Skip to main content

murk-secrets

PyPI

Python bindings for murk — an encrypted secrets manager for developers.

murk stores encrypted secrets in a single .murk file safe to commit to git. This package lets Python apps read those secrets at runtime.

Prerequisites

You need the murk CLI to create and manage vaults. This package only reads them.

# Install the CLI first
brew tap interrupted-inc/murk && brew install murk

# Initialize a vault and add secrets
murk init
murk add DATABASE_URL
murk add API_KEY

Then add the Python package to your project:

pip install murk-secrets

Quick start

# Load your key (created by murk init)
source .env
import murk

# Load the vault (reads MURK_KEY from environment)
vault = murk.load()

# Get a single secret
db_url = vault.get("DATABASE_URL")

# Get all secrets as a dict
secrets = vault.export()

# Dict-style access
api_key = vault["API_KEY"]

API

murk.load(vault_path=".murk") -> Vault

Load and decrypt a murk vault. Reads MURK_KEY or MURK_KEY_FILE from the environment.

murk.get(key, vault_path=".murk") -> str | None

One-liner: load the vault and get a single value.

murk.export_all(vault_path=".murk") -> dict[str, str]

One-liner: load the vault and export all secrets as a dict.

murk.has_identity() -> bool

Whether a decryption identity (MURK_KEY / MURK_KEY_FILE) is available — i.e. whether load() can decrypt. This is not a check for whether a secret exists; use key in vault / vault.keys() for that.

Vault

Method Returns Description
vault.get(key) str | None Get a single decrypted value
vault.export() dict[str, str] All secrets as a dict
vault.keys() list[str] List of key names
vault[key] str Dict-style access (raises on missing key)
key in vault bool Check if a key exists
len(vault) int Number of secrets

Scoped (per-user) overrides are applied automatically — if you have a scoped value for a key, it takes priority over the shared value.

Memory hygiene

Every decrypted value murk returns is a plain Python string. murk zeroes plaintext from its own memory when a value is dropped, but that guarantee ends at the FFI boundary: once a value crosses into Python the interpreter owns it, and its garbage collector — not murk — controls its lifetime. This is inherent to reading secrets into a process (see the threat model); avoid holding decrypted values longer than you need them.

Agent policy

When the loaded key is an agent grant (minted with murk agent grant), the vault's agent policy is enforced on read, the same way the CLI enforces it at murk agent exec: get() and export() raise RuntimeError if the policy forbids a key. Operator keys are unaffected. This makes a policy vault strict from every entry point — though an agent already cannot decrypt out-of-scope secrets at all, since its ephemeral key is not a recipient of them.

Environment

Set one of:

  • MURK_KEY — your age secret key directly
  • MURK_KEY_FILE — path to your key file (created by murk init)

The easiest setup is source .env in your project directory after running murk init.

Requirements

  • Python >= 3.9
  • murk CLI installed (to create and manage vaults)
  • A .murk vault file in your project (created with murk init)
  • MURK_KEY or MURK_KEY_FILE in the environment (created by murk init, loaded via source .env)

License

MIT OR Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

murk_secrets-0.10.3.tar.gz (7.1 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

murk_secrets-0.10.3-cp39-abi3-win_amd64.whl (1.0 MB view details)

Uploaded CPython 3.9+Windows x86-64

murk_secrets-0.10.3-cp39-abi3-manylinux_2_28_aarch64.whl (1.2 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.28+ ARM64

murk_secrets-0.10.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.3 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.17+ x86-64

murk_secrets-0.10.3-cp39-abi3-macosx_11_0_arm64.whl (1.1 MB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

murk_secrets-0.10.3-cp39-abi3-macosx_10_12_x86_64.whl (1.2 MB view details)

Uploaded CPython 3.9+macOS 10.12+ x86-64

File details

Details for the file murk_secrets-0.10.3.tar.gz.

File metadata

  • Download URL: murk_secrets-0.10.3.tar.gz
  • Upload date:
  • Size: 7.1 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for murk_secrets-0.10.3.tar.gz
Algorithm Hash digest
SHA256 a2062ad41bf641c2eaf9b0460d82220c49d86b3b6014a63207fe0fd614701b00
MD5 6e7b91a47df3da8ff6ebe8c084237562
BLAKE2b-256 d20ef6b6333abdd8869a248370cd241f6f50195080357844d6fc7f39f8b6e90f

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.3.tar.gz:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.3-cp39-abi3-win_amd64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.3-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 0d8ad39aec3975d874b66789aabd7577e625b9757711958ddda94a0fe5211c7f
MD5 e859af07f0c9a3ddefc5c89dab4c8d85
BLAKE2b-256 070f72a6f934333b73f47ded2f8714e52276b4e6ec28d5469e13d4f52dfb167a

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.3-cp39-abi3-win_amd64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.3-cp39-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.3-cp39-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 8bd39489ea5a5d99c1c11ad2008713a2f834c5b6864db3513f4e9b3db1444984
MD5 f0483d6283a6d2e409b85b0d4e9f7666
BLAKE2b-256 71b8bc718aa108c1ece9a89641d06a2a211d99b0ecd623d98b297e286e958468

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.3-cp39-abi3-manylinux_2_28_aarch64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 b4f225bb74932ca75bc5a4cc1d6d471914fac4731f3483e40bb43f7b74d7c9c8
MD5 79b0cc08e01a59bb2a8687e91679c5bd
BLAKE2b-256 6cb84e0b90ca13ef087c7ccc7f34a3dd384158f54101ac53a898dc2216710520

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.3-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.3-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 e3d08e1470e23fb31605fde470253049328ec53d6bf48b7b556deb6c3fd5388e
MD5 0b950d7b43aa34e564dffa0e8e35e269
BLAKE2b-256 e55c88a58c9233cf015809f62ca107e247f8fab350ef72e5c93b90be4ae440d3

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.3-cp39-abi3-macosx_11_0_arm64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.10.3-cp39-abi3-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.10.3-cp39-abi3-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 32f79487b58e8d49cd65e4a608341eac4d5327ee6ecd1bce6baba1d9e5101dd8
MD5 b0c6dc667744ef1475477ceba3c93437
BLAKE2b-256 e626c17518c1b3aa8bda2de025e3fe960e5fcdb042c016a492fbe6a68e1790db

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.10.3-cp39-abi3-macosx_10_12_x86_64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.11.0

6 files

This release

0.10.3 This release

6 files

0.10.2

6 files

0.10.1

6 files

0.10.0

6 files

0.9.1

6 files

0.9.0

6 files

0.8.0

6 files

0.7.0

6 files

0.6.2

6 files

0.6.1

6 files

0.6.0

6 files

0.5.11

6 files

0.5.10

6 files

0.5.9

6 files

0.5.8

6 files

0.5.7

6 files

0.5.6

6 files

0.5.5

6 files

0.5.4

6 files

0.5.3

6 files

0.5.1

6 files

0.5.0

6 files

0.4.1

6 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page