Skip to main content

Scrypt for Python

There are a lot of different scrypt modules for Python, but none of them have everything that I’d like, so here’s One More1.

Features

  • Uses system libscrypt2 as the first choice.

  • If that isn’t available, tries the scrypt Python module3.

  • Offers a pure Python scrypt implementation for when there’s no C scrypt.

  • Not unusably slow, even in pure Python… at least with pypy4.

With PyPy as the interpreter the Python implementation is around one fifth the speed of C scrypt. With cPython it is one fiftieth if libsodium5 is available, one two-hundredth if not.

Requirements

  • Python 2.7 or 3.4 or so. Pypy 2.2 also works. Older versions may or may not.

  • If you want speed: libscrypt 1.8+ (older may work) or py-scrypt 0.6+ or pypy

Usage

You most likely want to create MCF hashes and store them somewhere, then check user-entered passwords against those hashes. For that you only need to use two functions from the API:

from pylibscrypt import *
# Generate an MCF hash with random salt
mcf = scrypt_mcf('Hello World')
# Test it
print(scrypt_mcf_check(mcf, 'Hello World'))   # prints True
print(scrypt_mcf_check(mcf, 'HelloPyWorld'))  # prints False

For full API, you can try help(pylibscrypt) from python.

Versioning

The package has a version number that can be read from python like so:

print(pylibscrypt.__version__)

The version number is of the form X.Y.Z, following Semantic Versioning6. Releases are tagged vX.Y.Z and release branches bX.Y.x when they differ from master.

Development

Development happens on GitHub2. If you find a bug, please open an issue there.

tests.py tests both implementations with some quick tests. Running either implementation directly will also compare to scrypt test vectors from the paper but this is slow for the Python version unless you have pypy. The best way to report a bug is to also provide a new test that fails, but that is not required.

The run_coverage.sh script calls coverage.py7 to report test coverage. If you would like to include a new feature, it should be adequately covered with tests.

Metadata

Release files for pylibscrypt 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pylibscrypt 1.1.0
File Size Uploaded
pylibscrypt-1.1.0.tar.gz 11.9 kB Details

Release files / pylibscrypt-1.1.0.tar.gz

Download URL pylibscrypt-1.1.0.tar.gz
Size 11.9 kB
Tags Source
SHA-256 checksum
How to use checksums
87c3e3d362b23027c81b38612bb07c97223b88eaffcf95190da64c395a0817a7
BLAKE2b-256 checksum
How to use checksums
5f5508c9edb0a4a0a0ca1abbc5b319d2d7092720b0b9343285ca01ca0773d2e0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

2.0.0

1 release file

1.8.0

1 release file

1.7.1

1 release file

1.7.0

1 release file

1.6.1

1 release file

1.6.0

1 release file

1.5.3

1 release file

1.5.2

1 release file

1.5.1

1 release file

1.5.0

1 release file

1.4.1

1 release file

1.4.0

1 release file

1.3.0

1 release file

1.2.1

1 release file

1.2.0

1 release file

1.1.3

1 release file

1.1.2

1 release file

1.1.1

1 release file

This release

1.1.0 This release

1 release file

1.0.3

1 release file

1.0.2

1 release file

1.0.1

1 release file

1.0.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page