Skip to main content

pyonyphe

CI PyPI Python

Python client and command line interface for ONYPHE, the Cyber Defense Search Engine.

  • Sync (Onyphe) and async (AsyncOnyphe) clients, both fully typed.
  • Covers APIv2: User, Search, Export, Summary, Simple, Simple Best, the Bulk variants, Discovery and Alert — plus a request() escape hatch for anything ONYPHE ships next.
  • pyonyphe CLI with table / JSON / NDJSON output.
  • Automatic pagination, retries with backoff, Retry-After support.

Install

The library on its own:

uv add pyonyphe

The pyonyphe command needs the cli extra, which pulls in Typer and Rich:

uv add 'pyonyphe[cli]'
uv run pyonyphe --help

Since 3.1.0 those two are no longer runtime dependencies, so importing the client no longer constrains rich in your own resolution.

Library

from pyonyphe import Onyphe

with Onyphe() as api:  # key read from ONYPHE_API_KEY
    page = api.search("category:datascan product:Nginx country:FR")
    print(page.total, "results")

    for hit in api.search_iter("domain:example.com", max_results=500):
        print(hit["ip"], hit.get("port"))

    for doc in api.export("category:vulnscan domain:example.com"):
        ...

Async, same surface:

import asyncio
from pyonyphe import AsyncOnyphe


async def main() -> None:
    async with AsyncOnyphe() as api:
        page = await api.search("protocol:rdp")
        async for hit in api.export("domain:example.com"):
            print(hit["ip"])


asyncio.run(main())

CLI

Needs uv add 'pyonyphe[cli]', or use the container image below.

export ONYPHE_API_KEY=...

pyonyphe user
pyonyphe search 'protocol:rdp country:FR' --size 20
pyonyphe search 'domain:example.com' --all --format ndjson -o results.ndjson
pyonyphe export 'category:vulnscan domain:example.com' -o export.ndjson
pyonyphe summary ip 8.8.8.8
pyonyphe simple whois 8.8.8.8 --best
pyonyphe resolve example.com
pyonyphe bulk simple datascan ips.txt -o out.ndjson
pyonyphe alert list

Configuration

The API key is resolved in this order:

  1. api_key= argument, or --api-key on the CLI
  2. the ONYPHE_API_KEY environment variable
  3. ~/.config/pyonyphe/config.toml
  4. ~/.onyphe.ini — the file used by the official ONYPHE CLI
# ~/.config/pyonyphe/config.toml
[onyphe]
api_key = "..."

Docker

The CLI is published as a container image on GHCR, built for linux/amd64 and linux/arm64:

docker run --rm -e ONYPHE_API_KEY ghcr.io/onyphe/pyonyphe:latest \
  search 'category:datascan product:Nginx country:FR' --size 5

Tags: latest and the semver ones (3, 3.0, 3.0.0) on each release, main and sha-<commit> on every push to the default branch.

The image runs as an unprivileged user and its working directory is /work, so mount there to read an asset list or write an export:

docker run --rm -e ONYPHE_API_KEY -v "$PWD:/work" ghcr.io/onyphe/pyonyphe:latest \
  bulk simple datascan ips.txt -o datascan.ndjson

MCP server

An optional MCP server exposes ONYPHE to an assistant:

uv add 'pyonyphe[mcp]'
ONYPHE_API_KEY=... pyonyphe-mcp

Four read-only tools — search, summary, resolve, user — with clamped page sizes and truncated fields, so a model cannot drain your credits or your context window. See docs/mcp.md.

Documentation

License

MIT — see LICENSE.

Metadata

Release files for pyonyphe 3.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pyonyphe 3.1.0
File Size Uploaded
pyonyphe-3.1.0.tar.gz 43.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pyonyphe 3.1.0
File Interpreter ABI Platform
pyonyphe-3.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 72.9 kB

Release files / pyonyphe-3.1.0.tar.gz

Download URL pyonyphe-3.1.0.tar.gz
Size 43.8 kB
Tags Source
SHA-256 checksum
How to use checksums
199fd077214f453a9d6bedd72764ecb0b1c2f9a10d75bdc86e90b0c42e54cda6
BLAKE2b-256 checksum
How to use checksums
11f5cf63bb7cd6ec4515486603d175ba59efe5033eab39aa78d8ba994ab3f9b8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 4, 2026.

Transparency log

Release files / pyonyphe-3.1.0-py3-none-any.whl

Download URL pyonyphe-3.1.0-py3-none-any.whl
Size 29.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d915708bea030aac4b58508136db3bcdc95f834b7508c114869e43e7607cb431
BLAKE2b-256 checksum
How to use checksums
3299960afa78b508d619feab5284b5f4d4f764737b4ff86d35f621070ccee0fc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 4, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

3.1.0 This release

2 release files

3.0.3

2 release files

3.0.2

2 release files

3.0.1

2 release files

3.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page