Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Swarmauri Logo

PyPI - Downloads Hits PyPI - Python Version PyPI - License PyPI - swarmauri_keyprovider_ssh Discord

Swarmauri SSH Key Provider

An asynchronous KeyProviderBase implementation that keeps SSH key material in memory and bridges it to Swarmauri's signing abstractions.

Features

  • Generate new Ed25519, RSA-PSS (SHA-256), or ECDSA P-256 key pairs on demand.
  • Import existing private keys (PEM) or public keys (OpenSSH) while respecting each key's ExportPolicy.
  • Rotate keys, enumerate versions, and optionally destroy specific versions or entire key identifiers.
  • Export public keys as RFC 7517-compliant JWKs/JWKS with OpenSSH fingerprints embedded in the tags metadata.
  • Produce random bytes and derive keying material using the HKDF construction (RFC 5869).

Installation

Choose the tool that matches your workflow:

# pip
pip install swarmauri_keyprovider_ssh

# Poetry
poetry add swarmauri_keyprovider_ssh

# uv
uv add swarmauri_keyprovider_ssh

Usage

The provider exposes an asynchronous interface for creating and managing SSH-based signing keys. The snippet below creates a new Ed25519 key and exports its public component as a JSON Web Key (JWK):

import asyncio
from swarmauri_keyprovider_ssh import SshKeyProvider
from swarmauri_core.key_providers.types import (
    KeySpec,
    KeyAlg,
    KeyClass,
    ExportPolicy,
    KeyUse,
)


async def main() -> None:
    provider = SshKeyProvider()
    spec = KeySpec(
        klass=KeyClass.asymmetric,
        alg=KeyAlg.ED25519,
        uses=(KeyUse.SIGN, KeyUse.VERIFY),
        export_policy=ExportPolicy.PUBLIC_ONLY,
    )
    ref = await provider.create_key(spec)
    jwk = await provider.get_public_jwk(ref.kid)
    print(jwk)


asyncio.run(main())

Keys can also be rotated, and the provider will track key versions:

ref = await provider.create_key(spec)
await provider.rotate_key(ref.kid)
assert await provider.list_versions(ref.kid) == (1, 2)

Use destroy_key() to remove an entire key identifier or just a single version, and jwks(prefix_kids=...) when you need to emit a filtered JWKS for downstream consumers.

Existing keys can be imported from PEM or OpenSSH data and exposed via JWKS:

from pathlib import Path

pem = Path("id_ed25519").read_bytes()
ref = await provider.import_key(spec, pem)
jwks = await provider.jwks()

Want to help?

If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.

Metadata

Release files for swarmauri_keyprovider_ssh 0.11.0.dev1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmauri_keyprovider_ssh 0.11.0.dev1
File Size Uploaded
swarmauri_keyprovider_ssh-0.11.0.dev1.tar.gz 9.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmauri_keyprovider_ssh 0.11.0.dev1
File Interpreter ABI Platform
swarmauri_keyprovider_ssh-0.11.0.dev1-py3-none-any.whl Python 3 none any Details

Total release size: 20.1 kB

Release files / swarmauri_keyprovider_ssh-0.11.0.dev1.tar.gz

Download URL swarmauri_keyprovider_ssh-0.11.0.dev1.tar.gz
Size 9.5 kB
Tags Source
SHA-256 checksum
How to use checksums
7a1764f54fc23975be01a6a0aa4b6075f999ec438087d81dbe4617678fbac387
BLAKE2b-256 checksum
How to use checksums
dd5ba98915fbbc7c28ab8e178be95ac4699332f575b8100372893eb336f6773a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmauri_keyprovider_ssh-0.11.0.dev1-py3-none-any.whl

Download URL swarmauri_keyprovider_ssh-0.11.0.dev1-py3-none-any.whl
Size 10.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b0c43d7bd6d4069b4f987e587da08d23c0ca48c89b7f5196a404b4a31a561fca
BLAKE2b-256 checksum
How to use checksums
f4f352c6ab4b7771c49fc0a43a0441a55b2ee84ea8ac2c21edaaede8d0f6676b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page