keyring-gitlab-pypi is a backend for keyring which recognises GitLab package registry URLs.
- ⚡️ Works seamlessly with uv
- 🚀 Zero config needed on GitLab CI
- 🗝️ No more per-index credentials on your machine
Using it locally
-
Install keyring with this backend
uv tool install keyring --with keyring-gitlab-pypi
-
Open the config file for editing:
User
- macOS
$HOME/Library/Application Support/gitlab-pypi/gitlab-pypi.tomlif directory$HOME/Library/Application Support/gitlab-pypiexists, or$HOME/.config/gitlab-pypi.tomlotherwise.- Linux
$XDG_CONFIG_HOME/gitlab-pypi.tomlifXDG_CONFIG_HOMEis set, or$HOME/.config/gitlab-pypi.tomlotherwise.- Windows
%LOCALAPPDATA%\gitlab-pypi\gitlab-pypi.toml
System
- macOS
/Library/Application Support/gitlab-pypi/gitlab-pypi.toml- Linux
-
<config_dir>/gitlab-pypi/gitlab-pypi.tomlwhere<config_dir>is any of the paths set in$XDG_CONFIG_DIRSpaths, defaulting to/etc/xdg/etc/gitlab-pypi.tomlis higher priority than the above. - Windows
C:\ProgramData\gitlab-pypi\gitlab-pypi.toml
-
Configure a token
Personal Access Token
Create a personal access token with the
read_apiscope and add it to the config file:["gitlab.com"] token = "<token>"
or set environment variables where
<name>is an arbitrary key to group the variables, e.g.MYORGexport KEYRING_GITLAB_PYPI_<name>_INSTANCE=gitlab.com export KEYRING_GITLAB_PYPI_<name>_TOKEN=<token>
Deploy Token
Create a deploy token with the
read_package_registryscope and add it to the config file:["gitlab.com"] username = "<username>" token = "<token>"
or set environment variables where
<name>is an arbitrary key to group the variables, e.g.MYORGexport KEYRING_GITLAB_PYPI_<name>_INSTANCE=gitlab.com export KEYRING_GITLAB_PYPI_<name>_USERNAME=<username> export KEYRING_GITLAB_PYPI_<name>_TOKEN=<token>
-
Configure
keyring-providerin uv:-
using an environment variable:
export UV_KEYRING_PROVIDER=subprocess
-
or in
uv.toml:keyring-provider = "subprocess"
-
or using the option
uv sync --keyring-provider=subprocess
-
-
Configure one or more GitLab package indexes
For example, in
pyproject.toml:[[tool.uv.index]] name = "myindex" url = "https://gitlab.example.com/api/v4/projects/1/packages/pypi/simple" authenticate = "always"
Note
You need
authenticate = "always"for uv to invoke keyring when no username is specified. This option is a good idea anyway!Alternatively, add the username (which is
__token__for personal access tokens) to the URL, but this is not recommended forpyproject.tomlas you likely want to use a different username in CI, for example. -
Done!
keyring-gitlab-pypiwill return your token for URLs that look like package installs.
Using it in GitLab CI
$CI_JOB_TOKEN will be used automatically as long as the index URL matches the running GitLab instance.
In principle this is all you need:
variables:
UV_KEYRING_PROVIDER: subprocess
UV_TOOL_BIN_DIR: /usr/local/bin
test:
image: ghcr.io/astral-sh/uv:python3.13-bookworm
before_script:
- uv tool install keyring --with keyring-gitlab-pypi
- uv sync
This assumes that you haven't set UV_INDEX. (uv tool ignores pyproject.toml so you don't need to worry about indexes configured there).
It's recommended to constrain the versions:
printf '%s\n' keyring keyring-gitlab-pypi > keyring-constraints.in
uv pip compile --universal keyring-constraints.in -o keyring-constraints.txt
variables:
UV_KEYRING_PROVIDER: subprocess
UV_TOOL_BIN_DIR: /usr/local/bin
test:
image: ghcr.io/astral-sh/uv:python3.13-bookworm
before_script:
- uv tool install keyring --with keyring-gitlab-pypi -c keyring-constraints.txt
- uv sync
Motivation
- When using multiple GitLab package indexes, it can be cumbersome to configure them with the same token via environment variables or otherwise.
- keyring's keychain backend on macOS does not support
--mode creds - uv will reuse credentials for URLs on the same host, but it feels fragile to just configure one of the indexes and let the credentials cache serve the rest. At the very least,
keyring-gitlab-pypiis set-and-forget across multiple projects.
Metadata
Release files for keyring-gitlab-pypi 1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| keyring_gitlab_pypi-1.2.tar.gz | 8.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| keyring_gitlab_pypi-1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 15.3 kB
Release files / keyring_gitlab_pypi-1.2.tar.gz
| Download URL | keyring_gitlab_pypi-1.2.tar.gz |
|---|---|
| Size | 8.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
048f00715c65b87931c8fc5581fbfd995a62d923abdf83f27df782efb513e979
|
|
BLAKE2b-256 checksum How to use checksums |
ed3e00bd6760135fc9545c6967226ba2f13a07c5c65d21566293331c4c7b9edb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.12.9
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 27, 2026.
Transparency logRelease files / keyring_gitlab_pypi-1.2-py3-none-any.whl
| Download URL | keyring_gitlab_pypi-1.2-py3-none-any.whl |
|---|---|
| Size | 7.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ec95fe4c000bfab06b5767e38c3c90a011697484e92f44cc03cfb19587a6ea82
|
|
BLAKE2b-256 checksum How to use checksums |
a1b8484e7dc0af46a15934a2c94b2e69d10540f2a66042add161d626ebfbc759
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.12.9
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 27, 2026.
Transparency log