Skip to main content

Prometheus

CI Python License: MIT

World-class CLI for symmetric encryption of secrets. Legacy v1 compatible, modern v2 secure.

Features

  • Crypto v2 (recommended): ChaCha20-Poly1305 + Argon2id — authenticated encryption with forward secrecy
  • Crypto v1 (legacy): XOR + SHA-256 + Base64 — backward compatible, NOT recommended for new encryption
  • Auto-detect: Automatically detects algorithm version from ciphertext format
  • Interactive mode: Guided prompts for encrypt/decrypt operations
  • Multiple output formats: Human-readable panels, JSON, quiet mode

Install

pip install prometheus-crypto

Or with optional Argon2id support (recommended):

pip install "prometheus-crypto[crypto]"

Quick Start

Encrypt

# Interactive mode
prometheus encrypt --secret "my-secret-key" --plaintext "password123"

# JSON output
prometheus encrypt --secret "my-secret-key" --plaintext "password123" --format json

# Quiet output (just the ciphertext)
prometheus encrypt --secret "my-secret-key" --plaintext "password123" --format quiet

# Force v1 legacy algorithm
prometheus encrypt --secret "my-secret-key" --plaintext "password123" --algo v1

Decrypt

# Auto-detect version from ciphertext
prometheus decrypt --secret "my-secret-key" --ciphertext "v2|salt|nonce|ct|tag"

# JSON output
prometheus decrypt --secret "my-secret-key" --ciphertext "v2|salt|nonce|ct|tag" --format json

Interactive Mode

prometheus interactive
Choose operation:
  (e) Encrypt
  (d) Decrypt
  (v) Show version
  (f) Finish
>> e
Secret: my-secret-key
Password: password123
┌─────────────── Encrypted ───────────────┐
│ v2|...                                  │
└──────────────── algorithm: v2 ──────────┘

Version & Info

prometheus version    # Algorithm info
prometheus info       # Full architecture details

Architecture

src/prometheus/
├── domain/          # Core business logic (no dependencies)
│   ├── entities.py  # Profile, GlobalConfig
│   ├── value_objects.py  # SecretKey, Plaintext, Ciphertext
│   ├── ports.py     # CryptoPort, ConfigPort, StoragePort, OutputPort
│   └── events.py    # Domain events
├── cipher/          # Crypto adapters
│   ├── v1_legacy/   # XOR + SHA-256 + Base64 (INMUTABLE)
│   ├── v2_modern/   # ChaCha20-Poly1305 + Argon2id
│   └── factory.py   # Auto-detect version, adapter selection
├── cli/             # Typer + Rich CLI
│   └── app.py       # encrypt, decrypt, interactive, version, info
└── adapters/        # Future: storage, config, keyring adapters

Hexagonal architecture (Ports & Adapters):

  • Domain is pure business logic with zero I/O dependencies
  • Ports define interfaces (CryptoPort, ConfigPort, StoragePort, OutputPort)
  • Adapters implement those interfaces for concrete technologies

Security

  • Key derivation: Argon2id (OWASP 2024: 3 iterations, 64MB memory, 4 parallelism)
  • Fallback: PBKDF2-SHA256 (600k iterations) if argon2-cffi is not installed
  • Encryption: ChaCha20-Poly1305 AEAD (12-byte nonce, 16-byte tag)
  • Forward secrecy: Random salt + nonce per encryption
  • Format: v2|salt_b64|nonce_b64|ciphertext_b64|tag_b64

v1 (Legacy)

  • NOT cryptographically secure
  • XOR + SHA-256 + Base64/latin1 encoding
  • Retained solely for backward compatibility with existing v1 ciphertexts
  • Do not use for new encryption — use v2 instead

Development

Setup

git clone https://github.com/Kemquiros/Prometheus.git
cd Prometheus
python -m venv .venv
source .venv/bin/activate
pip install -e ".[crypto,dev]"

Quality

ruff check src/ tests/         # Lint
mypy src/prometheus/ --strict  # Type check
pytest tests/ -v               # Tests

Test Coverage

pytest tests/ --cov=prometheus --cov-report=term-missing

Coverage threshold: 90% (enforced in CI).

License

MIT — see LICENSE.md

Metadata

Release files for prometheus-crypto 2.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for prometheus-crypto 2.0.0
File Size Uploaded
prometheus_crypto-2.0.0.tar.gz 530.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for prometheus-crypto 2.0.0
File Interpreter ABI Platform
prometheus_crypto-2.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 573.2 kB

Release files / prometheus_crypto-2.0.0.tar.gz

Download URL prometheus_crypto-2.0.0.tar.gz
Size 530.1 kB
Tags Source
SHA-256 checksum
How to use checksums
0685752182d17b0a17bbece28eb2dd4f94de256bbe266492c28808f1725ba3ab
BLAKE2b-256 checksum
How to use checksums
d05072926015f04f64eb95285887b8ae86917a4d9ca12b79a4e91c3dae473037
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / prometheus_crypto-2.0.0-py3-none-any.whl

Download URL prometheus_crypto-2.0.0-py3-none-any.whl
Size 43.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
34b78b6aecf8abe26ead0c30f8539cffc140b535707ae259be9ac6bb116b5ae0
BLAKE2b-256 checksum
How to use checksums
17f913987ef24af89ca0fafa7695aaabfa43523456ce029fe656d27949f96316
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

2.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page