pqfile (Python bindings)
Python bindings for pqfile, a
quantum-resistant file encryption library: ML-KEM (512/768/1024) and hybrid
X25519+ML-KEM-768 key encapsulation with ChaCha20-Poly1305 authenticated
encryption. Built with PyO3 and packaged with
maturin; the crypto itself lives entirely in the
pqfile Rust crate, not in this binding layer.
Install (from source, until wheels are published)
pip install maturin
cd pqfile-python
maturin develop --release
Quick start
import pqfile
# Generate a key pair
pub_pem, priv_pem = pqfile.keygen() # level=768 by default; also 512, 1024
# Encrypt / decrypt in memory
ciphertext = pqfile.encrypt_bytes(pub_pem, b"hello, post-quantum world")
plaintext = pqfile.decrypt_bytes(priv_pem, ciphertext)
assert plaintext == b"hello, post-quantum world"
# Encrypt / decrypt files directly (streams; flat memory use regardless of size)
pqfile.encrypt_file(pub_pem, "report.pdf", "report.pdf.pqf")
pqfile.decrypt_file(priv_pem, "report.pdf.pqf", "report.pdf")
A passphrase-protected private key:
pub_pem, priv_pem = pqfile.keygen(passphrase="correct horse battery staple")
plaintext = pqfile.decrypt_bytes(priv_pem, ciphertext, passphrase="correct horse battery staple")
Hybrid X25519 + ML-KEM-768 (defense in depth against a future ML-KEM break):
pub_pem, priv_pem = pqfile.keygen_hybrid()
Errors
All failures raise pqfile.PqfileError, a subclass of Exception, with a
human-readable message and the stable numeric error code from
docs/ERROR_CODES.md appended, e.g.
decryption failure: authentication tag mismatch (code 7).
Scope
This wraps pqfile::encrypt/pqfile::decrypt's single-recipient streaming
path only (keygen/encrypt_bytes/decrypt_bytes/encrypt_file/decrypt_file).
Multi-recipient encryption, signing/signcrypt, Shamir sharing, certificates,
and the other CLI features are not yet exposed here - see
docs/ROADMAP.md, "Python, Node.js, and mobile bindings", for status.
Compatibility
Produces and reads the same .pqf v3/v5 wire format as the pqfile CLI and
GUI (see docs/FORMAT.md), so files are interchangeable in both directions.
CI and publishing
ci.yml's bindings-python job builds this crate and runs the pytest suite
on every push/PR. publish-python.yml is scaffolding for the actual PyPI
release - it builds wheels for Linux (manylinux, via PyO3/maturin-action's
bundled Docker image)/Windows/macOS (x86_64 and aarch64) plus an sdist, and
would publish them to PyPI on a GitHub Release being published. It has never
actually run: publishing uses PyPI Trusted Publishing (OIDC) rather than a
stored token, which needs a one-time "pending publisher" registered on PyPI
first (pypi.org -> your account -> Publishing -> Add a new pending
publisher) - project name pqfile, owner dangel34, repository
PQ-File-Encryption, workflow publish-python.yml, environment release.
Until that's registered, the publish job's id-token: write permission has
nothing to authenticate against and the upload step fails.
Metadata
Release files for pqfile 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pqfile-0.1.0.tar.gz | 396.8 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| pqfile-0.1.0-cp312-cp312-win_amd64.whl | CPython 3.12 | CPython 3.12 | Windows x86-64 | Details |
| pqfile-0.1.0-cp312-cp312-macosx_11_0_arm64.whl | CPython 3.12 | CPython 3.12 | macOS 11.0+ ARM64 | Details |
| pqfile-0.1.0-cp312-cp312-macosx_10_12_x86_64.whl | CPython 3.12 | CPython 3.12 | macOS 10.12+ x86-64 | Details |
| pqfile-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.9 | CPython 3.9 | Linux glibc 2.17+ x86-64 | Details |
Total release size: 3.5 MB
Release files / pqfile-0.1.0.tar.gz
| Download URL | pqfile-0.1.0.tar.gz |
|---|---|
| Size | 396.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8cf02efd02e8d12800985aa9e581cea64b2232d980592215b58b49c9b0ac8c15
|
|
BLAKE2b-256 checksum How to use checksums |
515900317297caaf7dcfdb792f42bf82adb39627a23310b606847261d955e478
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.
Transparency logRelease files / pqfile-0.1.0-cp312-cp312-win_amd64.whl
| Download URL | pqfile-0.1.0-cp312-cp312-win_amd64.whl |
|---|---|
| Size | 1.1 MB |
| Tags | CPython 3.12 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
c1f846e522d3f9fcd56ab8e02b1128799ec32fa0d0ffc57b1cf4efe3a41309e9
|
|
BLAKE2b-256 checksum How to use checksums |
fb80b35848705f86d1654e61054dc8ee1cc7d11819985d46934681d114366b96
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.
Transparency logRelease files / pqfile-0.1.0-cp312-cp312-macosx_11_0_arm64.whl
| Download URL | pqfile-0.1.0-cp312-cp312-macosx_11_0_arm64.whl |
|---|---|
| Size | 593.4 kB |
| Tags | CPython 3.12 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
5f2fb9f56faa2d0d077f1bcde170c6514349472df1a03ae67c94d5c4b8c26cc3
|
|
BLAKE2b-256 checksum How to use checksums |
254ead4608837b142cb78ab911bd5b5ccd45eb1de0897cacfb646a0a6c8c6071
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.
Transparency logRelease files / pqfile-0.1.0-cp312-cp312-macosx_10_12_x86_64.whl
| Download URL | pqfile-0.1.0-cp312-cp312-macosx_10_12_x86_64.whl |
|---|---|
| Size | 637.8 kB |
| Tags | CPython 3.12 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
5e099adeb621f4c7aa5a3cbde55e71fc59f6bd4b40e017f436cceca65cbc940d
|
|
BLAKE2b-256 checksum How to use checksums |
5525dab6cf24e72a85d98fc174090ca0172f4966770cc7cb0e550f8743542477
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.
Transparency logRelease files / pqfile-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | pqfile-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 712.6 kB |
| Tags | CPython 3.9 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
7f531145234ac68f052a08ca8cc4fe92df98d22b1e9aa73a224f38423a5d5323
|
|
BLAKE2b-256 checksum How to use checksums |
916dd6c0f3f392a1c037c0f4ecd3334d1d9c16ff1087800783d5673ccf67299f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.
Transparency log