Skip to main content

murk-secrets

PyPI

Python bindings for murk — an encrypted secrets manager for developers.

murk stores encrypted secrets in a single .murk file safe to commit to git. This package lets Python apps read those secrets at runtime.

Prerequisites

You need the murk CLI to create and manage vaults. This package only reads them.

# Install the CLI first
brew tap interrupted-inc/murk && brew install murk

# Initialize a vault and add secrets
murk init
murk add DATABASE_URL
murk add API_KEY

Then add the Python package to your project:

pip install murk-secrets

Quick start

# Load your key (created by murk init)
source .env
import murk

# Load the vault (reads MURK_KEY from environment)
vault = murk.load()

# Get a single secret
db_url = vault.get("DATABASE_URL")

# Get all secrets as a dict
secrets = vault.export()

# Dict-style access
api_key = vault["API_KEY"]

API

murk.load(vault_path=".murk") -> Vault

Load and decrypt a murk vault. Reads MURK_KEY or MURK_KEY_FILE from the environment.

murk.get(key, vault_path=".murk") -> str | None

One-liner: load the vault and get a single value.

murk.export_all(vault_path=".murk") -> dict[str, str]

One-liner: load the vault and export all secrets as a dict.

murk.has_identity() -> bool

Whether a decryption identity (MURK_KEY / MURK_KEY_FILE) is available — i.e. whether load() can decrypt. This is not a check for whether a secret exists; use key in vault / vault.keys() for that.

Vault

Method Returns Description
vault.get(key) str | None Get a single decrypted value
vault.export() dict[str, str] All secrets as a dict
vault.keys() list[str] List of key names
vault[key] str Dict-style access (raises on missing key)
key in vault bool Check if a key exists
len(vault) int Number of secrets

Scoped (per-user) overrides are applied automatically — if you have a scoped value for a key, it takes priority over the shared value.

Memory hygiene

Every decrypted value murk returns is a plain Python string. murk zeroes plaintext from its own memory when a value is dropped, but that guarantee ends at the FFI boundary: once a value crosses into Python the interpreter owns it, and its garbage collector — not murk — controls its lifetime. This is inherent to reading secrets into a process (see the threat model); avoid holding decrypted values longer than you need them.

Agent policy

When the loaded key is an agent grant (minted with murk agent grant), the vault's agent policy is enforced on read, the same way the CLI enforces it at murk agent exec: get() and export() raise RuntimeError if the policy forbids a key. Operator keys are unaffected. This makes a policy vault strict from every entry point — though an agent already cannot decrypt out-of-scope secrets at all, since its ephemeral key is not a recipient of them.

Environment

Set one of:

  • MURK_KEY — your age secret key directly
  • MURK_KEY_FILE — path to your key file (created by murk init)

The easiest setup is source .env in your project directory after running murk init.

Requirements

  • Python >= 3.9
  • murk CLI installed (to create and manage vaults)
  • A .murk vault file in your project (created with murk init)
  • MURK_KEY or MURK_KEY_FILE in the environment (created by murk init, loaded via source .env)

License

MIT OR Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

murk_secrets-0.11.0.tar.gz (7.1 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

murk_secrets-0.11.0-cp39-abi3-win_amd64.whl (1.2 MB view details)

Uploaded CPython 3.9+Windows x86-64

murk_secrets-0.11.0-cp39-abi3-manylinux_2_28_aarch64.whl (1.2 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.28+ ARM64

murk_secrets-0.11.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (1.3 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.17+ x86-64

murk_secrets-0.11.0-cp39-abi3-macosx_11_0_arm64.whl (1.1 MB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

murk_secrets-0.11.0-cp39-abi3-macosx_10_12_x86_64.whl (1.2 MB view details)

Uploaded CPython 3.9+macOS 10.12+ x86-64

File details

Details for the file murk_secrets-0.11.0.tar.gz.

File metadata

  • Download URL: murk_secrets-0.11.0.tar.gz
  • Upload date:
  • Size: 7.1 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for murk_secrets-0.11.0.tar.gz
Algorithm Hash digest
SHA256 f77c4ecc86c22b8039f9ec131ab7f7c7cbd6c9916d6e67e0dd9d75d6f443ed29
MD5 c7e4bd206990907198013dbd4d46c46a
BLAKE2b-256 c44e0e2bc2b7f91dd2202943745e0648aded3c79d442726170c34c593dbd1064

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.11.0.tar.gz:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.11.0-cp39-abi3-win_amd64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.11.0-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 249f5927f9974d99d999b914bcdbfedcae8993234a3056aa04f4f5fa10f83c24
MD5 a84c78da057f385f9c7569e7dde6f586
BLAKE2b-256 bdf801ff03ef193156ca6a9842aef04403f604af28b0922eafdf489c8bd4a87e

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.11.0-cp39-abi3-win_amd64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.11.0-cp39-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.11.0-cp39-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 80fbb8addd208b5a0896f289d73e72c0a2016fdc5185014b9f36fabb6c87c3a3
MD5 932f44a3a3a90263e0bd9e057037616d
BLAKE2b-256 3c2e6f3fb46df642d33db333fca1b174dc4d7a2bae2a45c31557a8d5669e1f04

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.11.0-cp39-abi3-manylinux_2_28_aarch64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.11.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.11.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 ed10a8de8a7e6fcb13a2136a0b43d2e88d8964b3735d73efe30a9c2ad70b7848
MD5 2777e4d4577b8e5c57fb1c547ddb25c1
BLAKE2b-256 a1b57ead731c1c22b41363160af3db9e02c4786efafb59f14593a2f934d9c16b

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.11.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.11.0-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.11.0-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 c8645ba71208ef997021a1340ebe33ec743dd67feda2ef23e926d992b3cd57fd
MD5 eb01b28651548018b0222cf76ff0438f
BLAKE2b-256 1ab788c25a3b0e0c3c520a6af1a672ee4dad394ac7876ec4632c7c883d277f1f

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.11.0-cp39-abi3-macosx_11_0_arm64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file murk_secrets-0.11.0-cp39-abi3-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for murk_secrets-0.11.0-cp39-abi3-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 afb460599803f5feb68c9417309994822a8aaf7150f22bfc7d67b0ad19d1ee60
MD5 59280d9f17b29253b1e401ae1c53fcf6
BLAKE2b-256 29cd618521e3f60e70a002cf49819098d34497a32acd4cbe14be874a4a4b9430

See more details on using hashes here.

Provenance

The following attestation bundles were made for murk_secrets-0.11.0-cp39-abi3-macosx_10_12_x86_64.whl:

Publisher: python.yaml on interrupted-inc/murk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.11.0 This release

6 files

0.10.3

6 files

0.10.2

6 files

0.10.1

6 files

0.10.0

6 files

0.9.1

6 files

0.9.0

6 files

0.8.0

6 files

0.7.0

6 files

0.6.2

6 files

0.6.1

6 files

0.6.0

6 files

0.5.11

6 files

0.5.10

6 files

0.5.9

6 files

0.5.8

6 files

0.5.7

6 files

0.5.6

6 files

0.5.5

6 files

0.5.4

6 files

0.5.3

6 files

0.5.1

6 files

0.5.0

6 files

0.4.1

6 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page