Skip to main content

Note: redis-py-entraid 1.0.0 is the last version of redis-py that supports Python 3.9, as it has reached end of life. redis-py-entraid 1.1.0 supports Python 3.9+.

The redis-entraid Python package helps simplifying the authentication with Azure Managed Redis and Azure Cache for Redis using Microsoft Entra ID (formerly Azure Active Directory). It enables seamless integration with Azure's Redis services by fetching authentication tokens and managing the token renewal in the background. This package builds on top of redis-py and provides a structured way to authenticate by using a:

  • System-assigned managed identity
  • User-assigned managed identity
  • Service principal

You can learn more about managed identities in the Microsoft Entra ID documentation.

Preparation

Create a service principal in Azure

In this quick start guide, you will register an application and create a service principal in Azure. Then the following credentials are used to authenticate via Entra ID:

  • Tenant id
  • Client id
  • Client secret

Create cache and grant access

Create a Redis cache in Azure and grant your service principal access:

  1. Create a cache resource and wait until it was created successfully
  2. Navigate to Settings/Authentication
  3. If needed, enable Entra ID authentication
  4. Assign your previously created service principal to the cache

Further details are available in the AMR or ACR documentation.

Install the Entra ID package

You need to install the redis-py Entra ID package via the following command:

pip install redis-entraid

The package depends on redis-py.

Usage

Step 1 - Import the dependencies

After having installed the package, you can import its modules:

from redis import Redis
from redis_entraid.cred_provider import *

Step 2 - Create the credential provider via the factory method

Following factory methods are offered depends on authentication type you need:

create_from_managed_identity - Creates a credential provider based on a managed identity. Managed identities allow Azure services to authenticate without needing explicit credentials, as they are automatically assigned by Azure.

create_from_service_principal - Creates a credential provider using a service principal. A service principal is typically used when you want to authenticate as an application, rather than as a user, with Azure Active Directory.

create_from_default_azure_credential - Creates a credential provider from a Default Azure Credential. This method allows automatic selection of the appropriate credential mechanism based on the environment (e.g., environment variables, managed identities, service principal, interactive browser etc.).

Examples

Managed Identity

credential_provider = create_from_managed_identity(
    identity_type=ManagedIdentityType.SYSTEM_ASSIGNED,
    resource="https://redis.azure.com/"
)

Service principal

credential_provider = create_from_service_principal(
    CLIENT_ID, 
    CLIENT_SECRET, 
    TENANT_ID
)

Default Azure Credential

credential_provider = create_from_default_azure_credential(
    ("https://redis.azure.com/.default",),
)

More examples available in examples folder.

Step 3 - Provide optional token renewal configuration

The default configuration would be applied, but you're able to customise it.

credential_provider = create_from_service_principal(
    CLIENT_ID, 
    CLIENT_SECRET, 
    TENANT_ID,
    token_manager_config=TokenManagerConfig(
        expiration_refresh_ratio=0.9,
        lower_refresh_bound_millis=DEFAULT_LOWER_REFRESH_BOUND_MILLIS,
        token_request_execution_timeout_in_ms=DEFAULT_TOKEN_REQUEST_EXECUTION_TIMEOUT_IN_MS,
        retry_policy=RetryPolicy(
            max_attempts=5,
            delay_in_ms=50
        )
    )
)

You can test the credentials provider by obtaining a token. The following example demonstrates both, a synchronous and an asynchronous approach:

# Synchronous
credential_provider.get_credentials()

# Asynchronous
await credential_provider.get_credentials_async()

Step 4 - Connect to Redis

When using Entra ID, Azure enforces TLS on your Redis connection. Here is an example that shows how to test the connection in an insecure way:

client = Redis(host=HOST, port=PORT, ssl=True, ssl_cert_reqs=None, credential_provider=credential_provider)
print("The database size is: {}".format(client.dbsize()))

Metadata

Release files for redis-entraid 1.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for redis-entraid 1.2.1
File Size Uploaded
redis_entraid-1.2.1.tar.gz 9.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for redis-entraid 1.2.1
File Interpreter ABI Platform
redis_entraid-1.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 17.8 kB

Release files / redis_entraid-1.2.1.tar.gz

Download URL redis_entraid-1.2.1.tar.gz
Size 9.8 kB
Tags Source
SHA-256 checksum
How to use checksums
a7c479ce46e6edb35bce9dd804d1cad7be99a3330815cfe028a648b486a10b41
BLAKE2b-256 checksum
How to use checksums
a2a70ddaeb27b33c76709e05a12b3bbeefce893c82a3a830146608d6fe620000
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.12

Release files / redis_entraid-1.2.1-py3-none-any.whl

Download URL redis_entraid-1.2.1-py3-none-any.whl
Size 8.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9de7e4a716b156d966a2d6bb5b5ccd64a692db30ae21fe3987f57d233793d558
BLAKE2b-256 checksum
How to use checksums
cdca01b8607102de756b270d3f6befeee700bd82dace4303d6f47ce0f53c11b0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.12
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page