Skip to main content

soapbar

CI PyPI Python versions Downloads GitHub stars License Conformance suite OpenSSF Scorecard OpenSSF Best Practices

A SOAP library for Python — client, server, and WSDL handling.

soapbar implements SOAP 1.1 and 1.2 with all five binding styles, auto-generates WSDL from Python service classes, parses existing WSDL to drive a typed client, and integrates with any ASGI or WSGI framework via thin adapter classes. The XML parser is hardened against XXE attacks using lxml with resolve_entities=False.

Conformance — soapbar ships with an internal conformance suite of 116 tests across 11 spec-mapped classes (tests/audit/test_compliance.py) covering SOAP 1.1/1.2, WSDL 1.1, and WS-I Basic Profile 1.1 — including the WS-I BSP X.509 token profile — and the gaps found by earlier internal audits; all pass. This is a self-administered test suite, not an independent third-party audit.


Documentation

Full documentation lives at hitoshyamamoto.github.io/soapbar — quick start, client and server guides, WS-Security, MTOM, real-world service clients, architecture, and more.


Installation

pip install soapbar              # core + server + WSDL (lxml only)
pip install soapbar[client]      # + httpx for the HTTP client
pip install soapbar[security]    # + signxml + cryptography (XML Sig/Enc, mutual TLS)
pip install soapbar[all]         # everything (client + security)

Or with uv:

uv add soapbar
uv add "soapbar[client]"
uv add "soapbar[security]"
uv add "soapbar[all]"

The installed version is available as soapbar.__version__.

Optional contrib extras install typed clients for real-world services: soapbar[vies], soapbar[witsml], soapbar[ana], soapbar[nfe] — coverage varies by service, and Real-world services states each client's scope.


Quick start — server

# app.py
from soapbar import SoapService, soap_operation, SoapApplication, AsgiSoapApp


class CalculatorService(SoapService):
    __service_name__ = "Calculator"
    __tns__ = "http://example.com/calculator"

    @soap_operation()
    def add(self, a: int, b: int) -> int:
        return a + b

    @soap_operation()
    def subtract(self, a: int, b: int) -> int:
        return a - b


soap_app = SoapApplication(service_url="http://localhost:8000")
soap_app.register(CalculatorService())

app = AsgiSoapApp(soap_app)
# Run: uvicorn app:app --port 8000
# WSDL: GET http://localhost:8000?wsdl

Mounting inside FastAPI/Flask, defining services, and binding styles are covered in the Quick start docs.


Quick start — client

Drive a typed client from an existing WSDL:

from soapbar import SoapClient

client = SoapClient(wsdl_url="http://localhost:8000?wsdl")
result = client.service.add(a=3, b=5)     # or client.call("add", a=3, b=5)

Async (await client.call_async(...)), WSDL-less SoapClient.manual(...), mutual TLS (HttpTransport(client_cert=..., ca_bundle=...), load_pkcs12(...)), and session cookies are covered in the Client docs.


Features

  • SOAP 1.1 and 1.2 with all 5 WSDL/SOAP binding style combinations; version auto-detected, fault codes auto-translated
  • SOAP server for any ASGI or WSGI framework (AsgiSoapApp / WsgiSoapApp), plus a sync and async WSDL-driven client
  • Auto-generates WSDL from service classes and parses existing WSDL — no config files needed
  • Hardened by default: XXE-safe lxml parser, SSRF guard on wsdl:import, message size and nesting depth limits, error scrubbing
  • Continuously assured: CodeQL static analysis and property-based tests (Hypothesis) on every pull request, coverage-guided fuzzing (Atheris) weekly; holds the OpenSSF Best Practices passing badge
  • WS-Security: UsernameToken (PasswordText/PasswordDigest), XML Signature (incl. Id-targeted SEFAZ NF-e profile), AES-256-GCM XML Encryption, WS-I BSP X.509 token profile
  • MTOM/XOP binary attachments on both client and server
  • Mutual TLS with PKCS#12 helper, session cookies, WS-Addressing 1.0, one-way MEP, opt-in WSDL schema validation
  • XSD type registry (27 built-in types), complex types, SOAP arrays, multi-reference encoding
  • Optional typed clients for real-world services: EU VIES, WITSML, SEFAZ NF-e (status/protocol queries and <infNFe> signing — issuance is out of scope), ANA (soapbar.contrib.*)
  • Interoperable with zeep and spyne (the spyne suite runs on Python ≤ 3.11 — upstream spyne does not import on 3.12+); fully type-annotated (PEP 561); Python 3.10 – 3.14


Sponsoring

soapbar is maintained by a single developer. If your organization depends on it — or on SOAP integrations with services such as VIES, NF-e, WITSML, or ANA — consider sponsoring its maintenance:


License

Apache License 2.0 — see LICENSE and NOTICE.

Metadata

Release files for soapbar 0.20.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for soapbar 0.20.3
File Size Uploaded
soapbar-0.20.3.tar.gz 241.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for soapbar 0.20.3
File Interpreter ABI Platform
soapbar-0.20.3-py3-none-any.whl Python 3 none any Details

Total release size: 375.4 kB

Release files / soapbar-0.20.3.tar.gz

Download URL soapbar-0.20.3.tar.gz
Size 241.6 kB
Tags Source
SHA-256 checksum
How to use checksums
66836eb2041d2eb99de8045aee33b97d345a4e065a9aeb3a1d19f4750496710c
BLAKE2b-256 checksum
How to use checksums
5abaa85b64aec3aac518cfbc88e4d7cae6441a1bf368fcade9a4fb7103797c91
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / soapbar-0.20.3-py3-none-any.whl

Download URL soapbar-0.20.3-py3-none-any.whl
Size 133.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
10a4938667434f1464c7032b30dab5bd550092eae78e27d8995dc5839c7313f7
BLAKE2b-256 checksum
How to use checksums
77e7e94408d515d1605ce5c4f7acd050bac57a02c9130af1a92192d89cf1de99
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.20.3 This release

2 release files

0.17.4

2 release files

0.17.3

2 release files

0.17.2

2 release files

0.17.1

2 release files

0.17.0

2 release files

0.16.1

2 release files

0.16.0

2 release files

0.15.9

2 release files

0.15.8

2 release files

0.15.7

2 release files

0.15.6

2 release files

0.15.5

2 release files

0.15.4

2 release files

0.15.3

2 release files

0.15.2

2 release files

0.15.1

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.4

2 release files

0.6.3

2 release files

0.6.2

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.5

2 release files

0.5.4

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page