NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2249 most downloaded on PyPI
AWS Encryption SDK implementation for Python
Last release 1 months ago
04 Sep 2026
Release timing varies
gaps range from 2 weeks to 1.6 years
Nearly every release is documented
notes for 38 of 38 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
38 releases · first in 2017
fix: validate encryption context entry lengths ( #813 ) Thanks to kiwigitops for the contribution.
fix: validate encryption context entry lengths (#813)
Thanks to kiwigitops for the contribution.
fix: preserve root-cause errors in KMSMasterKey exception chaining (#815)
Thanks to @arpitjain099 for the contribution.
One column per quarter.
fix: validate encryption materials from cmm are compatible with key commitment policy #795
MPL v1.11.2 fixes de-serializing Error_OpaqueWithText and bumps cryptography upperbound to <47 due to CVE-2026-26007
deps: Extend supported MPL_ versions to include v1.11.2 #788
MPL v1.11.2 fixes de-serializing Error_OpaqueWithText and bumps cryptography upperbound to <47 due to CVE-2026-26007 (#1800)
This library is NOT impacted by CVE-2026-26007. This library does not use SECT curves.
deps: Extend supported MPL versions to include v1.11.1 #770
deps: Extend supported MPL versions to include v1.11.0.
fix: Improve header serialization
fix: Improve header serialization (#747)
ESDK-Python <4.0.1 would truncate non-ASCII key provider IDs it wrote to message headers.
If a Raw or Custom MasterKeyProvider or Keyring supplied a non-ASCII key provider ID / key namespace,
ESDK-Python would truncate the the key provider ID it wrote to the message's header.
The message can be decrypted by replacing the truncated provider ID with the expected provider ID in decryption code.
Contact AWS for any questions about this approach.
Add support for constructs from the AWS Cryptographic Material Providers Library (MPL). The MPL contains new constructs for encrypting and decrypting
fix: validate encryption materials from cmm are compatible with key commitment policy #796
The AWS Encryption SDK for Python no longer supports Python 3.7 as of version 3.3; only Python 3.8+ is supported.
The AWS Encryption SDK for Python no longer supports Python 3.7 as of version 3.3; only Python 3.8+ is supported.
The AWS Encryption SDK for Python no longer supports Python 3.7
as of version 3.3; only Python 3.8+ is supported.
deprecate python36 from chalice (#539 (https://github.com/josecorella/aws-encryption-sdk-python/issues/539)) (f8aa29f (https://github.com/josecorella/…
Replace deprecated cryptography verify_interface with isinstance #467
Warn on Deprecated Python usage #368
The AWS Encryption SDK for Python no longer supports Python 3.5 as of version 3.1; only Python 3.6+ is supported. Customers using Python 3.5 can still use the 2.x line of the AWS Encryption SDK for Python, which will continue to receive security updates, in accordance with our Support Policy.
Move away from deprecated cryptography int_from_bytes #355.
The AWS Encryption SDK for Python no longer supports Python 2 or Python 3.4 as of major version 3.x; only Python 3.5+ is supported. Customers using Python 2 or Python 3.4 can still use the 2.x line of the AWS Encryption SDK for Python, which will continue to receive security updates for the next 12 months, in accordance with our Support Policy.
int_from_bytes #355.Emit Deprecation Warning on library initialization
The AWS Encryption SDK for Python Major Version 2 is End of Support. It will no longer receive security updates or bug fixes. Consider updating to the latest version of the AWS Encryption SDK for Python.
cryptography range to greater than or equal to 2.5.0 less than 37Pin cryptography to last version that supports Python2
cryptography to last version that supports Python2The AWS Encryption SDK for Python is discontinuing support for Python 2. Future major versions of this library will drop support for Python 2 and begi
The AWS Encryption SDK for Python is discontinuing support for Python 2. Future major versions of this library will drop support for Python 2 and begin to adopt changes that are known to break Python 2.
Support for Python 3.4 will be removed at the same time. Moving forward, we will support Python 3.5+.
Security updates will still be available for the Encryption SDK 2.x line for the next 12 months, in accordance with our Support Policy.
AWS KMS multi-Region Key support
AWS KMS multi-Region Key support (#350)
Added new the master key MRKAwareKMSMasterKey and the new master key providers MRKAwareStrictAwsKmsMasterKeyProvider and MRKAwareDiscoveryAwsKmsMasterKeyProvider that support AWS KMS multi-Region Keys.
