rootme-sdk
An unofficial, typed Python SDK for Root-Me: automated login, session reuse, profile and challenge exploration, and answer submission.
Installation
Clone the repository and install the package with pip (Python >= 3.13 required):
git clone https://github.com/Thomas97460/rootme-sdk.git
cd rootme-sdk
pip install .
Playwright is included. On first use, it automatically uses your local Chrome/Chromium or downloads a managed Chromium browser.
Quickstart
1. Login and read challenges
from rootme_sdk import RootMeClient
# Connect with credentials directly
with RootMeClient("your-username", "your-password") as client:
# Read a challenge statement
challenge = client.read_challenge(5)
print(f"Title: {challenge.title}")
print(f"Statement: {challenge.statement}")
# Browse challenges
for item in client.iter_challenges(lang="en", score=5):
print(f"[{item.id}] {item.title} ({item.score} pts)")
Alternatively, pass credentials via a JSON file:
{"login": "your-username", "password": "your-password"}
with RootMeClient(credentials_file=".secrets/credentials.json") as client:
user = client.get_user(12345)
print(f"User: {user.nom}, Score: {user.score}")
2. Submit an answer
from rootme_sdk import RootMeClient, SubmissionStatus
with RootMeClient("your-username", "your-password") as client:
result = client.submit_answer(5, "flag{your_flag_here}")
if result.status == SubmissionStatus.ACCEPTED:
print("Flag validated!")
elif result.status == SubmissionStatus.ALREADY_SOLVED:
print("Challenge already solved.")
elif result.status == SubmissionStatus.REJECTED:
print("Incorrect flag.")
elif result.status == SubmissionStatus.INDETERMINATE:
print(f"Ambiguous response: {result.message}")
3. Session reuse
Save the session to avoid re-authenticating on every run:
from rootme_sdk import RootMeClient, Session
with RootMeClient("your-username", "your-password") as client:
client.session.save(".secrets/session.json")
# Later: reload the saved session
with RootMeClient(session=Session.load(".secrets/session.json")) as client:
challenge = client.read_challenge(5)
Important Notes
- Graphical Display: Password login uses an isolated, headed Chromium browser to handle Root-Me's native login flow. A working graphical display is required (
DISPLAYon Linux). - Security: Never commit your passwords or
.secrets/directory. Saved sessions contain cookies and should be restricted to your user account. - Documentation:
- API Reference — Exhaustive methods and types documentation.
- Capabilities & Limits — Observed platform behaviors and known limitations.
- Contributing — Development workflow, quality gates, and testing guidelines.
- Security Policy — Vulnerability reporting and security practices.
Development
nix develop # or install uv + task manually
uv sync --locked
git config core.hooksPath .githooks
task ci
Metadata
Release files for rootme-sdk 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rootme_sdk-0.3.0.tar.gz | 130.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rootme_sdk-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 157.6 kB
Release files / rootme_sdk-0.3.0.tar.gz
| Download URL | rootme_sdk-0.3.0.tar.gz |
|---|---|
| Size | 130.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
45d524991d452b8416ff68ff22fab05adb586bbb9c1c35474a4199dfd8937979
|
|
BLAKE2b-256 checksum How to use checksums |
66b91b260ac1d0d9b98e98efaa7752569e4729f7b6a6b30ef3585504f91c7dc4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / rootme_sdk-0.3.0-py3-none-any.whl
| Download URL | rootme_sdk-0.3.0-py3-none-any.whl |
|---|---|
| Size | 27.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
24aae11f80771395a0c248832b695d7704a3e9e5ce7033da9d9c27fd20b4f28c
|
|
BLAKE2b-256 checksum How to use checksums |
a60300cd6635836afd181d13d8efcfb17f570728359f9f3a58cb4fd419a27713
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency log