Skip to main content

secretspec (Python SDK)

Python bindings for SecretSpec, a declarative secrets manager. This package is a thin client over a pyo3 extension that calls secretspec::resolve_json directly: resolution (providers, chains, profiles, generation, as_path) happens in the Rust core, so the SDK inherits every provider with no Python-side logic.

from secretspec import SecretSpec

resolved = (
    SecretSpec.builder()
    .with_provider("keyring://")
    .with_profile("production")
    .with_reason("boot web app")
    .load()
)

print(resolved.provider, resolved.profile)
db = resolved.secrets["DATABASE_URL"]
print(db.get)              # the value, or the file path for as_path secrets
resolved.set_as_env()      # export everything into os.environ

A missing required secret raises MissingRequiredError; any other failure raises SecretSpecError (with a stable .kind).

Scopes (0.17+)

Use .with_scope("api") to resolve only a named [scopes.api] subset. Both resolved.scope and report.scope return the selected scope:

resolved = SecretSpec.builder().with_scope("api").load()

Cleanup

as_path secrets are materialized to temp files that outlive the call. Use the result as a context manager (with SecretSpec.builder()...load() as resolved:) or call resolved.close() when done so the secret files do not accumulate.

Value-free report

report() returns the inventory/preflight view: per-secret status and provenance, never a value. Unlike load(), it does not raise when a required secret is missing — it appears as a SecretReport with status "missing_required".

report = SecretSpec.builder().with_profile("production").report()
for s in report.secrets:
    print(s.name, s.status, s.required)

Native library

The Rust resolver is statically linked into a compiled pyo3 extension (secretspec._native, built from the secretspec-py-native crate) inside the installed wheel, so there is nothing to locate at runtime. The prebuilt abi3 wheels are self-contained (pip install secretspec). From a source checkout the extension is built on demand by the test harness via maturin develop, which needs maturin and a Rust toolchain on PATH.

Metadata

Release files for secretspec 0.21.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for secretspec 0.21.0
File
secretspec-0.21.0-cp39-abi3-win_amd64.whl CPython 3.9 abi3 Windows x86-64 Details
secretspec-0.21.0-cp39-abi3-manylinux_2_28_x86_64.whl CPython 3.9 abi3 Linux glibc 2.28+ x86-64 Details
secretspec-0.21.0-cp39-abi3-manylinux_2_28_aarch64.whl CPython 3.9 abi3 Linux glibc 2.28+ ARM64 Details
secretspec-0.21.0-cp39-abi3-macosx_11_0_arm64.whl CPython 3.9 abi3 macOS 11.0+ ARM64 Details

Total release size: 74.9 MB

Release files / secretspec-0.21.0-cp39-abi3-win_amd64.whl

Download URL secretspec-0.21.0-cp39-abi3-win_amd64.whl
Size 15.9 MB
Tags CPython 3.9 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
b128526fb60b9105e3a7494a54445eef21fff6e3b01dccc44dd9ff9d56b1ccc8
BLAKE2b-256 checksum
How to use checksums
0a65b1da9c82eabc5afa7fe8d64de53ea732e0bea19ff5d315da7c8d87c8b097
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release files / secretspec-0.21.0-cp39-abi3-manylinux_2_28_x86_64.whl

Download URL secretspec-0.21.0-cp39-abi3-manylinux_2_28_x86_64.whl
Size 20.9 MB
Tags CPython 3.9 Linux glibc 2.28+ x86-64 abi3
SHA-256 checksum
How to use checksums
be85adfdf827bdcc9f7ccc02b17f7cde5651adb2e77bceac20a981ff8e3cceef
BLAKE2b-256 checksum
How to use checksums
9b2bb896546c101cf8194fa7b1e2576e54ef8add1859b906512b891ae7e053e4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release files / secretspec-0.21.0-cp39-abi3-manylinux_2_28_aarch64.whl

Download URL secretspec-0.21.0-cp39-abi3-manylinux_2_28_aarch64.whl
Size 20.5 MB
Tags CPython 3.9 Linux glibc 2.28+ ARM64 abi3
SHA-256 checksum
How to use checksums
05967f50b9d5a4767b99c11b81356a76835218b7894b9788607ddee69d97bf8c
BLAKE2b-256 checksum
How to use checksums
b5019e91826b11a5dbbea9e1552dd473d61b2f59d2c831700239d69bf7f4db8d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release files / secretspec-0.21.0-cp39-abi3-macosx_11_0_arm64.whl

Download URL secretspec-0.21.0-cp39-abi3-macosx_11_0_arm64.whl
Size 17.5 MB
Tags CPython 3.9 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
5fff17932845b04f55c3fc7f840e59dceafc47175785e6160360f778f426e336
BLAKE2b-256 checksum
How to use checksums
5fec5d9ad11256efb1a084b89d9e68c3bcfafae0a9f85b510fd2d606f906660e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release history Release notifications | RSS feed

0.21.1

4 release files

This release

0.21.0 This release

4 release files

0.20.0

4 release files

0.19.1

4 release files

0.19.0

4 release files

0.17.0

4 release files

0.16.0

3 release files

0.15.0

3 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page