Skip to main content

murk-secrets

PyPI

Python bindings for murk — an encrypted secrets manager for developers.

murk stores encrypted secrets in a single .murk file safe to commit to git. This package lets Python apps read those secrets at runtime.

Prerequisites

You need the murk CLI to create and manage vaults. This package only reads them.

# Install the CLI first
brew tap iicky/murk && brew install murk

# Initialize a vault and add secrets
murk init
murk add DATABASE_URL
murk add API_KEY

Then add the Python package to your project:

pip install murk-secrets

Quick start

# Load your key (created by murk init)
source .env
import murk

# Load the vault (reads MURK_KEY from environment)
vault = murk.load()

# Get a single secret
db_url = vault.get("DATABASE_URL")

# Get all secrets as a dict
secrets = vault.export()

# Dict-style access
api_key = vault["API_KEY"]

API

murk.load(vault_path=".murk") -> Vault

Load and decrypt a murk vault. Reads MURK_KEY or MURK_KEY_FILE from the environment.

murk.get(key, vault_path=".murk") -> str | None

One-liner: load the vault and get a single value.

murk.export_all(vault_path=".murk") -> dict[str, str]

One-liner: load the vault and export all secrets as a dict.

murk.has_identity() -> bool

Whether a decryption identity (MURK_KEY / MURK_KEY_FILE) is available — i.e. whether load() can decrypt. This is not a check for whether a secret exists; use key in vault / vault.keys() for that.

Vault

Method Returns Description
vault.get(key) str | None Get a single decrypted value
vault.export() dict[str, str] All secrets as a dict
vault.keys() list[str] List of key names
vault[key] str Dict-style access (raises on missing key)
key in vault bool Check if a key exists
len(vault) int Number of secrets

Scoped (per-user) overrides are applied automatically — if you have a scoped value for a key, it takes priority over the shared value.

Memory hygiene

Every decrypted value murk returns is a plain Python string. murk zeroes plaintext from its own memory when a value is dropped, but that guarantee ends at the FFI boundary: once a value crosses into Python the interpreter owns it, and its garbage collector — not murk — controls its lifetime. This is inherent to reading secrets into a process (see the threat model); avoid holding decrypted values longer than you need them.

Agent policy

When the loaded key is an agent grant (minted with murk agent grant), the vault's agent policy is enforced on read, the same way the CLI enforces it at murk agent exec: get() and export() raise RuntimeError if the policy forbids a key. Operator keys are unaffected. This makes a policy vault strict from every entry point — though an agent already cannot decrypt out-of-scope secrets at all, since its ephemeral key is not a recipient of them.

Environment

Set one of:

  • MURK_KEY — your age secret key directly
  • MURK_KEY_FILE — path to your key file (created by murk init)

The easiest setup is source .env in your project directory after running murk init.

Requirements

  • Python >= 3.9
  • murk CLI installed (to create and manage vaults)
  • A .murk vault file in your project (created with murk init)
  • MURK_KEY or MURK_KEY_FILE in the environment (created by murk init, loaded via source .env)

License

MIT OR Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

murk_secrets-0.10.1.tar.gz (6.6 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

murk_secrets-0.10.1-cp39-abi3-win_amd64.whl (999.8 kB view details)

Uploaded CPython 3.9+Windows x86-64

murk_secrets-0.10.1-cp39-abi3-manylinux_2_28_aarch64.whl (1.2 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.28+ ARM64

murk_secrets-0.10.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.3 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.17+ x86-64

murk_secrets-0.10.1-cp39-abi3-macosx_11_0_arm64.whl (1.1 MB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

murk_secrets-0.10.1-cp39-abi3-macosx_10_12_x86_64.whl (1.2 MB view details)

Uploaded CPython 3.9+macOS 10.12+ x86-64

File details

Details for the file murk_secrets-0.10.1.tar.gz.

File metadata

  • Download URL: murk_secrets-0.10.1.tar.gz
  • Upload date:
  • Size: 6.6 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for murk_secrets-0.10.1.tar.gz
Algorithm Hash digest
SHA256 d7f09357f3160934039cc6a33861d9f51e3f9fb00a8e09bfa8cba35310c20044
MD5 f59ad3d1d830ce326c652a881ecfbfe3
BLAKE2b-256 cf9ad8467b23d0130b8050f9361c424a7cf981e6c92f68d0a5f6c3fcd1e6ee11

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.1.tar.gz:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.1-cp39-abi3-win_amd64.whl.

File metadata

  • Download URL: murk_secrets-0.10.1-cp39-abi3-win_amd64.whl
  • Upload date:
  • Size: 999.8 kB
  • Tags: CPython 3.9+, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for murk_secrets-0.10.1-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 7b91ba66b9f3a498594475a8b43a3ef99ffc305a8e54e3aa168cc1c06716a338
MD5 710f5a6169974cf3d2beddfdc418a763
BLAKE2b-256 4c56724b71e80baed1992b25a564a64621c07ecf738e042230137b1d965a0cf7

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.1-cp39-abi3-win_amd64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.1-cp39-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.1-cp39-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 6ec251dc113e324524ec1c4210ebcb0923ffa62c94a6f15f83435c7c95ed1c05
MD5 0a818494f9e54364397cb2bec4ff7ae2
BLAKE2b-256 28d8366cd6088923e8f15a1ee9cd9086992fbd3992bde5f0e8ab9ee2ad5f3380

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.1-cp39-abi3-manylinux_2_28_aarch64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 a02f89ad1248a5b88be22d3bc246a2c78a2fc1d1676215ccb2ce0052ac4f4bc6
MD5 dab06e808e12943ca26d784a30f8302a
BLAKE2b-256 2c09565abd5520d57fa823807f0b61dcb085d65aadac31f4125034e92adf2445

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.1-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.1-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 fdb51c1a05c18d745dad649d7f2b8e41935298f80c3427963ac943be2aa421ae
MD5 ccd2252f904af2ab8b4e628a7d55cb5b
BLAKE2b-256 a9d011569f6ba26d3ec5e92db60c35e34c8a80d8bb500135720fad9b70bca656

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.1-cp39-abi3-macosx_11_0_arm64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.1-cp39-abi3-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.1-cp39-abi3-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 87292009453fd5f5df157e94c49c807f5a7c0c01a0848667c2f5ea3389af5361
MD5 66e97bf1c9518b8979ca8ae07472f0df
BLAKE2b-256 0e9f093d61c0ab8dbedc251973444eceee7355a3cb18d9f4b749e8a1495ea3d4

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.1-cp39-abi3-macosx_10_12_x86_64.whl:

Publisher: python.yaml on iicky/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.11.0

6 files

0.10.3

6 files

0.10.2

6 files

This release

0.10.1 This release

6 files

0.10.0

6 files

0.9.1

6 files

0.9.0

6 files

0.8.0

6 files

0.7.0

6 files

0.6.2

6 files

0.6.1

6 files

0.6.0

6 files

0.5.11

6 files

0.5.10

6 files

0.5.9

6 files

0.5.8

6 files

0.5.7

6 files

0.5.6

6 files

0.5.5

6 files

0.5.4

6 files

0.5.3

6 files

0.5.1

6 files

0.5.0

6 files

0.4.1

6 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page