Skip to main content

KeySigil

Embeddable API key management SDK with LLM token budget tracking.

from keysigil import KeyForge

kf = KeyForge("sqlite:///keys.db")
await kf.setup()

# Create key — plaintext shown once
result = await kf.create_key(
    name="Production",
    rate_limit={"requests": 100, "window": "1m"},
    token_budget={"monthly": 1_000_000},
    permissions=["models.invoke"],
)
print(result.plaintext)  # kf_live_abc123...

# Verify on every request
v = await kf.verify(result.plaintext)
print(v.valid, v.permissions, v.token_budget_remaining)

# Track LLM usage
await kf.track_usage(result.key.id, input_tokens=500, output_tokens=200, model="claude-sonnet-5-5")

Install

pip install keysigil                    # core (SQLite)
pip install 'keysigil[cli]'             # + CLI
pip install 'keysigil[all]'             # everything

CLI

keysigil init
keysigil create --name "my-key" --rate-requests 100 --monthly-tokens 500000
keysigil verify kf_live_xxx
keysigil list
keysigil usage key_xxx
keysigil rotate key_xxx
keysigil revoke key_xxx

Storage backends

  • SQLite (default) — dev / single-server
  • PostgreSQL — pip install 'keysigil[postgres]', use postgresql://... URL
  • Redis — pip install 'keysigil[redis]', for rate limiting

FastAPI middleware

from keysigil.middleware.fastapi import KeyForgeAuth

auth = KeyForgeAuth(kf, require_permissions=["models.invoke"])

@app.post("/chat", dependencies=[Depends(auth)])
async def chat(request: Request):
    key_id = request.state.key_id  # injected by middleware

MCP server (LLM agents)

keysigil serve

Tools: create_api_key, verify_api_key, list_api_keys, revoke_api_key, track_token_usage, get_usage_stats

Key design

  • Format: kf_live_<256-bit-random> (Stripe pattern, enables GitHub secret scanning)
  • Hash: SHA-256 (high-entropy keys; argon2 too slow for hot-path verification)
  • Rate limiting: sliding window algorithm (Cloudflare-proven)
  • Plaintext shown once at creation — never stored

Metadata

Release files for keysigil 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for keysigil 0.1.2
File Size Uploaded
keysigil-0.1.2.tar.gz 17.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for keysigil 0.1.2
File Interpreter ABI Platform
keysigil-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 40.6 kB

Release files / keysigil-0.1.2.tar.gz

Download URL keysigil-0.1.2.tar.gz
Size 17.7 kB
Tags Source
SHA-256 checksum
How to use checksums
a2effa4f77c416c281dc452bdaab2dc7515f5db56e00644e419f2b9901dc3513
BLAKE2b-256 checksum
How to use checksums
8beca477eae0f58afd5226ef698e377675399222f212bfff7a678e6bfc7c7376
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release files / keysigil-0.1.2-py3-none-any.whl

Download URL keysigil-0.1.2-py3-none-any.whl
Size 22.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
263607e9d10c15be1d1693036059c6e856c6cb8c17d17c4a98f7fc4f27a6e880
BLAKE2b-256 checksum
How to use checksums
ac4dd80463767c24d3b18f440dca44eaf56ecf7e29414541a38784b7465c4a58
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page