Lanyard Python SDK 0.2
A synchronous desktop/CLI client for the local Lanyard vault. Requires Lanyard desktop 0.2 or later and Python 3.9+.
pip install 'lanyard>=0.2.0,<0.3'
from lanyard import LanyardClient
client = LanyardClient('My desktop app', app_id='com.example.desktop')
linked = client.request_link(category='api_key', reason='Choose a key for this connection.')
# Save this nonsecret ID in your application preferences.
target_id = linked['target_id']
key = client.get_field(target_id, 'API_KEY')
The user must approve requests. Always grants work while the vault is unlocked. Pairing identities are generated randomly and stored in the OS credential store using keyring; names alone cannot inherit permissions. Linux needs an unlocked Secret Service keyring. No plaintext credential fallback is used.
For an ephemeral CLI invocation use session_only=True. Apps with their own secure store may pass a CredentialStore implementing load(app_id) -> Credential | None and save(app_id, credential). Preserve the same identity between launches. Credential.token is excluded from its representation, but must still be treated as a secret.
python -m lanyard --app 'My CLI' --app-id com.example.cli link --category api_key
python -m lanyard --app 'My CLI' --app-id com.example.cli get ITEM_UUID --field API_KEY
These explicit CLI commands print requested secrets to stdout. Direct output to the consuming process, avoid logs and command history, and do not place tokens on command lines.
Errors derive from LanyardError: LanyardNotRunningError, LanyardAccessDeniedError, LanyardTimeoutError, LanyardKeyNotFoundError, and LanyardUpgradeRequiredError. Requests rediscover the desktop port each time, bypass proxies, reject redirects, and enforce response limits. The maximum consent timeout is 300 seconds.
Migrating 0.1.2
Upgrade SDK and desktop together. Existing method names and return shapes are retained. Add a stable app_id (recommended), and handle native keychain availability. Old name-based grants require user approval again. First-launch desktop migration keeps the original Python vault untouched and imports its items/projects after validating its PIN.
The language-independent protocol is documented in the desktop project's docs/DESKTOP_API.md. Any native language with HTTP, JSON, secure randomness, and a credential-store integration can implement it.
Run tests with python -m unittest discover -s tests.
Metadata
Release files for lanyard 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| lanyard-0.2.0.tar.gz | 8.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| lanyard-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.9 kB
Release files / lanyard-0.2.0.tar.gz
| Download URL | lanyard-0.2.0.tar.gz |
|---|---|
| Size | 8.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5d7f7ffd92474b5c9227a1c620b908f85d6a8b733dd7b772fc1999cf9f63f137
|
|
BLAKE2b-256 checksum How to use checksums |
7eb3628c01fa50943ed97309fcf27c513bbf7d2f37ad15e1502442b3eb66ca09
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.3
|
Release files / lanyard-0.2.0-py3-none-any.whl
| Download URL | lanyard-0.2.0-py3-none-any.whl |
|---|---|
| Size | 8.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ea22a8afbbacfb290216069c5e6695883567a7daf5314d6acd3ec84910eb8a00
|
|
BLAKE2b-256 checksum How to use checksums |
a30e7e334709829fa797ced774df42c4db6491e0f434f04dff4034aa197d76d0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.3
|