Skip to main content

soapbar

CI PyPI Python versions Downloads GitHub stars License Conformance suite OpenSSF Scorecard OpenSSF Best Practices

A SOAP library for Python — client, server, and WSDL handling.

soapbar implements SOAP 1.1 and 1.2 with all five binding styles, auto-generates WSDL from Python service classes, parses existing WSDL to drive a typed client, and integrates with any ASGI or WSGI framework via thin adapter classes. The XML parser is hardened against XXE attacks using lxml with resolve_entities=False.

Conformance — soapbar ships with an internal conformance suite of 116 tests across 11 spec-mapped classes (tests/audit/test_compliance.py) covering SOAP 1.1/1.2, WSDL 1.1, and WS-I Basic Profile 1.1 — including the WS-I BSP X.509 token profile — and the gaps found by earlier internal audits; all pass. This is a self-administered test suite, not an independent third-party audit.


Documentation

Full documentation lives at hitoshyamamoto.github.io/soapbar — quick start, client and server guides, WS-Security, MTOM, real-world service clients, architecture, and more.


Installation

pip install soapbar              # core + server + WSDL (lxml only)
pip install soapbar[client]      # + httpx for the HTTP client
pip install soapbar[security]    # + signxml + cryptography (XML Sig/Enc, mutual TLS)
pip install soapbar[all]         # everything (client + security)

Or with uv:

uv add soapbar
uv add "soapbar[client]"
uv add "soapbar[security]"
uv add "soapbar[all]"

Optional contrib extras install typed clients for real-world services: soapbar[vies], soapbar[witsml], soapbar[ana], soapbar[nfe] — see Real-world services.


Quick start — server

# app.py
from soapbar import SoapService, soap_operation, SoapApplication, AsgiSoapApp


class CalculatorService(SoapService):
    __service_name__ = "Calculator"
    __tns__ = "http://example.com/calculator"

    @soap_operation()
    def add(self, a: int, b: int) -> int:
        return a + b

    @soap_operation()
    def subtract(self, a: int, b: int) -> int:
        return a - b


soap_app = SoapApplication(service_url="http://localhost:8000")
soap_app.register(CalculatorService())

app = AsgiSoapApp(soap_app)
# Run: uvicorn app:app --port 8000
# WSDL: GET http://localhost:8000?wsdl

Mounting inside FastAPI/Flask, defining services, and binding styles are covered in the Quick start docs.


Quick start — client

Drive a typed client from an existing WSDL:

from soapbar import SoapClient

client = SoapClient(wsdl_url="http://localhost:8000?wsdl")
result = client.service.add(a=3, b=5)     # or client.call("add", a=3, b=5)

Async (await client.call_async(...)), WSDL-less SoapClient.manual(...), mutual TLS (HttpTransport(client_cert=..., ca_bundle=...), load_pkcs12(...)), and session cookies are covered in the Client docs.


Features

  • SOAP 1.1 and 1.2 with all 5 WSDL/SOAP binding style combinations; version auto-detected, fault codes auto-translated
  • SOAP server for any ASGI or WSGI framework (AsgiSoapApp / WsgiSoapApp), plus a sync and async WSDL-driven client
  • Auto-generates WSDL from service classes and parses existing WSDL — no config files needed
  • Hardened by default: XXE-safe lxml parser, SSRF guard on wsdl:import, message size and nesting depth limits, error scrubbing
  • Continuously assured: CodeQL static analysis and property-based tests (Hypothesis) on every pull request, coverage-guided fuzzing (Atheris) weekly; holds the OpenSSF Best Practices passing badge
  • WS-Security: UsernameToken (PasswordText/PasswordDigest), XML Signature (incl. Id-targeted SEFAZ NF-e profile), AES-256-GCM XML Encryption, WS-I BSP X.509 token profile
  • MTOM/XOP binary attachments on both client and server
  • Mutual TLS with PKCS#12 helper, session cookies, WS-Addressing 1.0, one-way MEP, opt-in WSDL schema validation
  • XSD type registry (27 built-in types), complex types, SOAP arrays, multi-reference encoding
  • Optional typed clients for real-world services: EU VIES, WITSML, SEFAZ NF-e, ANA (soapbar.contrib.*)
  • Interoperable with zeep and spyne (the spyne suite runs on Python ≤ 3.11 — upstream spyne does not import on 3.12+); fully type-annotated (PEP 561); Python 3.10 – 3.14

Links


Sponsoring

soapbar is maintained by a single developer. If your organization depends on it — or on SOAP integrations with services such as VIES, NF-e, WITSML, or ANA — consider sponsoring its maintenance:


License

Apache License 2.0 — see LICENSE and NOTICE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

soapbar-0.15.11.tar.gz (200.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

soapbar-0.15.11-py3-none-any.whl (114.8 kB view details)

Uploaded Python 3

File details

Details for the file soapbar-0.15.11.tar.gz.

File metadata

  • Download URL: soapbar-0.15.11.tar.gz
  • Upload date:
  • Size: 200.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for soapbar-0.15.11.tar.gz
Algorithm Hash digest
SHA256 3404c7402e0708279e0e27f0569715d65064b8fb72df38c7c227c1b7e0491024
MD5 a9d2b8ed94b9b4c0efbae912564507a1
BLAKE2b-256 e233d973c6bb77fb93e45d78bfbd7f7dc931495d81af285aeb850acf3cce8a8a

See more details on using hashes here.

Provenance

The following attestation bundles were made for soapbar-0.15.11.tar.gz:

Publisher: release.yml on hitoshyamamoto/soapbar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file soapbar-0.15.11-py3-none-any.whl.

File metadata

  • Download URL: soapbar-0.15.11-py3-none-any.whl
  • Upload date:
  • Size: 114.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for soapbar-0.15.11-py3-none-any.whl
Algorithm Hash digest
SHA256 3dbbe1e5207ef12568b5647dd4442604b1bfa57a485eae34e58db245df6d577a
MD5 efd6be07461ea310203c56286434726a
BLAKE2b-256 fc1b71db1049e961a3808f8e8cd56e1ecb303307bd0755e14d9fa98a31db4596

See more details on using hashes here.

Provenance

The following attestation bundles were made for soapbar-0.15.11-py3-none-any.whl:

Publisher: release.yml on hitoshyamamoto/soapbar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.17.11

2 files

0.17.10

2 files

0.17.9

2 files

0.17.8

2 files

0.17.7

2 files

0.17.6

2 files

0.17.5

2 files

0.17.4

2 files

0.17.3

2 files

0.17.2

2 files

0.17.1

2 files

0.17.0

2 files

0.16.1

2 files

0.16.0

2 files

0.15.13

2 files

0.15.12

2 files

This release

0.15.11 This release

2 files

0.15.10

2 files

0.15.9

2 files

0.15.8

2 files

0.15.7

2 files

0.15.6

2 files

0.15.5

2 files

0.15.4

2 files

0.15.3

2 files

0.15.2

2 files

0.15.1

2 files

0.15.0

2 files

0.14.1

2 files

0.14.0

2 files

0.13.0

2 files

0.12.1

2 files

0.12.0

2 files

0.11.1

2 files

0.11.0

2 files

0.10.0

2 files

0.9.0

2 files

0.8.1

2 files

0.8.0

2 files

0.7.0

2 files

0.6.4

2 files

0.6.3

2 files

0.6.2

2 files

0.6.1

2 files

0.6.0

2 files

0.5.5

2 files

0.5.4

2 files

0.5.3

2 files

0.5.2

2 files

0.5.1

2 files

0.5.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page