Skip to main content

soapbar

CI PyPI Python versions License Conformance suite OpenSSF Scorecard OpenSSF Best Practices

A SOAP library for Python — client, server, and WSDL handling.

soapbar implements SOAP 1.1 and 1.2 with all five binding styles, auto-generates WSDL from Python service classes, parses existing WSDL to drive a typed client, and integrates with any ASGI or WSGI framework via thin adapter classes. The XML parser is hardened against XXE attacks using lxml with resolve_entities=False.

Conformance — soapbar ships with an internal conformance suite of 116 tests across 11 spec-mapped classes (tests/audit/test_compliance.py) covering SOAP 1.1/1.2, WSDL 1.1, and WS-I Basic Profile 1.1. The suite encodes 46 checkpoints derived from F01–F09 original findings, G01–G11 gap findings, I01–I04 informational observations, and S10 (WS-I BSP X.509 token profile); all 46 pass. This is a self-administered test suite, not an independent third-party audit.


Documentation

Full documentation lives at hitoshyamamoto.github.io/soapbar — quick start, client and server guides, WS-Security, MTOM, real-world service clients, architecture, and more.


Installation

pip install soapbar              # core + server + WSDL (lxml only)
pip install soapbar[client]      # + httpx for the HTTP client
pip install soapbar[security]    # + signxml + cryptography (XML Sig/Enc, mutual TLS)
pip install soapbar[all]         # everything (client + security)

Or with uv:

uv add soapbar
uv add "soapbar[client]"
uv add "soapbar[security]"
uv add "soapbar[all]"

Optional contrib extras install typed clients for real-world services: soapbar[vies], soapbar[witsml], soapbar[ana], soapbar[nfe] — see Real-world services.


Quick start — server

# app.py
from soapbar import SoapService, soap_operation, SoapApplication, AsgiSoapApp


class CalculatorService(SoapService):
    __service_name__ = "Calculator"
    __tns__ = "http://example.com/calculator"

    @soap_operation()
    def add(self, a: int, b: int) -> int:
        return a + b

    @soap_operation()
    def subtract(self, a: int, b: int) -> int:
        return a - b


soap_app = SoapApplication(service_url="http://localhost:8000")
soap_app.register(CalculatorService())

app = AsgiSoapApp(soap_app)
# Run: uvicorn app:app --port 8000
# WSDL: GET http://localhost:8000?wsdl

Mounting inside FastAPI/Flask, defining services, binding styles, and the client are covered in the Quick start and Client docs.


Features

  • SOAP 1.1 and 1.2 with all 5 WSDL/SOAP binding style combinations; version auto-detected, fault codes auto-translated
  • SOAP server for any ASGI or WSGI framework (AsgiSoapApp / WsgiSoapApp), plus a sync and async WSDL-driven client
  • Auto-generates WSDL from service classes and parses existing WSDL — no config files needed
  • Hardened by default: XXE-safe lxml parser, SSRF guard on wsdl:import, message size and nesting depth limits, error scrubbing
  • Continuously assured: CodeQL static analysis, coverage-guided fuzzing (Atheris) and property-based tests (Hypothesis) in CI; holds the OpenSSF Best Practices passing badge
  • WS-Security: UsernameToken (PasswordText/PasswordDigest), XML Signature (incl. Id-targeted SEFAZ NF-e profile), AES-256-GCM XML Encryption, WS-I BSP X.509 token profile
  • MTOM/XOP binary attachments on both client and server
  • Mutual TLS with PKCS#12 helper, session cookies, WS-Addressing 1.0, one-way MEP, opt-in WSDL schema validation
  • XSD type registry (27 built-in types), complex types, SOAP arrays, multi-reference encoding
  • Optional typed clients for real-world services: EU VIES, WITSML, SEFAZ NF-e, ANA (soapbar.contrib.*)
  • Interoperable with zeep and spyne; fully type-annotated (PEP 561); Python 3.10 – 3.14

Links


Sponsoring

soapbar is maintained by a single developer. If your organization depends on it — or on SOAP integrations with services such as VIES, NF-e, CCEE, or ANA — consider sponsoring its maintenance:


License

Apache License 2.0 — see LICENSE and NOTICE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

soapbar-0.15.1.tar.gz (195.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

soapbar-0.15.1-py3-none-any.whl (110.4 kB view details)

Uploaded Python 3

File details

Details for the file soapbar-0.15.1.tar.gz.

File metadata

  • Download URL: soapbar-0.15.1.tar.gz
  • Upload date:
  • Size: 195.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for soapbar-0.15.1.tar.gz
Algorithm Hash digest
SHA256 3578be4018e2d831cc3f44fcd9f3cc4c93b17598557b60c2f9d80b261126a2bc
MD5 801d1b8301e22adddffe8bc5e089a78e
BLAKE2b-256 c29c81fcc46711a08c58b59cdc8348e2d2809489a85c4623d17611b0e31250b6

See more details on using hashes here.

Provenance

The following attestation bundles were made for soapbar-0.15.1.tar.gz:

Publisher: release.yml on hitoshyamamoto/soapbar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file soapbar-0.15.1-py3-none-any.whl.

File metadata

  • Download URL: soapbar-0.15.1-py3-none-any.whl
  • Upload date:
  • Size: 110.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for soapbar-0.15.1-py3-none-any.whl
Algorithm Hash digest
SHA256 bf1a6b114903de09d11482cd3e2b5b0eee95fe86b738bad9f233cba16c15ef6d
MD5 82f548bcb50a3361d8203a9768a4930d
BLAKE2b-256 c71c9fb06b287276eac11fad0c857573f7e380a38b29bc09989e7e6d1d6f3042

See more details on using hashes here.

Provenance

The following attestation bundles were made for soapbar-0.15.1-py3-none-any.whl:

Publisher: release.yml on hitoshyamamoto/soapbar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page