PyPIToken is an open-source Python library for generating and manipulating PyPI tokens.
PyPI tokens are very powerful, as that they are based on Macaroons. They allow the bearer to add additional restrictions to an existing token. For example, given a PyPI token that can upload releases for any project of its owner, you can generate a token that will only allow some projects, or even a single one.
Here’s an example:
$ pip install pypitoken
import pypitoken
token = pypitoken.Token.load("pypi-foobartoken")
print(token.restrictions)
# [ProjectIDsRestriction(project_ids=["00000000-0000-0000-0000-000000000000"])]
token.restrict(project_names=["requests"])
print(token.restrictions)
# [
# ProjectIDsRestriction(project_ids=["00000000-0000-0000-0000-000000000000"]),
# ProjectNamesRestriction(project_names=["requests"]),
# ]
token.dump()
# pypi-newfoobartoken
This token we’ve created above will be restricted to uploading releases of requests. Of course, your PyPI user will still need to have upload permissions on requests for this to happen.
The aim of this library is to provide a simple toolbelt for manipulating PyPI tokens. Ideally, someday, PyPI (Warehouse) itself may generate their tokens using this library too. This should make it easier to iterate on new kinds of restrictions for PyPI tokens, such as those discussed in the original implementation issue.
A discussion for integrating this library to the Warehouse environment is ongoing:
In the Python Packaging discussions for putting the project under the PyPA umbrella
In the Warehouse tracker for replacing the current macaroon implementation with this lib
Where to go from here
The complete docs is probably the best place to learn about the project.
If you encounter a bug, or want to get in touch, you’re always welcome to open a ticket.
Metadata
Release files for pypitoken 7.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pypitoken-7.1.1.tar.gz | 198.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pypitoken-7.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 211.3 kB
Release files / pypitoken-7.1.1.tar.gz
| Download URL | pypitoken-7.1.1.tar.gz |
|---|---|
| Size | 198.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2e91822471f2de99183f6a881ddb173372f2a2f8e7c55b574235aee1b0417e42
|
|
BLAKE2b-256 checksum How to use checksums |
21d61b52d35f6aab68d75a0b38211bd6ea6eca0aceefb3e95cd6ca30be03adf9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.12.9
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 11, 2025.
Transparency logRelease files / pypitoken-7.1.1-py3-none-any.whl
| Download URL | pypitoken-7.1.1-py3-none-any.whl |
|---|---|
| Size | 12.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
013e1b273168b37c46d5fbdf572f0d7a454a52fae492d0d7a5f2da600f75bca7
|
|
BLAKE2b-256 checksum How to use checksums |
43ddfdcf4e9bfe80a8ebd9f3b47cd77b7722e2933e6923e32ddf1da2e321d464
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.12.9
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 11, 2025.
Transparency log