Skip to main content

rootme-sdk

An unofficial, typed Python SDK for Root-Me: automated login, session reuse, profile and challenge exploration, and answer submission.

CI pypi latest coverage mypy python license

Installation

Requires Python >= 3.13.

With pip

# Install
pip install rootme-sdk

# Upgrade
pip install -U rootme-sdk

With uv

# In a project
uv add rootme-sdk
uv lock --upgrade-package rootme-sdk

# In a virtual environment
uv pip install rootme-sdk
uv pip install -U rootme-sdk

Playwright is included. On first use, it automatically uses your local Chrome/Chromium or downloads a managed Chromium browser.

Quickstart

Copy a snippet, replace the credentials and run it. Login opens a Chromium window and fills the form automatically.

1. Find a challenge by its name and read its statement

from rootme_sdk import RootMeClient

with RootMeClient("your-username", "your-password") as client:
    summary = next(client.search_challenges(query="ELF x86 - 0 protection"))
    challenge = client.get_challenge(summary.id)
    print(challenge.id, challenge.title)  # 41 ELF x86 - 0 protection
    print(challenge.statement)

2. Download the challenge files

from rootme_sdk import RootMeClient

with RootMeClient("your-username", "your-password") as client:
    print(client.download_files(41))  # (PosixPath('ch1.zip'),)

3. Submit a flag

from rootme_sdk import RootMeClient

with RootMeClient("your-username", "your-password") as client:
    result = client.submit_flag(41, "your-flag")
    print(result.status, result.message)  # SubmissionStatus.ACCEPTED ...

4. Browse challenges with filters

from rootme_sdk import Category, Difficulty, RootMeClient

with RootMeClient("your-username", "your-password") as client:
    for item in client.search_challenges(
        category=Category.CRACKING, difficulty=Difficulty.EASY, limit=20
    ):
        print(f"[{item.id}] {item.title} ({item.score} pts)")

5. Reuse a session

from rootme_sdk import RootMeClient

with RootMeClient(
    credentials_file=".secrets/credentials.json", session_file=".secrets/session.json"
) as client:
    print(client.get_challenge(41).title)

session_file reuses the saved session while Root-Me still accepts it and logs in with the credentials only when the file is missing, invalid, expired or rejected. Rate limits and network failures are raised instead of triggering a new login. The file is updated after login and on close, and logout() deletes it. Prefer this over logging in on every run.

Credentials can also come from a JSON file {"login": "...", "password": "..."}: RootMeClient(credentials_file="credentials.json").

Important Notes

  • Graphical Display: Password login uses an isolated, headed Chromium browser to handle Root-Me's native login flow. A working graphical display is required (DISPLAY on Linux).
  • Rate Limits: Root-Me throttles bursts with HTTP 429, sometimes for several minutes. The client waits at least 2 seconds between requests by default (min_request_interval=2); keep this pace across clients and processes sharing one network address. RateLimitedError.retry_after gives the server's waiting interval when one is sent, and submit_flag returns SubmissionStatus.BLOCKED instead of raising. Wait at least that long before calling again; do not wrap SDK calls in automatic retry loops, and never resubmit an answer automatically.
  • Network Family: Connections use the system's IPv4/IPv6 selection. To pin one family, pass a bound transport, e.g. RootMeClient(..., transport=httpx.HTTPTransport(local_address="0.0.0.0")) for IPv4 or local_address="::" for IPv6.
  • Security: Never commit your passwords or .secrets/ directory. Saved sessions contain cookies and should be restricted to your user account.
  • Documentation:

Development

nix develop         # or install uv + task manually
uv sync --locked
git config core.hooksPath .githooks
task ci

Metadata

Release files for rootme-sdk 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rootme-sdk 0.7.0
File Size Uploaded
rootme_sdk-0.7.0.tar.gz 152.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rootme-sdk 0.7.0
File Interpreter ABI Platform
rootme_sdk-0.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 192.3 kB

Release files / rootme_sdk-0.7.0.tar.gz

Download URL rootme_sdk-0.7.0.tar.gz
Size 152.2 kB
Tags Source
SHA-256 checksum
How to use checksums
eda658d7d185d9e635eaeb7ea4ce954c3b183a9ea4b6e5efb729b32424d46957
BLAKE2b-256 checksum
How to use checksums
7410999f1831ee0aafa00c8635f928df298f9ac3d25f1b9ed1ae6710f390a9ef
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / rootme_sdk-0.7.0-py3-none-any.whl

Download URL rootme_sdk-0.7.0-py3-none-any.whl
Size 40.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2c6e68d489b9cbda8039c00e198cd4cf6807289d26c79156f0dc4f84c66e254d
BLAKE2b-256 checksum
How to use checksums
d389411d8679879d2c4b6dd6cd7e3a4c72bcc453c0d6ec3c7c7482d0ac964844
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

0.7.1

2 release files

This release

0.7.0 This release

2 release files

0.6.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page