Python SPNEGO Library
Library to handle SPNEGO (Negotiate, NTLM, Kerberos) and CredSSP authentication. Also includes a packet parser that can be used to decode raw NTLM/SPNEGO/Kerberos tokens into a human readable format.
Requirements
See How to Install for more details
- CPython 3.9+
- cryptography
- sspilib - Windows only
Optional Requirements
The following Python libraries can be installed to add extra features that do not come with the base package:
- python-gssapi and pykrb5 for Kerberos authentication on Linux
- ruamel.yaml for YAML output support on
pyspnego-parse
How to Install
To install pyspnego with all basic features, run
pip install pyspnego
Kerberos Authentication
While pyspnego supports Kerberos authentication on Linux, it isn't included by default due to its reliance on system packages to be present.
To install these packages, run the below
# Debian/Ubuntu
apt-get install gcc python3-dev libkrb5-dev
# Centos/RHEL/Fedora
dnf install gcc python-devel krb5-devel
# Arch Linux
pacman -S gcc krb5
Once installed you can install the Python packages with
pip install pyspnego[kerberos]
Kerberos also needs to be configured to talk to the domain but that is outside the scope of this page.
How to Use
See the examples section for examples on how to use the authentication side of the library.
Note: While server/acceptor authentication is available for all protocols it is highly recommended you have the system GSSAPI and NTLM system libraries present for acceptor authentication. Pyspnego NTLM acceptor authentication should work but it is not as thoroughly tested as the GSSAPI implementation.
CredSSP Authentication
Since version 0.2.0, pyspnego can be used for CredSSP authentication. While this isn't part of the SPNEGO/Negotiate
protocol it uses common features and code like ASN.1 structures and even Negotiate auth as part of the CredSSP process.
Both initiate and accept usages are supported when specifying protocol='credssp' but there are no guarantees the
acceptor is free of any bugs so use with caution.
Backlog
- Add support for anonymous authentication
- See if
pywinrmwants to use this
Metadata
Release files for pyspnego 0.12.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pyspnego-0.12.3.tar.gz | 226.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pyspnego-0.12.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 356.9 kB
Release files / pyspnego-0.12.3.tar.gz
| Download URL | pyspnego-0.12.3.tar.gz |
|---|---|
| Size | 226.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c4982c9f92e6aa5979c9d9a142a21339ff82ebcfbdb4e0649320cb050961a3cd
|
|
BLAKE2b-256 checksum How to use checksums |
fd8f30bb9568554899a6147bed657762a3c707e2d3dcaabf3492161cc9550bb4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / pyspnego-0.12.3-py3-none-any.whl
| Download URL | pyspnego-0.12.3-py3-none-any.whl |
|---|---|
| Size | 130.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
39b87aa00491e554cef05441bf2f7e52e85b09b5229ff62a89c35b59548794be
|
|
BLAKE2b-256 checksum How to use checksums |
93fd0e09467d5b8e229388c897126b4aed1e5fef2295a8661e2cad21fa9a8214
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log