Skip to main content

SyftWallet 🔐

Unified secure management for both single secrets (API keys) and credentials (username + password) using 1Password integration

SyftWallet intelligently handles both types of secrets that exist in 1Password:

  • 🔑 Single Values: API keys, tokens, passwords (PASSWORD items)
  • 👤 Credentials: Username + password combinations (LOGIN items)

Features

🔒 Security First

  • 🛡️ Approval Required for All Access - No silent secret retrieval
  • 🖥️ Native System Dialogs - Works in background tasks and all environments
  • 📟 Multi-Platform Support - macOS, Windows, and Linux native dialogs
  • ⏰ Timeout Protection - Auto-deny after 5 minutes
  • 📝 Full Context Display - App name, reason, and security warnings
  • 🚫 Zero Trust Model - Every access requires explicit user approval
  • 🔧 Background Task Compatible - Unlike Jupyter widgets, works everywhere

💾 Storage & Management

  • 🔐 Secure 1Password Integration - Primary storage using 1Password CLI
  • 🔄 Multiple Fallbacks - System keyring and environment variables
  • ⚡ Intelligent Caching - Configurable TTL for performance
  • 🏷️ Tagging System - Organize secrets with tags
  • 🌐 Dynamic Vault Discovery - Automatically finds and searches all vaults
  • 🧠 Smart Type Detection - LOGIN vs PASSWORD items handled intelligently
  • 👤 Credential Management - Full support for username + password combinations

🎨 User Experience

  • ✨ Beautiful Jupyter Display - Rich HTML rendering for notebooks
  • 🎯 Interactive Search Widget - Search, select, and copy keys with one click
  • 🖥️ CLI Interface - Command-line tool for easy management
  • 🔍 Status Monitoring - Check availability of all backends

Quick Start

Installation

pip install syft-wallet

Python API

import syft_wallet as wallet

# Store single secrets (API keys, tokens) - NO APPROVAL NEEDED
wallet.store("api_key", "secret123", tags=["api"])

# Store credentials (username + password) - NO APPROVAL NEEDED
wallet.store_credentials("github", "username", "password", tags=["git"])

# 🔒 SECURE RETRIEVAL - REQUIRES USER APPROVAL WITH CONTEXT
api_key = wallet.get(
    name="api_key",
    app_name="my_application", 
    reason="Access API key for making authenticated requests"
)

github = wallet.get_credentials(
    name="github",
    app_name="git_client",
    reason="Access GitHub credentials for repository operations"
)

# Specific field access with approval
username = wallet.get_username(
    name="github", 
    app_name="auth_service",
    reason="Get username for authentication display"
)

password = wallet.get_password(
    name="github",
    app_name="git_sync",
    reason="Access password for repository push/pull operations"
)

# Browse and manage (no approval needed)
keys = wallet.list_keys()         # Rich table with type info
status = wallet.status()          # Status dashboard  
wallet.search_keys()              # Interactive search widget
wallet.show_status()              # Terminal display

🔒 Security: Native System Approval Required

Every secret access requires explicit approval via native system dialogs:

🍎 macOS: Native AppleScript dialogs with system styling
🪟 Windows: Native MessageBox dialogs or PowerShell prompts
🐧 Linux: Zenity, KDialog, or XMessage depending on desktop
📟 Fallback: Rich CLI prompts if no GUI available

🔧 Works Everywhere: Unlike Jupyter widgets, native dialogs work in:

  • ✅ Background processes and daemons
  • ✅ Cron jobs and scheduled tasks
  • ✅ Web servers and APIs
  • ✅ CLI applications and scripts
  • ✅ Jupyter notebooks and IDEs

Example approval dialog shows:

  • 🔑 Secret Name: tinfoil_api_key
  • 📱 Application: syft-nsai
  • 💭 Reason: Access Tinfoil AI API for running language models in secure enclaves
  • ⚠️ Security Warning: Only approve trusted applications

Benefits:

  • ✅ Universal Compatibility - Works in any environment, not just notebooks
  • ✅ No Silent Access - Every request requires explicit approval
  • ✅ Full Context - Users see exactly why secrets are needed
  • ✅ App Identification - Know which application is requesting access
  • ✅ Timeout Protection - Requests auto-deny after 5 minutes
  • ✅ System Integration - Uses native OS security patterns

CLI Usage

# Store a single secret
syft-wallet set api_key "secret123" --tags api

# Store credentials (interactive)
syft-wallet set-credentials github --username myuser --password mypass

# Retrieve secrets
syft-wallet get api_key
syft-wallet get-credentials github

# Show status with vault info
syft-wallet status

Integration with SyftBox

Works seamlessly with other SyftBox packages:

import syft_wallet as wallet
import syft_nsai as nsai

# Store your API key securely
wallet.store("tinfoil_api_key", "tk_your_key_here")

# syft-nsai will automatically retrieve it
# No hardcoded keys needed!

License

Apache 2.0 - See LICENSE file for details.

Metadata

Release files for syft-wallet 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for syft-wallet 0.1.1
File Size Uploaded
syft_wallet-0.1.1.tar.gz 21.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for syft-wallet 0.1.1
File Interpreter ABI Platform
syft_wallet-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 45.3 kB

Release files / syft_wallet-0.1.1.tar.gz

Download URL syft_wallet-0.1.1.tar.gz
Size 21.9 kB
Tags Source
SHA-256 checksum
How to use checksums
4291d07ea249dc269f2e7fe4304ed61afc82cd087c7b49a9d8233daa5886c6a0
BLAKE2b-256 checksum
How to use checksums
44976d1075f02506a9153746a3c5294ccb7b1ae9349d7cd9adb6855bcaeb46e2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.3

Release files / syft_wallet-0.1.1-py3-none-any.whl

Download URL syft_wallet-0.1.1-py3-none-any.whl
Size 23.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7d7f87df91ca936d9068228a9605f38c710e5d17d734cb8c34642059ac09cac6
BLAKE2b-256 checksum
How to use checksums
281e75e68b14a5833b236d7047f2311d2c5fad0f79105c6730b859db68256b23
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.3

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page