Skip to main content

pypitoken-cli

pypitoken-cli is a tool for adding restrictions to PyPI tokens, and a thin wrapper around the pypitoken library.

Motivation

PyPI currently lets you create tokens scoped for your entire account and for a single package, but not a token scoped for multiple packages. This is a problem if you publish a lot of packages yet still want to limit the impact of credential disclosure.

Usage

To create a token scoped for multiple packages (mypackage and mypackage-cli in this example), create a token scoped for your entire account (pypi-xxxxxxxx here), then run pypitoken-cli as follows:

$ pipx run pypitoken-cli -p mypackage mypackage-cli
Enter token: pypi-xxxxxxxx
New restrictions:
 - UserIDRestriction(user_id='01234567-89ab-cdef-0123-456789abcdef')
 - ProjectNamesRestriction(project_names=['mypackage', 'mypackage-cli'])
pypi-yyyyyyyy

It will create a new token (pypi-yyyyyyyy here) that can only be used to upload artifacts for the specified packages.

Limitations

Other token restrictions, such as "Not Before" and "Not After", aren't implemented yet.

License

0-clause BSD

Metadata

Release files for pypitoken-cli 1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for pypitoken-cli 1.1
File Interpreter ABI Platform
pypitoken_cli-1.1-py3-none-any.whl Python 3 none any Details

Release files / pypitoken_cli-1.1-py3-none-any.whl

Download URL pypitoken_cli-1.1-py3-none-any.whl
Size 3.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e2184329847a0fc96d02084424eec737b0ffae0656529e5222789af9ec0519d4
BLAKE2b-256 checksum
How to use checksums
1bf259696e02c0940269fcc409ad2b24a33517fa8a39a1ccd815121cd5695adb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

1.1 This release

1 release file

1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page