secretspec (Python SDK)
Python bindings for SecretSpec, a declarative secrets
manager. This package is a thin client over a pyo3 extension that calls
secretspec::resolve_json directly: resolution (providers, chains, profiles,
generation, as_path) happens in the Rust core, so the SDK inherits every
provider with no Python-side logic.
from secretspec import SecretSpec
resolved = (
SecretSpec.builder()
.with_provider("keyring://")
.with_profile("production")
.with_reason("boot web app")
.load()
)
print(resolved.provider, resolved.profile)
db = resolved.secrets["DATABASE_URL"]
print(db.get) # the value, or the file path for as_path secrets
resolved.set_as_env() # export everything into os.environ
A missing required secret raises MissingRequiredError; any other failure
raises SecretSpecError (with a stable .kind).
Scopes (0.17+)
Use .with_scope("api") to resolve only a named [scopes.api] subset. Both
resolved.scope and report.scope return the selected scope:
resolved = SecretSpec.builder().with_scope("api").load()
Cleanup
as_path secrets are materialized to temp files that outlive the call. Use the
result as a context manager (with SecretSpec.builder()...load() as resolved:)
or call resolved.close() when done so the secret files do not accumulate.
Value-free report
report() returns the inventory/preflight view: per-secret status and
provenance, never a value. Unlike load(), it does not raise when a required
secret is missing — it appears as a SecretReport with status
"missing_required".
report = SecretSpec.builder().with_profile("production").report()
for s in report.secrets:
print(s.name, s.status, s.required)
Native library
The Rust resolver is statically linked into a compiled pyo3 extension
(secretspec._native, built from the secretspec-py-native crate) inside the
installed wheel, so there is nothing to locate at runtime. The prebuilt abi3
wheels are self-contained (pip install secretspec). From a source checkout
the extension is built on demand by the test harness via maturin develop,
which needs maturin and a Rust toolchain on PATH.
Metadata
Release files for secretspec 0.20.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| secretspec-0.20.0-cp39-abi3-win_amd64.whl | CPython 3.9 | abi3 | Windows x86-64 | Details |
| secretspec-0.20.0-cp39-abi3-manylinux_2_28_x86_64.whl | CPython 3.9 | abi3 | Linux glibc 2.28+ x86-64 | Details |
| secretspec-0.20.0-cp39-abi3-manylinux_2_28_aarch64.whl | CPython 3.9 | abi3 | Linux glibc 2.28+ ARM64 | Details |
| secretspec-0.20.0-cp39-abi3-macosx_11_0_arm64.whl | CPython 3.9 | abi3 | macOS 11.0+ ARM64 | Details |
Total release size: 68.1 MB
Release files / secretspec-0.20.0-cp39-abi3-win_amd64.whl
| Download URL | secretspec-0.20.0-cp39-abi3-win_amd64.whl |
|---|---|
| Size | 14.4 MB |
| Tags | CPython 3.9 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
1abdb2e3eeacb1a905ff961bad04d7c0e0ae4620bee58a2760bc9732cb9e2e54
|
|
BLAKE2b-256 checksum How to use checksums |
d3609fc0399a90cd2cc6443a4d8e90c7cd661c5c3f7a719581236ac32f943c5e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.
Transparency logRelease files / secretspec-0.20.0-cp39-abi3-manylinux_2_28_x86_64.whl
| Download URL | secretspec-0.20.0-cp39-abi3-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 19.0 MB |
| Tags | CPython 3.9 Linux glibc 2.28+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
78f0af58e2937e88bdc3af0a6b1b87cfa6a4ed46fc844ba3d34858af12164edc
|
|
BLAKE2b-256 checksum How to use checksums |
0c547a8812e0e2954d1162780e0cd01c95dfbbefe1881c3ce7b92500cfcf67c8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.
Transparency logRelease files / secretspec-0.20.0-cp39-abi3-manylinux_2_28_aarch64.whl
| Download URL | secretspec-0.20.0-cp39-abi3-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 18.8 MB |
| Tags | CPython 3.9 Linux glibc 2.28+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
326bf1b6e57b31b8b7f55e5d83e512f01ce6e57117050d8d9407965ede442991
|
|
BLAKE2b-256 checksum How to use checksums |
f2695e52afc313320271d8749caf123be07848a55a0bf4ef84885a8fe0c9c37a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.
Transparency logRelease files / secretspec-0.20.0-cp39-abi3-macosx_11_0_arm64.whl
| Download URL | secretspec-0.20.0-cp39-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 15.9 MB |
| Tags | CPython 3.9 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
faccb17eeb4fbedae3c2ad9ad629c5e7e98487cfdce09fd99cd8fdc31d7d2db6
|
|
BLAKE2b-256 checksum How to use checksums |
73bffb94287a898780939a579666a7bf58470160b3b6035e8c61b57eb416f544
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.
Transparency log