Skip to main content

Thycotic SDK Python Package

A Python package to facilitate the connection to the Thycotic Secret Server

Prerequisites

Python 2.7* and Python 3.*

Downloading the package

You can download the package here or through the pip command:

pip install secret-server-sdk-client

Initial Setup

Import the SDK Client

from secret_server.sdk_client import SDK_Client

Instantiate the SDK_Client object

client = SDK_Client()

Configure the connection to your Secret Server instance by using the

configure(<sdk_path>, <url>, <rule>, <key>)

required parameters:

  • sdk_path - the path to the directory containing the SDK client
  • url - theURL to your Secret Server instance
  • rule - the name of an onboarding rule you have created
  • key - the onboarding key for that rule, if applicable
client.configure(os.environ.get('HOME') + '\\tss\\', 'https://myserver/SecretServer',
                 'OnboardingRule', 'oB0arD1ngKey')

Another way to configure the connection to your Secret Server instance:

client.config.SDK_CONFIG['path'] = os.environ.get('HOME') + '\\tss\\'
client.config.SDK_CONFIG['url'] = 'https://myserver/SecretServer'
client.config.SDK_CONFIG['rule'] = 'OnboardingRule'
client.config.SDK_CONFIG['key'] = 'oB0arD1ngKey'

Alternatively, you can also pull configuration from the current environment using the os.environ object:

client.configure_from_env()

The methods sets the config using the following variables

os.environ.get('SDK_CLIENT_PATH')
os.environ.get('SECRET_SERVER_URL')
os.environ.get('SDK_CLIENT_RULE')
os.environ.get('SDK_CLIENT_KEY')

Initialize the connection to the Secret Server:

client.commands.initialize()

Once the configuration and initialization are complete, they do not need to be run again. Encrypted configuration files created in the current directory will be used to establish the connection to Secret Server instance.

Usage

Fetch a secret by ID

# retrieve the full representation of a secret
secret = client.commands.get_secret(1)

# retrieve only the secret fields
secret = client.commands.get_secret(1, field = 'all')

# retrieve only a single secret field value by slug
password = client.commands.get_secret(1, field = 'password')

To remove the connection to Secret Server and delete all configuration:

client.commands.remove()

Cache Settings

By default, no secret values are stored on the local machine. As such, every call to

get_secret will result in a round-trip to the server. If the server is unavailable, the call will fail.

To change this behavior, set the cache strategy using the

set_cache(<cache_strategy>, <cache_age>) with the required parameters:

  • cache_strategy - the numeric representation of the cache strategy for the secrets
  • cache_age - cache age (the maximum time, in minutes, that a cached value will be usable)

Examples of setting cache:

# The default (never cache secrets). Cache age is optional for this choice
client.set_cache(0)

# Check the server first; if unavailable, return the last retrieved value, if present.
# Use this strategy for improved fault tolerance.
# Server Then Cache for 5 minutes
client.set_cache(1, 5)

# Check the cache first; if no value is present, retrieve it from the server.
# Use this strategy for improved performance.
# Cache Then Server for 10 minutes
client.set_cache(2, 10)

# Same as the above mode, but allow an expired cached value to be used if the server 
# is unavailable.
# Cache Then Server Fallback on Expired Cache for 15 minutes
client.set_cache(3, 15)

# Clear all cached values immediately
client.commands.clear_cache()

Authors

Paulo Dorado

License

This project is licensed under the MIT License - see the LICENSE.md file for details

Acknowledgments

Thycotic SDK

Metadata

Release files for secret-server-sdk-client 1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secret-server-sdk-client 1.0
File Size Uploaded
secret-server-sdk-client-1.0.tar.gz 4.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for secret-server-sdk-client 1.0
File Interpreter ABI Platform
secret_server_sdk_client-1.0-py2-none-any.whl Python 2 none any Details

Total release size: 9.6 kB

Release files / secret-server-sdk-client-1.0.tar.gz

Download URL secret-server-sdk-client-1.0.tar.gz
Size 4.3 kB
Tags Source
SHA-256 checksum
How to use checksums
06ea5d72c4dd517d5857f2e837c0f67a4f9abf1740611afa2c55d8b4f291aa12
BLAKE2b-256 checksum
How to use checksums
1821263f270691561f659ec8295efe40fd38a10970b05ad67251426bdfdd6566
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.11.0 pkginfo/1.4.2 requests/2.19.1 setuptools/40.2.0 requests-toolbelt/0.8.0 tqdm/4.25.0 CPython/2.7.14

Release files / secret_server_sdk_client-1.0-py2-none-any.whl

Download URL secret_server_sdk_client-1.0-py2-none-any.whl
Size 5.2 kB
Tags Python 2
SHA-256 checksum
How to use checksums
dd96786832989d96aec6930facef7be8097de7c17dcc5c10f82a4e38f1164834
BLAKE2b-256 checksum
How to use checksums
e5b2b533be0bafa507a2eb1c7f115a93288fadbcb47550b93d0efe6ec9c9a33f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.11.0 pkginfo/1.4.2 requests/2.19.1 setuptools/40.2.0 requests-toolbelt/0.8.0 tqdm/4.25.0 CPython/2.7.14

Release history Release notifications | RSS feed

This release

1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page