Skip to main content

PyPI CI Status MIT License

keyring-gitlab-pypi is a backend for keyring which recognises GitLab package registry URLs.

  • ⚡️ Works seamlessly with uv
  • 🚀 Zero config needed on GitLab CI
  • 🗝️ No more per-index credentials on your machine

Using it locally

  1. Install keyring with this backend

    uv tool install keyring --with keyring-gitlab-pypi
    
  2. Open the config file for editing:

    User

    macOS
    $HOME/Library/Application Support/gitlab-pypi/gitlab-pypi.toml if directory $HOME/Library/Application Support/gitlab-pypi exists, or $HOME/.config/gitlab-pypi.toml otherwise.
    Linux
    $XDG_CONFIG_HOME/gitlab-pypi.toml if XDG_CONFIG_HOME is set, or $HOME/.config/gitlab-pypi.toml otherwise.
    Windows
    %LOCALAPPDATA%\gitlab-pypi\gitlab-pypi.toml

    System

    macOS
    /Library/Application Support/gitlab-pypi/gitlab-pypi.toml
    Linux

    <config_dir>/gitlab-pypi/gitlab-pypi.toml where <config_dir> is any of the paths set in $XDG_CONFIG_DIRS paths, defaulting to /etc/xdg

    /etc/gitlab-pypi.toml is higher priority than the above.

    Windows
    C:\ProgramData\gitlab-pypi\gitlab-pypi.toml
  3. Configure a token

    Personal Access Token

    Create a personal access token with the read_api scope and add it to the config file:

    ["gitlab.com"]
    token = "<token>"
    

    or set environment variables where <name> is an arbitrary key to group the variables, e.g. MYORG

    export KEYRING_GITLAB_PYPI_<name>_INSTANCE=gitlab.com
    export KEYRING_GITLAB_PYPI_<name>_TOKEN=<token>
    

    Deploy Token

    Create a deploy token with the read_package_registry scope and add it to the config file:

    ["gitlab.com"]
    username = "<username>"
    token = "<token>"
    

    or set environment variables where <name> is an arbitrary key to group the variables, e.g. MYORG

    export KEYRING_GITLAB_PYPI_<name>_INSTANCE=gitlab.com
    export KEYRING_GITLAB_PYPI_<name>_USERNAME=<username>
    export KEYRING_GITLAB_PYPI_<name>_TOKEN=<token>
    
  4. Configure keyring-provider in uv:

    • using an environment variable:

      export UV_KEYRING_PROVIDER=subprocess
      
    • or in uv.toml:

      keyring-provider = "subprocess"
      
    • or using the option

      uv sync --keyring-provider=subprocess
      
  5. Configure one or more GitLab package indexes

    For example, in pyproject.toml:

    [[tool.uv.index]]
    name = "myindex"
    url = "https://gitlab.example.com/api/v4/projects/1/packages/pypi/simple"
    authenticate = "always"
    

    Note

    You need authenticate = "always" for uv to invoke keyring when no username is specified. This option is a good idea anyway!

    Alternatively, add the username (which is __token__ for personal access tokens) to the URL, but this is not recommended for pyproject.toml as you likely want to use a different username in CI, for example.

  6. Done! keyring-gitlab-pypi will return your token for URLs that look like package installs.

Using it in GitLab CI

$CI_JOB_TOKEN will be used automatically as long as the index URL matches the running GitLab instance.

In principle this is all you need:

variables:
  UV_KEYRING_PROVIDER: subprocess
  UV_TOOL_BIN_DIR: /usr/local/bin

test:
  image: ghcr.io/astral-sh/uv:python3.13-bookworm
  before_script:
    - uv tool install keyring --with keyring-gitlab-pypi
    - uv sync

This assumes that you haven't set UV_INDEX. (uv tool ignores pyproject.toml so you don't need to worry about indexes configured there).

It's recommended to constrain the versions:

printf '%s\n' keyring keyring-gitlab-pypi > keyring-constraints.in
uv pip compile --universal keyring-constraints.in -o keyring-constraints.txt
variables:
  UV_KEYRING_PROVIDER: subprocess
  UV_TOOL_BIN_DIR: /usr/local/bin

test:
  image: ghcr.io/astral-sh/uv:python3.13-bookworm
  before_script:
    - uv tool install keyring --with keyring-gitlab-pypi -c keyring-constraints.txt
    - uv sync

Motivation

  • When using multiple GitLab package indexes, it can be cumbersome to configure them with the same token via environment variables or otherwise.
  • keyring's keychain backend on macOS does not support --mode creds
  • uv will reuse credentials for URLs on the same host, but it feels fragile to just configure one of the indexes and let the credentials cache serve the rest. At the very least, keyring-gitlab-pypi is set-and-forget across multiple projects.

Metadata

Release files for keyring-gitlab-pypi 1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for keyring-gitlab-pypi 1.2
File Size Uploaded
keyring_gitlab_pypi-1.2.tar.gz 8.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for keyring-gitlab-pypi 1.2
File Interpreter ABI Platform
keyring_gitlab_pypi-1.2-py3-none-any.whl Python 3 none any Details

Total release size: 15.3 kB

Release files / keyring_gitlab_pypi-1.2.tar.gz

Download URL keyring_gitlab_pypi-1.2.tar.gz
Size 8.3 kB
Tags Source
SHA-256 checksum
How to use checksums
048f00715c65b87931c8fc5581fbfd995a62d923abdf83f27df782efb513e979
BLAKE2b-256 checksum
How to use checksums
ed3e00bd6760135fc9545c6967226ba2f13a07c5c65d21566293331c4c7b9edb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 27, 2026.

Transparency log

Release files / keyring_gitlab_pypi-1.2-py3-none-any.whl

Download URL keyring_gitlab_pypi-1.2-py3-none-any.whl
Size 7.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ec95fe4c000bfab06b5767e38c3c90a011697484e92f44cc03cfb19587a6ea82
BLAKE2b-256 checksum
How to use checksums
a1b8484e7dc0af46a15934a2c94b2e69d10540f2a66042add161d626ebfbc759
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 27, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.2 This release

2 release files

1.1

2 release files

1.0

2 release files

0.3

2 release files

0.2

2 release files

0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page