Skip to main content

murk-secrets

PyPI

Python bindings for murk — an encrypted secrets manager for developers.

murk stores encrypted secrets in a single .murk file safe to commit to git. This package lets Python apps read those secrets at runtime.

Prerequisites

You need the murk CLI to create and manage vaults. This package only reads them.

# Install the CLI first
brew tap iicky/murk && brew install murk

# Initialize a vault and add secrets
murk init
murk add DATABASE_URL
murk add API_KEY

Then add the Python package to your project:

pip install murk-secrets

Quick start

# Load your key (created by murk init)
source .env
import murk

# Load the vault (reads MURK_KEY from environment)
vault = murk.load()

# Get a single secret
db_url = vault.get("DATABASE_URL")

# Get all secrets as a dict
secrets = vault.export()

# Dict-style access
api_key = vault["API_KEY"]

API

murk.load(vault_path=".murk") -> Vault

Load and decrypt a murk vault. Reads MURK_KEY or MURK_KEY_FILE from the environment.

murk.get(key, vault_path=".murk") -> str | None

One-liner: load the vault and get a single value.

murk.export_all(vault_path=".murk") -> dict[str, str]

One-liner: load the vault and export all secrets as a dict.

murk.has_identity() -> bool

Whether a decryption identity (MURK_KEY / MURK_KEY_FILE) is available — i.e. whether load() can decrypt. This is not a check for whether a secret exists; use key in vault / vault.keys() for that.

Vault

Method Returns Description
vault.get(key) str | None Get a single decrypted value
vault.export() dict[str, str] All secrets as a dict
vault.keys() list[str] List of key names
vault[key] str Dict-style access (raises on missing key)
key in vault bool Check if a key exists
len(vault) int Number of secrets

Scoped (per-user) overrides are applied automatically — if you have a scoped value for a key, it takes priority over the shared value.

Memory hygiene

Every decrypted value murk returns is a plain Python string. murk zeroes plaintext from its own memory when a value is dropped, but that guarantee ends at the FFI boundary: once a value crosses into Python the interpreter owns it, and its garbage collector — not murk — controls its lifetime. This is inherent to reading secrets into a process (see the threat model); avoid holding decrypted values longer than you need them.

Agent policy

When the loaded key is an agent grant (minted with murk agent grant), the vault's agent policy is enforced on read, the same way the CLI enforces it at murk agent exec: get() and export() raise RuntimeError if the policy forbids a key. Operator keys are unaffected. This makes a policy vault strict from every entry point — though an agent already cannot decrypt out-of-scope secrets at all, since its ephemeral key is not a recipient of them.

Environment

Set one of:

  • MURK_KEY — your age secret key directly
  • MURK_KEY_FILE — path to your key file (created by murk init)

The easiest setup is source .env in your project directory after running murk init.

Requirements

  • Python >= 3.9
  • murk CLI installed (to create and manage vaults)
  • A .murk vault file in your project (created with murk init)
  • MURK_KEY or MURK_KEY_FILE in the environment (created by murk init, loaded via source .env)

License

MIT OR Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

murk_secrets-0.10.0.tar.gz (6.7 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

murk_secrets-0.10.0-cp39-abi3-win_amd64.whl (999.8 kB view details)

Uploaded CPython 3.9+Windows x86-64

murk_secrets-0.10.0-cp39-abi3-manylinux_2_28_aarch64.whl (1.2 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.28+ ARM64

murk_secrets-0.10.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.3 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.17+ x86-64

murk_secrets-0.10.0-cp39-abi3-macosx_11_0_arm64.whl (1.1 MB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

murk_secrets-0.10.0-cp39-abi3-macosx_10_12_x86_64.whl (1.2 MB view details)

Uploaded CPython 3.9+macOS 10.12+ x86-64

File details

Details for the file murk_secrets-0.10.0.tar.gz.

File metadata

  • Download URL: murk_secrets-0.10.0.tar.gz
  • Upload date:
  • Size: 6.7 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for murk_secrets-0.10.0.tar.gz
Algorithm Hash digest
SHA256 57edbf3a8f7dc60dd4fa5516911600dc31321e032937cb5864ea78132701cdb9
MD5 ca65cd9e683cb90762644c89a96856f7
BLAKE2b-256 45ae013437e4311850443938efed56bd8af42046b594495ea8a9a552581120b2

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.0.tar.gz:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.0-cp39-abi3-win_amd64.whl.

File metadata

  • Download URL: murk_secrets-0.10.0-cp39-abi3-win_amd64.whl
  • Upload date:
  • Size: 999.8 kB
  • Tags: CPython 3.9+, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for murk_secrets-0.10.0-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 ba6371022e0f6af7853dcda73b599dd26745d3530d41d98b658b563e8c0f0a3f
MD5 5706f7723418a136a41122cc9b0a9b41
BLAKE2b-256 33acc7f5b1523fd0cfaee59a995bb6183cf819d581150119f41e6e1bf89ad15d

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.0-cp39-abi3-win_amd64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.0-cp39-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.0-cp39-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 291edcf1d54134873b765a9e2a6e836ed8a575d30276d320182af4b542df417a
MD5 0c0bbe0b8e9ce29d7dfdd86553b663cd
BLAKE2b-256 a6416f726b2ef95e70a63b367137e11e1f88290221a8471a7aa9632bbfc0e077

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.0-cp39-abi3-manylinux_2_28_aarch64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 a6c0a0aaa80479db0bb4aa006e32c9569ab6e3c102c851cc51a50f710cd92a7c
MD5 ad7144eafaeac269dcc8600a12c90384
BLAKE2b-256 fb92abb8f10edc1dedefdcde73efd212f8923ee684517eb2fbc5324174856bc0

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.0-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.0-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 5b6a452805181009dd07196af74b935959ec796a59811cb96f318e9e254d48ed
MD5 0ef8da463073e7be51d2ed00e71a2884
BLAKE2b-256 84aaae64410166df7296f57bc631812f3e26086a13786d2b8416301c0010ad34

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.0-cp39-abi3-macosx_11_0_arm64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.0-cp39-abi3-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.0-cp39-abi3-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 045e96a5437e1daaff9333c214879439a16bb610047da4e33a302670f27e5937
MD5 6e04252a4a6747e4e0d2dd3a18cb4779
BLAKE2b-256 8e04ff582f0a60f4829693ed9e9d03dc0d0692438d169248a6091b63e543c258

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.0-cp39-abi3-macosx_10_12_x86_64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.11.0

6 files

0.10.3

6 files

0.10.2

6 files

0.10.1

6 files

This release

0.10.0 This release

6 files

0.9.1

6 files

0.9.0

6 files

0.8.0

6 files

0.7.0

6 files

0.6.2

6 files

0.6.1

6 files

0.6.0

6 files

0.5.11

6 files

0.5.10

6 files

0.5.9

6 files

0.5.8

6 files

0.5.7

6 files

0.5.6

6 files

0.5.5

6 files

0.5.4

6 files

0.5.3

6 files

0.5.1

6 files

0.5.0

6 files

0.4.1

6 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page