Skip to main content

rootme-sdk

An unofficial, typed Python SDK for Root-Me: automated login, session reuse, profile and challenge exploration, and answer submission.

CI pypi latest coverage mypy python license

Installation

Requires Python >= 3.13.

With pip

# Install
pip install rootme-sdk

# Upgrade
pip install -U rootme-sdk

With uv

# In a project
uv add rootme-sdk
uv lock --upgrade-package rootme-sdk

# In a virtual environment
uv pip install rootme-sdk
uv pip install -U rootme-sdk

Playwright is included. On first use, it automatically uses your local Chrome/Chromium or downloads a managed Chromium browser.

Quickstart

Copy a snippet, replace the credentials and run it. Login opens a Chromium window and fills the form automatically.

1. Find a challenge by its name and read its statement

from rootme_sdk import RootMeClient

with RootMeClient("your-username", "your-password") as client:
    summary = next(client.search_challenges(query="ELF x86 - 0 protection"))
    challenge = client.get_challenge(summary.id)
    print(challenge.id, challenge.title)  # 41 ELF x86 - 0 protection
    print(challenge.statement)

2. Download the challenge files

from rootme_sdk import RootMeClient

with RootMeClient("your-username", "your-password") as client:
    print(client.download_files(41))  # (PosixPath('ch1.zip'),)

3. Submit a flag

from rootme_sdk import RootMeClient

with RootMeClient("your-username", "your-password") as client:
    result = client.submit_flag(41, "your-flag")
    print(result.status, result.message)  # SubmissionStatus.ACCEPTED ...

4. Browse challenges with filters

from rootme_sdk import Category, Difficulty, RootMeClient

with RootMeClient("your-username", "your-password") as client:
    for item in client.search_challenges(
        category=Category.CRACKING, difficulty=Difficulty.EASY, limit=20
    ):
        print(f"[{item.id}] {item.title} ({item.score} pts)")

5. Reuse a session

from rootme_sdk import RootMeClient, Session

with RootMeClient("your-username", "your-password") as client:
    client.session.save("session.json")

with RootMeClient(session=Session.load("session.json")) as client:
    print(client.get_challenge(41).title)

Credentials can also come from a JSON file {"login": "...", "password": "..."}: RootMeClient(credentials_file="credentials.json").

Important Notes

  • Graphical Display: Password login uses an isolated, headed Chromium browser to handle Root-Me's native login flow. A working graphical display is required (DISPLAY on Linux).
  • Rate Limits: Root-Me throttles bursts with HTTP 429, sometimes for several minutes. The client waits at least 2 seconds between requests by default (min_request_interval=2); keep this pace across clients and processes sharing one network address. RateLimitedError.retry_after gives the server's waiting interval when one is sent, and submit_flag returns SubmissionStatus.BLOCKED instead of raising.
  • Network Family: Connections use the system's IPv4/IPv6 selection. To pin one family, pass a bound transport, e.g. RootMeClient(..., transport=httpx.HTTPTransport(local_address="0.0.0.0")) for IPv4 or local_address="::" for IPv6.
  • Security: Never commit your passwords or .secrets/ directory. Saved sessions contain cookies and should be restricted to your user account.
  • Documentation:

Development

nix develop         # or install uv + task manually
uv sync --locked
git config core.hooksPath .githooks
task ci

Metadata

Release files for rootme-sdk 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rootme-sdk 0.6.0
File Size Uploaded
rootme_sdk-0.6.0.tar.gz 150.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rootme-sdk 0.6.0
File Interpreter ABI Platform
rootme_sdk-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 189.9 kB

Release files / rootme_sdk-0.6.0.tar.gz

Download URL rootme_sdk-0.6.0.tar.gz
Size 150.4 kB
Tags Source
SHA-256 checksum
How to use checksums
877c538e645a7c4f769f17340316b540fd569074938f9902986a38f21d23b2a8
BLAKE2b-256 checksum
How to use checksums
b3992e042109f1f8ca9599b10daa4b4ad00532c8f41a91cca734a45b7b76bd37
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / rootme_sdk-0.6.0-py3-none-any.whl

Download URL rootme_sdk-0.6.0-py3-none-any.whl
Size 39.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
503dac626ab6657dfe804439802e9abd533ac00c2b18356964464d998ca40073
BLAKE2b-256 checksum
How to use checksums
a1d3ad5b9e66e350678dc3d7495f9116c881d22a68d9040e31120eb981010bd5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

0.7.1

2 release files

0.7.0

2 release files

This release

0.6.0 This release

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page