See https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.html for more details about AWS KMS multi-Region Keys. See https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/configure.html#config-mrks for more details about how the AWS Encryption SDK interoperates with AWS KMS multi-Region keys.
Improvements to the message decryption process (#343) See https://github.com/aws/aws-encryption-sdk-python/security/advisories/GHSA-x5h4-9gqw-942j
Improvements to the message decryption process
See https://github.com/aws/aws-encryption-sdk-python/security/advisories/GHSA-x5h4-9gqw-942j.
New minimum cryptography dependency 2.5.0 since we're using newer byte type checking #308
Updates to the AWS Encryption SDK 73cce71
See migration guide for more details: https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/migration.html
Updates to the AWS Encryption SDK. 73cce71
KMSMasterKeyProvider is removed. Customers must use StrictAwsKmsMasterKeyProvider with explicit key ids, or DiscoveryAwsKmsMasterKeyProvider to allow decryption of any ciphertext to which the application has access.
The encrypt, decrypt, and stream methods in the aws_encryption_sdk module are removed, replaced by identically named methods on the new EncryptionSDKClient class.
Key committing algorithm suites are now default.
See Migration guide for more details.
Emit Deprecation Warning on library initialization
The AWS Encryption SDK for Python Major Version 1 is End of Support. It will no longer receive security updates or bug fixes. Consider updating to the latest version of the AWS Encryption SDK for Python.
Pin cryptography to last version that supports Python2
cryptography to last version that supports Python2Improvements to the message decryption process (#342) See https://github.com/aws/aws-encryption-sdk-python/security/advisories/GHSA-x5h4-9gqw-942j
Reintroduce removed symbol in top-level aws_encryption_sdk module
aws_encryption_sdk moduleFix region configuration override in botocore sessions. #190 #193
StreamDecryptor.body_start and StreamDecryptor.body_end, deprecated in a prior release, have now been removed.
source_stream APIs except for read(). #103source_stream when they themselves close.
If you are using context managers for all of your stream handling,
this change will not affect you.
However, if you have been relying on the StreamDecryptor
or StreamEncryptor to close your source_stream for you,
you will now need to close those streams yourself.StreamDecryptor.body_start and StreamDecryptor.body_end,
deprecated in a prior release,
have now been removed.unittest tests to pytest. #99MasterKeyprovider.decrypt_data_key_from_list error handling. #150Remove debug logging that may contain input data when encrypting non-default unframed messages. #105
## Bugfixes
Remove debug logging that may contain input data when encrypting non-default unframed messages. #105
## Minor
Add support to remove clients from KMSMasterKeyProvider client cache if they fail to connect to endpoint. #86
Add support for SHA384 and SHA512 for use with RSA OAEP wrapping algorithms. #56
Fix streaming_client classes to properly interpret short reads in source streams. #24
Fix KMSMasterKeyProvider to determine the default region before trying to create the requested master keys. #83
StreamEncryptor and StreamDecryptor should always report as readable if they are open. #73 _
Move the aws-encryption-sdk-python repository from awslabs to aws.
Move the aws-encryption-sdk-python repository from awslabs to aws.
AWS KMS master key/provider user agent extension fixed. #47 _
Remove use of attrs functionality deprecated in 17.3.0 #29 _
Remove use of attrs functionality deprecated in 17.3.0 #29
Blacklisted pytest 3.3.0 #32 pytest-dev/pytest#2957
Addressed issue #13 _ to properly handle non-seekable source streams.
Addressed issue #13 to properly handle non-seekable source streams.
Broke out internal.crypto into smaller, feature-oriented, modules.
Moved source into src.
Moved examples into examples.
Broke out internal.crypto into smaller, feature-oriented, modules.
Added `tox`_ configuration to support automation and development tooling.
Added `pylint`_, `flake8`_, and `doc8`_ configuration to enforce style rules.
Updated internal.crypto.authentication.Verifier to use Prehashed.
Addressed docstring issue #7.
Addressed docstring issue #8.
Addressed logging issue #10.
Addressed assorted linting issues to bring source, tests, examples, and docs up to configured linting standards.
Added cryptographic materials managers as a concept
Fixed attrs version to 16.3.0 to avoid breaking changes in attrs 17.1.0_
Fixed attrs version to 16.3.0 to avoid `breaking changes in attrs 17.1.0`_
.. _MPL: https://github.com/aws/aws-cryptographic-material-providers-library .. _breaking changes in attrs 17.1.0: https://attrs.readthedocs.io/en/sta…
Initial public release
Your coding agent can read these notes before it upgrades. Set up the MCP server →