Skip to main content

secretspec (Python SDK)

Python bindings for SecretSpec, a declarative secrets manager. This package is a thin client over a pyo3 extension that calls secretspec::resolve_json directly: resolution (providers, chains, profiles, generation, as_path) happens in the Rust core, so the SDK inherits every provider with no Python-side logic.

from secretspec import SecretSpec

resolved = (
    SecretSpec.builder()
    .with_provider("keyring://")
    .with_profile("production")
    .with_reason("boot web app")
    .load()
)

print(resolved.provider, resolved.profile)
db = resolved.secrets["DATABASE_URL"]
print(db.get)              # the value, or the file path for as_path secrets
resolved.set_as_env()      # export everything into os.environ

A missing required secret raises MissingRequiredError; any other failure raises SecretSpecError (with a stable .kind).

Scopes (0.17+)

Use .with_scope("api") to resolve only a named [scopes.api] subset. Both resolved.scope and report.scope return the selected scope:

resolved = SecretSpec.builder().with_scope("api").load()

Cleanup

as_path secrets are materialized to temp files that outlive the call. Use the result as a context manager (with SecretSpec.builder()...load() as resolved:) or call resolved.close() when done so the secret files do not accumulate.

Value-free report

report() returns the inventory/preflight view: per-secret status and provenance, never a value. Unlike load(), it does not raise when a required secret is missing — it appears as a SecretReport with status "missing_required".

report = SecretSpec.builder().with_profile("production").report()
for s in report.secrets:
    print(s.name, s.status, s.required)

Native library

The Rust resolver is statically linked into a compiled pyo3 extension (secretspec._native, built from the secretspec-py-native crate) inside the installed wheel, so there is nothing to locate at runtime. The prebuilt abi3 wheels are self-contained (pip install secretspec). From a source checkout the extension is built on demand by the test harness via maturin develop, which needs maturin and a Rust toolchain on PATH.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

secretspec-0.19.1-cp39-abi3-win_amd64.whl (12.0 MB view details)

Uploaded CPython 3.9+Windows x86-64

secretspec-0.19.1-cp39-abi3-manylinux_2_28_x86_64.whl (16.3 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.28+ x86-64

secretspec-0.19.1-cp39-abi3-manylinux_2_28_aarch64.whl (16.2 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.28+ ARM64

secretspec-0.19.1-cp39-abi3-macosx_11_0_arm64.whl (13.5 MB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

File details

Details for the file secretspec-0.19.1-cp39-abi3-win_amd64.whl.

File metadata

  • Download URL: secretspec-0.19.1-cp39-abi3-win_amd64.whl
  • Upload date:
  • Size: 12.0 MB
  • Tags: CPython 3.9+, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for secretspec-0.19.1-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 b0bdd87335025a3a4584011809dd67e5cec9f012857b849818aec1ea69c3b0bc
MD5 8859f721bf861bafa6755cdff8324e84
BLAKE2b-256 5a63e63fdfa59a5c59835fcfdc2ac012d706d38a45e68923f7be2b827f64f57c

See more details on using hashes here.

Provenance

The following attestation bundles were made for secretspec-0.19.1-cp39-abi3-win_amd64.whl:

Publisher: python-wheels.yml on cachix/secretspec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file secretspec-0.19.1-cp39-abi3-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for secretspec-0.19.1-cp39-abi3-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 628ecfa558551e17aee1d11549d50b10aa972d6f7d4db0c3dfd9bd2b43f395bc
MD5 b687146f9407af6d491009e581ab4caf
BLAKE2b-256 0daa9bc73049872e47336690ae45d07f0996e2bdc9408b15a3a35492e3334951

See more details on using hashes here.

Provenance

The following attestation bundles were made for secretspec-0.19.1-cp39-abi3-manylinux_2_28_x86_64.whl:

Publisher: python-wheels.yml on cachix/secretspec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file secretspec-0.19.1-cp39-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for secretspec-0.19.1-cp39-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 1105385325cff72462792475e76e1b84772c352e8d1b1fa11c1d7f9403a08134
MD5 928a524d303db643f59e7b66efa30d8b
BLAKE2b-256 5f103a20bb7eb80e1d23dc1c1b7d1b1f8d7e9fd52fad95b3b8e9873225a6edbb

See more details on using hashes here.

Provenance

The following attestation bundles were made for secretspec-0.19.1-cp39-abi3-manylinux_2_28_aarch64.whl:

Publisher: python-wheels.yml on cachix/secretspec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file secretspec-0.19.1-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for secretspec-0.19.1-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 003f13b2c450d7d56859dbdb3d4cfb092ec28f751640927a25b91362d2d5e4bb
MD5 38c3c73e1725033b851317c2991b97e8
BLAKE2b-256 5c4c955fb52e874038e39fae6a7873643da8c8849d40f57e37c8aa8e9bed26c4

See more details on using hashes here.

Provenance

The following attestation bundles were made for secretspec-0.19.1-cp39-abi3-macosx_11_0_arm64.whl:

Publisher: python-wheels.yml on cachix/secretspec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page