

# Run keylet CLI from source
uv run keylet sign README.md

# run linters and type checker
make lint

# Fix formatting and lint issues
make fix

# run tests
make test

# run tests, including on-device tests
make test-device

Releasing

  • If a major or minor version bump is needed run uv version --bump=[major|minor]
  • run make release to create version bump commit, release tag and dev version bump commit
  • Push the commits and tag to trigger release workflow: git push --tags origin main

Metadata

Release files for keylet 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for keylet 1.0.0
File Size Uploaded
keylet-1.0.0.tar.gz 56.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for keylet 1.0.0
File Interpreter ABI Platform
keylet-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 115.4 kB

Release files / keylet-1.0.0.tar.gz

Download URL keylet-1.0.0.tar.gz
Size 56.8 kB
Tags Source
SHA-256 checksum
How to use checksums
0ebaea9ea3272d59c4fc69f94cd0b47e3feb930d5764214448fc834dd41caf65
BLAKE2b-256 checksum
How to use checksums
9582d3351f0103f093d1f89d363986906fee8db6e07bd36c6b7b6bc30931059b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / keylet-1.0.0-py3-none-any.whl

Download URL keylet-1.0.0-py3-none-any.whl
Size 58.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
aa6b377dfba97cea2a27180a3ddd7e042b510eb1ca6d47f6ad18518bce292c79
BLAKE2b-256 checksum
How to use checksums
428db6288b768e8e6e223df6d99cb48a5bc7d35e21422d4c03a05a5ae6ed9a60
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page