knime-passbolt-py
Python wrapper for consuming Passbolt credentials in KNIME Python Script nodes, via the Credential to Python bridge node shipped in the knime-passbolt extension.
Install
The package is distributed via PyPI. A conda-forge feedstock is planned
but not yet available — mamba install knime-passbolt-py / conda install knime-passbolt-py will fail until then.
pip install knime-passbolt-py
Inside a conda or mamba environment, install with pip after ensuring pip
itself is present:
mamba install python=3.10 pip
pip install knime-passbolt-py
The package is pure-Python with no compiled dependencies, so a pip install
inside a conda env is safe.
Usage
In a KNIME workflow, wire:
Passbolt Connector → Get Secret → Credential to Python → Python Script
In the Python Script node:
import knime.scripting.io as knio
import requests
cred = knio.input_objects[0] # PassboltSecret instance
with cred as c: # bytearray zeroed on __exit__
h = c.basic_auth_header()
resp = requests.get(url, headers={"Authorization": h.decode()})
Security model
The credential lives in the KNIME JVM, in the existing in-memory
CredentialCache owned by the upstream Get Secret node. This wrapper carries
only a loopback broker URL (http://127.0.0.1:<port>/v1/auth-header) and a
short-lived bearer token. The Authorization header is fetched on demand,
held in a bytearray, and zeroed (ctypes.memset) when the with block
exits.
__slots__prevents__dict__introspection.__repr__shows the (non-secret) broker URL and a truncated session UUID; the token and credential bytes are never included.__reduce__re-pickles to the broker handshake — credential bytes are never serialized, even by accident.- Broker URL is validated to be loopback at every fetch; tampering with a saved pickle to redirect to an external host is rejected client-side.
Limits. In-process Python code can read the bytearray while the with
block is open. CPython does not provide hardware-enforced isolation. The
posture is on par with KNIME's own Credentials Configuration flow variable
combined with a disciplined helper class — better is not achievable in
CPython without sandboxing.
Supply-chain provenance
Releases are published to PyPI from GitHub Actions using OIDC Trusted
Publishing — no long-lived API token is stored anywhere. Each release also
ships PEP 740 attestations linking the artifacts to the exact workflow run that
built them. To report a vulnerability, see SECURITY.md.
Compatibility
This package version (0.1.2) is compatible with the knime-passbolt KNIME extension version 0.1.1.20260520 and later. The full extension-↔-package compatibility matrix lives in CONTRACT.md.
Changelog
See CHANGELOG.md for per-release notes, including the
security hardening recorded for each version.
License
Apache 2.0. See the LICENSE file shipped with this package, or
https://www.apache.org/licenses/LICENSE-2.0.
About
knime-passbolt-py is published by Datanautics GmbH
as the companion Python package for the knime-passbolt KNIME extension.
Source: https://github.com/DataNautics-GmbH/knime-passbolt-py Issues: https://github.com/DataNautics-GmbH/knime-passbolt-py/issues
Metadata
Release files for knime-passbolt-py 0.1.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| knime_passbolt_py-0.1.3.tar.gz | 19.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| knime_passbolt_py-0.1.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 35.1 kB
Release files / knime_passbolt_py-0.1.3.tar.gz
| Download URL | knime_passbolt_py-0.1.3.tar.gz |
|---|---|
| Size | 19.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9eb2a4a8efe2ed3112afe680174b268d030964d8246d459c2957c090ffd51566
|
|
BLAKE2b-256 checksum How to use checksums |
417e5322f66a5360b842b0e87c695f1e3a5a231beff6b2eafb4f704b13e32606
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 1, 2026.
Transparency logRelease files / knime_passbolt_py-0.1.3-py3-none-any.whl
| Download URL | knime_passbolt_py-0.1.3-py3-none-any.whl |
|---|---|
| Size | 15.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2685eea766be528e1ab4bec0464a9a5f1126767467abdec0cdad51bcfffcaf16
|
|
BLAKE2b-256 checksum How to use checksums |
54ec6dad01239e0acf64785daafa71661daa8d87738d5b21dfa8af8dfb3aaeb0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 1, 2026.
Transparency log