rootme-sdk
An unofficial, typed Python SDK for Root-Me: automated login, session reuse, profile and challenge exploration, and answer submission.
Installation
Requires Python >= 3.13.
With pip
# Install
pip install rootme-sdk
# Upgrade
pip install -U rootme-sdk
With uv
# In a project
uv add rootme-sdk
uv lock --upgrade-package rootme-sdk
# In a virtual environment
uv pip install rootme-sdk
uv pip install -U rootme-sdk
Playwright is included. On first use, it automatically uses your local Chrome/Chromium or downloads a managed Chromium browser.
Quickstart
1. Search challenges and get full details
from rootme_sdk import Category, Difficulty, RootMeClient
with RootMeClient("your-username", "your-password") as client:
# Search challenges by category, difficulty or title
for item in client.search_challenges(
category=Category.WEB_SERVER, difficulty=Difficulty.VERY_EASY
):
print(f"[{item.id}] {item.title} ({item.score} pts)")
# Get complete challenge details, statement and resources
challenge = client.get_challenge(5)
print(f"Title: {challenge.title}")
print(f"Statement: {challenge.statement}")
for resource in challenge.resources:
print(f"{resource.label}: {resource.url}")
# Read account profile
profile = client.get_profile()
print(f"User: {profile.username}, Score: {profile.score}, Rank: {profile.rank}")
Alternatively, pass credentials via a JSON file:
{"login": "your-username", "password": "your-password"}
with RootMeClient(credentials_file=".secrets/credentials.json") as client:
profile = client.get_profile()
print(f"User: {profile.username}, Score: {profile.score}")
2. Submit a flag
from rootme_sdk import RootMeClient, SubmissionStatus
with RootMeClient("your-username", "your-password") as client:
result = client.submit_flag(5, "flag{your_flag_here}")
if result.status == SubmissionStatus.ACCEPTED:
print("Flag validated!")
elif result.status == SubmissionStatus.ALREADY_SOLVED:
print("Challenge already solved.")
elif result.status == SubmissionStatus.REJECTED:
print("Incorrect flag.")
3. Session reuse
Save the session to avoid re-authenticating on every run:
from rootme_sdk import RootMeClient, Session
with RootMeClient("your-username", "your-password") as client:
client.session.save(".secrets/session.json")
# Later: reload the saved session
with RootMeClient(session=Session.load(".secrets/session.json")) as client:
challenge = client.read_challenge(5)
Important Notes
- Graphical Display: Password login uses an isolated, headed Chromium browser to handle Root-Me's native login flow. A working graphical display is required (
DISPLAYon Linux). - Security: Never commit your passwords or
.secrets/directory. Saved sessions contain cookies and should be restricted to your user account. - Documentation:
- API Reference — Exhaustive methods and types documentation.
- Capabilities & Limits — Observed platform behaviors and known limitations.
- Contributing — Development workflow, quality gates, and testing guidelines.
- Security Policy — Vulnerability reporting and security practices.
Development
nix develop # or install uv + task manually
uv sync --locked
git config core.hooksPath .githooks
task ci
Metadata
Release files for rootme-sdk 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rootme_sdk-0.4.0.tar.gz | 145.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rootme_sdk-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 182.9 kB
Release files / rootme_sdk-0.4.0.tar.gz
| Download URL | rootme_sdk-0.4.0.tar.gz |
|---|---|
| Size | 145.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
02a2f5153b1f2c718489075572e74c9b9edd88a20a888d902abc4ce14153e99a
|
|
BLAKE2b-256 checksum How to use checksums |
673ae74e8745c5635fbce9e27a4a5e726ba56943cbc72b123a6f4117b0e1180e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency logRelease files / rootme_sdk-0.4.0-py3-none-any.whl
| Download URL | rootme_sdk-0.4.0-py3-none-any.whl |
|---|---|
| Size | 37.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
42ff7b213bb58d0d63bca3994fa9551adcab9b1c8451627631d9419ba01ec941
|
|
BLAKE2b-256 checksum How to use checksums |
c09633b149cb9de4e6afc5c38f8798219241192b77e5695c3fbf6d483a76cfa3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency log