Skip to main content

pqfile (Python bindings)

Python bindings for pqfile, a quantum-resistant file encryption library: ML-KEM (512/768/1024) and hybrid X25519+ML-KEM-768 key encapsulation with ChaCha20-Poly1305 authenticated encryption. Built with PyO3 and packaged with maturin; the crypto itself lives entirely in the pqfile Rust crate, not in this binding layer.

Install (from source, until wheels are published)

pip install maturin
cd pqfile-python
maturin develop --release

Quick start

import pqfile

# Generate a key pair
pub_pem, priv_pem = pqfile.keygen()  # level=768 by default; also 512, 1024

# Encrypt / decrypt in memory
ciphertext = pqfile.encrypt_bytes(pub_pem, b"hello, post-quantum world")
plaintext = pqfile.decrypt_bytes(priv_pem, ciphertext)
assert plaintext == b"hello, post-quantum world"

# Encrypt / decrypt files directly (streams; flat memory use regardless of size)
pqfile.encrypt_file(pub_pem, "report.pdf", "report.pdf.pqf")
pqfile.decrypt_file(priv_pem, "report.pdf.pqf", "report.pdf")

A passphrase-protected private key:

pub_pem, priv_pem = pqfile.keygen(passphrase="correct horse battery staple")
plaintext = pqfile.decrypt_bytes(priv_pem, ciphertext, passphrase="correct horse battery staple")

Hybrid X25519 + ML-KEM-768 (defense in depth against a future ML-KEM break):

pub_pem, priv_pem = pqfile.keygen_hybrid()

Errors

All failures raise pqfile.PqfileError, a subclass of Exception, with a human-readable message and the stable numeric error code from docs/ERROR_CODES.md appended, e.g. decryption failure: authentication tag mismatch (code 7).

Scope

This wraps pqfile::encrypt/pqfile::decrypt's single-recipient streaming path only (keygen/encrypt_bytes/decrypt_bytes/encrypt_file/decrypt_file). Multi-recipient encryption, signing/signcrypt, Shamir sharing, certificates, and the other CLI features are not yet exposed here - see docs/ROADMAP.md, "Python, Node.js, and mobile bindings", for status.

Compatibility

Produces and reads the same .pqf v3/v5 wire format as the pqfile CLI and GUI (see docs/FORMAT.md), so files are interchangeable in both directions.

CI and publishing

ci.yml's bindings-python job builds this crate and runs the pytest suite on every push/PR. publish-python.yml is scaffolding for the actual PyPI release - it builds wheels for Linux (manylinux, via PyO3/maturin-action's bundled Docker image)/Windows/macOS (x86_64 and aarch64) plus an sdist, and would publish them to PyPI on a GitHub Release being published. It has never actually run: publishing uses PyPI Trusted Publishing (OIDC) rather than a stored token, which needs a one-time "pending publisher" registered on PyPI first (pypi.org -> your account -> Publishing -> Add a new pending publisher) - project name pqfile, owner dangel34, repository PQ-File-Encryption, workflow publish-python.yml, environment release. Until that's registered, the publish job's id-token: write permission has nothing to authenticate against and the upload step fails.

Metadata

Release files for pqfile 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pqfile 0.1.0
File Size Uploaded
pqfile-0.1.0.tar.gz 396.8 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for pqfile 0.1.0
File
pqfile-0.1.0-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
pqfile-0.1.0-cp312-cp312-macosx_11_0_arm64.whl CPython 3.12 CPython 3.12 macOS 11.0+ ARM64 Details
pqfile-0.1.0-cp312-cp312-macosx_10_12_x86_64.whl CPython 3.12 CPython 3.12 macOS 10.12+ x86-64 Details
pqfile-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.9 CPython 3.9 Linux glibc 2.17+ x86-64 Details

Total release size: 3.5 MB

Release files / pqfile-0.1.0.tar.gz

Download URL pqfile-0.1.0.tar.gz
Size 396.8 kB
Tags Source
SHA-256 checksum
How to use checksums
8cf02efd02e8d12800985aa9e581cea64b2232d980592215b58b49c9b0ac8c15
BLAKE2b-256 checksum
How to use checksums
515900317297caaf7dcfdb792f42bf82adb39627a23310b606847261d955e478
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.

Transparency log

Release files / pqfile-0.1.0-cp312-cp312-win_amd64.whl

Download URL pqfile-0.1.0-cp312-cp312-win_amd64.whl
Size 1.1 MB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
c1f846e522d3f9fcd56ab8e02b1128799ec32fa0d0ffc57b1cf4efe3a41309e9
BLAKE2b-256 checksum
How to use checksums
fb80b35848705f86d1654e61054dc8ee1cc7d11819985d46934681d114366b96
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.

Transparency log

Release files / pqfile-0.1.0-cp312-cp312-macosx_11_0_arm64.whl

Download URL pqfile-0.1.0-cp312-cp312-macosx_11_0_arm64.whl
Size 593.4 kB
Tags CPython 3.12 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
5f2fb9f56faa2d0d077f1bcde170c6514349472df1a03ae67c94d5c4b8c26cc3
BLAKE2b-256 checksum
How to use checksums
254ead4608837b142cb78ab911bd5b5ccd45eb1de0897cacfb646a0a6c8c6071
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.

Transparency log

Release files / pqfile-0.1.0-cp312-cp312-macosx_10_12_x86_64.whl

Download URL pqfile-0.1.0-cp312-cp312-macosx_10_12_x86_64.whl
Size 637.8 kB
Tags CPython 3.12 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
5e099adeb621f4c7aa5a3cbde55e71fc59f6bd4b40e017f436cceca65cbc940d
BLAKE2b-256 checksum
How to use checksums
5525dab6cf24e72a85d98fc174090ca0172f4966770cc7cb0e550f8743542477
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.

Transparency log

Release files / pqfile-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL pqfile-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 712.6 kB
Tags CPython 3.9 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
7f531145234ac68f052a08ca8cc4fe92df98d22b1e9aa73a224f38423a5d5323
BLAKE2b-256 checksum
How to use checksums
916dd6c0f3f392a1c037c0f4ecd3334d1d9c16ff1087800783d5673ccf67299f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 24, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

5 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page