Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Swarmauri Logo

PyPI - Downloads Hits PyPI - Python Version PyPI - License PyPI - swarmauri_crypto_nacl_pkcs11 Discord

Swarmauri Crypto NaCl PKCS#11

swarmauri_crypto_nacl_pkcs11 is a hybrid crypto provider that combines PyNaCl for X25519 sealed-box operations with python-pkcs11 for AES key wrapping. The provider implements the CryptoBase contract and is discoverable via the swarmauri.cryptos entry-point as NaClPkcs11Crypto.

Supported operations

  • AES-GCM authenticated encryption via encrypt/decrypt using symmetric KeyRef material that is exactly 16, 24, or 32 bytes long.
  • AES Key Wrap (AES-KW) via wrap/unwrap against an HSM-protected key. The PKCS#11 session is resolved from the KeyRef.tags (module, slot_label, user_pin, label) or the environment variables PKCS11_MODULE, PKCS11_SLOT_LABEL, PKCS11_USER_PIN, and PKCS11_KEK_LABEL.
  • X25519 sealed boxes via seal/unseal and encrypt_for_many, enabling single or multi-recipient payload distribution. When additional authenticated data (AAD) is supplied the envelope is rebound with AES-GCM before delivery.

Installation

Choose the workflow that matches your project:

pip install swarmauri_crypto_nacl_pkcs11
poetry add swarmauri_crypto_nacl_pkcs11
uv add swarmauri_crypto_nacl_pkcs11

Usage

All cryptographic methods are asynchronous. The quick-start example below performs an AES-GCM round trip using a 256-bit symmetric key.

import asyncio

from swarmauri_crypto_nacl_pkcs11 import NaClPkcs11Crypto
from swarmauri_core.crypto.types import ExportPolicy, KeyRef, KeyType, KeyUse


async def main() -> None:
    crypto = NaClPkcs11Crypto()

    symmetric_key = KeyRef(
        kid="sym1",
        version=1,
        type=KeyType.SYMMETRIC,
        uses=(KeyUse.ENCRYPT, KeyUse.DECRYPT),
        export_policy=ExportPolicy.SECRET_WHEN_ALLOWED,
        material=b"\x00" * 32,
    )

    ciphertext = await crypto.encrypt(symmetric_key, b"hello")
    plaintext = await crypto.decrypt(symmetric_key, ciphertext)
    assert plaintext == b"hello"


asyncio.run(main())

Sealed box key exchange

seal and encrypt_for_many expect X25519 KeyRef instances. Provide the public key bytes via KeyRef.public for recipients and the private key bytes via KeyRef.material for unsealing. Each recipient receives an opaque sealed payload generated with nacl.public.SealedBox.

PKCS#11-backed key wrapping

wrap and unwrap require a key-encryption-key (KEK) stored in the configured PKCS#11 slot. Supply connection details through KeyRef.tags or environment variables as described above. The wrapped material is returned as a WrappedKey using the AES-KW algorithm.

Want to help?

If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.

Metadata

Release files for swarmauri_crypto_nacl_pkcs11 0.11.0.dev2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmauri_crypto_nacl_pkcs11 0.11.0.dev2
File Size Uploaded
swarmauri_crypto_nacl_pkcs11-0.11.0.dev2.tar.gz 9.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmauri_crypto_nacl_pkcs11 0.11.0.dev2
File Interpreter ABI Platform
swarmauri_crypto_nacl_pkcs11-0.11.0.dev2-py3-none-any.whl Python 3 none any Details

Total release size: 20.0 kB

Release files / swarmauri_crypto_nacl_pkcs11-0.11.0.dev2.tar.gz

Download URL swarmauri_crypto_nacl_pkcs11-0.11.0.dev2.tar.gz
Size 9.4 kB
Tags Source
SHA-256 checksum
How to use checksums
6a311e8192ebf3f6f92ff8b2feb0192a7551a8c0a9f74aaffaca428f50507cfe
BLAKE2b-256 checksum
How to use checksums
fb4e424626daf909b1484c698aa0f1b8f90e77947f17fe75c8273f1e1be8160d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmauri_crypto_nacl_pkcs11-0.11.0.dev2-py3-none-any.whl

Download URL swarmauri_crypto_nacl_pkcs11-0.11.0.dev2-py3-none-any.whl
Size 10.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
44a075f55656947496ff8e15c64da390598f5ed9f515a80a39a4b062c2bb4c11
BLAKE2b-256 checksum
How to use checksums
b38768b1969ab1b4048464d2fff7d7c82498b6b5021576e6f7849077b97b8ba6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page