Skip to main content

soapbar

CI PyPI Python versions Downloads GitHub stars License Conformance suite OpenSSF Scorecard OpenSSF Best Practices

A SOAP library for Python — client, server, and WSDL handling.

soapbar implements SOAP 1.1 and 1.2 with all five binding styles, auto-generates WSDL from Python service classes, parses existing WSDL to drive a typed client, and integrates with any ASGI or WSGI framework via thin adapter classes. The XML parser is hardened against XXE attacks using lxml with resolve_entities=False.

Conformance — soapbar ships with an internal conformance suite of 116 tests across 11 spec-mapped classes (tests/audit/test_compliance.py) covering SOAP 1.1/1.2, WSDL 1.1, and WS-I Basic Profile 1.1 — including the WS-I BSP X.509 token profile — and the gaps found by earlier internal audits; all pass. This is a self-administered test suite, not an independent third-party audit.


Documentation

Full documentation lives at hitoshyamamoto.github.io/soapbar — quick start, client and server guides, WS-Security, MTOM, real-world service clients, architecture, and more.


Installation

pip install soapbar              # core + server + WSDL (lxml only)
pip install soapbar[client]      # + httpx for the HTTP client
pip install soapbar[security]    # + signxml + cryptography (XML Sig/Enc, mutual TLS)
pip install soapbar[all]         # everything (client + security)

Or with uv:

uv add soapbar
uv add "soapbar[client]"
uv add "soapbar[security]"
uv add "soapbar[all]"

Optional contrib extras install typed clients for real-world services: soapbar[vies], soapbar[witsml], soapbar[ana], soapbar[nfe] — see Real-world services.


Quick start — server

# app.py
from soapbar import SoapService, soap_operation, SoapApplication, AsgiSoapApp


class CalculatorService(SoapService):
    __service_name__ = "Calculator"
    __tns__ = "http://example.com/calculator"

    @soap_operation()
    def add(self, a: int, b: int) -> int:
        return a + b

    @soap_operation()
    def subtract(self, a: int, b: int) -> int:
        return a - b


soap_app = SoapApplication(service_url="http://localhost:8000")
soap_app.register(CalculatorService())

app = AsgiSoapApp(soap_app)
# Run: uvicorn app:app --port 8000
# WSDL: GET http://localhost:8000?wsdl

Mounting inside FastAPI/Flask, defining services, and binding styles are covered in the Quick start docs.


Quick start — client

Drive a typed client from an existing WSDL:

from soapbar import SoapClient

client = SoapClient(wsdl_url="http://localhost:8000?wsdl")
result = client.service.add(a=3, b=5)     # or client.call("add", a=3, b=5)

Async (await client.call_async(...)), WSDL-less SoapClient.manual(...), mutual TLS (HttpTransport(client_cert=..., ca_bundle=...), load_pkcs12(...)), and session cookies are covered in the Client docs.


Features

  • SOAP 1.1 and 1.2 with all 5 WSDL/SOAP binding style combinations; version auto-detected, fault codes auto-translated
  • SOAP server for any ASGI or WSGI framework (AsgiSoapApp / WsgiSoapApp), plus a sync and async WSDL-driven client
  • Auto-generates WSDL from service classes and parses existing WSDL — no config files needed
  • Hardened by default: XXE-safe lxml parser, SSRF guard on wsdl:import, message size and nesting depth limits, error scrubbing
  • Continuously assured: CodeQL static analysis and property-based tests (Hypothesis) on every pull request, coverage-guided fuzzing (Atheris) weekly; holds the OpenSSF Best Practices passing badge
  • WS-Security: UsernameToken (PasswordText/PasswordDigest), XML Signature (incl. Id-targeted SEFAZ NF-e profile), AES-256-GCM XML Encryption, WS-I BSP X.509 token profile
  • MTOM/XOP binary attachments on both client and server
  • Mutual TLS with PKCS#12 helper, session cookies, WS-Addressing 1.0, one-way MEP, opt-in WSDL schema validation
  • XSD type registry (27 built-in types), complex types, SOAP arrays, multi-reference encoding
  • Optional typed clients for real-world services: EU VIES, WITSML, SEFAZ NF-e, ANA (soapbar.contrib.*)
  • Interoperable with zeep and spyne (the spyne suite runs on Python ≤ 3.11 — upstream spyne does not import on 3.12+); fully type-annotated (PEP 561); Python 3.10 – 3.14

Links


Sponsoring

soapbar is maintained by a single developer. If your organization depends on it — or on SOAP integrations with services such as VIES, NF-e, WITSML, or ANA — consider sponsoring its maintenance:


License

Apache License 2.0 — see LICENSE and NOTICE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

soapbar-0.16.1.tar.gz (210.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

soapbar-0.16.1-py3-none-any.whl (120.6 kB view details)

Uploaded Python 3

File details

Details for the file soapbar-0.16.1.tar.gz.

File metadata

  • Download URL: soapbar-0.16.1.tar.gz
  • Upload date:
  • Size: 210.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for soapbar-0.16.1.tar.gz
Algorithm Hash digest
SHA256 be683d600fe0a41543a9e5ea80548797b82663a567296907fa67acc3ac8ec43d
MD5 7314155cb2299f1b501c06294b21c3d1
BLAKE2b-256 becd73bfa690954bb9b838060e542fbc354daa32fa7b23551a5cfedfd6edc839

See more details on using hashes here.

Provenance

The following attestation bundles were made for soapbar-0.16.1.tar.gz:

Publisher: release.yml on hitoshyamamoto/soapbar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file soapbar-0.16.1-py3-none-any.whl.

File metadata

  • Download URL: soapbar-0.16.1-py3-none-any.whl
  • Upload date:
  • Size: 120.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for soapbar-0.16.1-py3-none-any.whl
Algorithm Hash digest
SHA256 7ae3f09e6d403edd47c20fd3970aab0582368b72fc0cf71dd9424ba924e67515
MD5 1ab490a72661956a2b42aea08ef6063e
BLAKE2b-256 726506857ed112f62f3fea02182fb19d99c4db0a0a50cbfec08e64daa456e02a

See more details on using hashes here.

Provenance

The following attestation bundles were made for soapbar-0.16.1-py3-none-any.whl:

Publisher: release.yml on hitoshyamamoto/soapbar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.17.11

2 files

0.17.10

2 files

0.17.9

2 files

0.17.8

2 files

0.17.7

2 files

0.17.6

2 files

0.17.5

2 files

0.17.4

2 files

0.17.3

2 files

0.17.2

2 files

0.17.1

2 files

0.17.0

2 files

This release

0.16.1 This release

2 files

0.16.0

2 files

0.15.13

2 files

0.15.12

2 files

0.15.11

2 files

0.15.10

2 files

0.15.9

2 files

0.15.8

2 files

0.15.7

2 files

0.15.6

2 files

0.15.5

2 files

0.15.4

2 files

0.15.3

2 files

0.15.2

2 files

0.15.1

2 files

0.15.0

2 files

0.14.1

2 files

0.14.0

2 files

0.13.0

2 files

0.12.1

2 files

0.12.0

2 files

0.11.1

2 files

0.11.0

2 files

0.10.0

2 files

0.9.0

2 files

0.8.1

2 files

0.8.0

2 files

0.7.0

2 files

0.6.4

2 files

0.6.3

2 files

0.6.2

2 files

0.6.1

2 files

0.6.0

2 files

0.5.5

2 files

0.5.4

2 files

0.5.3

2 files

0.5.2

2 files

0.5.1

2 files

0.5.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page