NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2316 most downloaded on PyPI
Microsoft Corporation Key Vault Administration Client Library for Python
Last release 2 days ago
02 Oct 2026
Release timing varies
gaps range from 9 days to 11 months
Nearly every release is documented
notes for 11 of 11 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
24 releases · first in 2020
One column per quarter.
Added support for service API version 2026-07-01-preview #48963
2026-07-01-preview #48963KeyVaultEkmClient. The client now exposesbegin_create_ekm_private_endpoint, begin_delete_ekm_private_endpoint, get_ekm_private_endpoint,list_ekm_private_endpoints, and get_ekm_private_endpoint_operation_status.KeyVaultEkmPrivateEndpoint, KeyVaultEkmPrivateEndpointConnectionState,KeyVaultEkmPrivateEndpointProperties, and KeyVaultEkmPrivateEndpointOperation models, along with theKeyVaultEkmConnectivityMode, KeyVaultEkmPrivateEndpointConnectionStatus,KeyVaultEkmPrivateEndpointOperationStatus, KeyVaultEkmPrivateEndpointOperationType, andKeyVaultEkmPrivateEndpointProvisioningState enums.connectivity_mode keyword argument and attribute to KeyVaultEkmConnection. Set this toKeyVaultEkmConnectivityMode.PRIVATE_ENDPOINT to reach the EKM proxy through an EKM proxy private endpoint, in whichhost is the name of the private endpoint instead of a DNS name or IP address.2026-07-01-preview is now the default.Fixed an issue where cached authentication challenges could bypass challenge resource verification.
Preserve newer cached authentication challenges installed by concurrent requests when an older request fails. Failed requests now clear only the cache entry they observed or accepted.
Hardened challenge cache reuse as a follow-up to #48710. Cached challenges are now verified before token use, and stale entries are cleared when challenge parsing or resource verification fails. Request replay and existing CAE scope/tenant precedence are preserved when concurrent requests invalidate the shared cache.
Preserved redirect header cleanup and header updates when restoring request bodies during authentication.
Reject request URLs containing backslashes in the authority before authentication.
Clear the request's cached challenge when a 401 response omits WWW-Authenticate, returning that response without an authentication retry.
If no newer challenge remains, the next request rediscovers it, which can add an unauthenticated request even when
resource verification is disabled.
Fixed a bug in the challenge authentication policy where the authentication challenge was cached before the challenge resource was verified. The challenge is now cached only after resource verification succeeds #48710.
Fixed a replay bug in challenge authentication policy. The original request is now stored at the request level instead of the client level. #47742
Added support for service API version 2026-01-01-preview #46895
2026-01-01-preview #46895KeyVaultEkmClient for managing Managed HSM External Key Manager (EKM) connections. This new client exposes get_ekm_connection,
create_ekm_connection, update_ekm_connection, delete_ekm_connection, get_ekm_certificate, and check_ekm_connection.KeyVaultEkmConnection, KeyVaultEkmProxyClientCertificateInfo, and KeyVaultEkmProxyInfo models supporting the EKM client.2026-01-01-preview is now the default.Reject request URLs containing backslashes in the authority before authentication.
WWW-Authenticate, without retrying authentication.Fixed the challenge authentication policy to cache the authentication challenge only after the challenge resource is verified, so that a rejected chal
Added support for service API version 2025-07-01 #46716
2025-07-01 #46716azure-keyvault-administration are not compatible with this version. Similarly, continuation tokens generated by
previous versions of this library are not compatible with versions of azure-core>=1.38.0.azure-core version to 1.38.02025-07-01 is now the defaultAdded support for service API version 7.6
7.6KeyVaultBackupClient.begin_pre_backup and KeyVaultBackupClient.begin_pre_restore methods for
checking if it is possible to perform a full key backup or full key restore
#375077.6 is now the defaulttyping-extensions version to 4.6.0These changes do not impact the API of stable versions such as 4.5.0. Only code written against a beta version such as 4.6.0b1 may be affected.
KeyVaultBackupClient.begin_pre_backup and KeyVaultBackupClient.begin_pre_restore to be
pollers returning NoneAdded support for service API version 7.6-preview.2
7.6-preview.2KeyVaultBackupClient.begin_pre_backup and KeyVaultBackupClient.begin_pre_restore methods for checking if it
is possible to perform a full key backup or full key restore
#37507typing-extensions version to 4.6.0Added support for Continuous Access Evaluation (CAE). enable_cae=True is passed to all get_token requests.
enable_cae=True is passed to all get_token requests.azure-core version to 1.31.0Added support for service API version 7.5
7.5KeyVaultBackupClient.begin_backup and KeyVaultBackupClient.begin_restore now accept a
use_managed_identity keyword-only argument to enable authentication via Managed Identity7.5 is now the defaultazure-core version to 1.29.5azure-common requirementAdded support for service API version 7.5-preview.1
7.5-preview.1KeyVaultBackupClient.begin_backup and KeyVaultBackupClient.begin_restore now accept a use_managed_identity
keyword-only argument to enable authentication via Managed Identity7.5-preview.1 is now the defaultToken requests made during AD FS authentication no longer specify an erroneous "adfs" tenant ID
Added support for service API version 7.4
7.4send_request method that can be used to send custom requests using the
client's existing pipeline (#25172)KeyVaultSettingsClients for getting and updating Managed HSM settingsKeyVaultSetting class has a getboolean method that will return the setting's value as a bool, if possible,
and raise a ValueError otherwiseThese changes do not impact the API of stable versions such as 4.2.0. Only code written against a beta version such as 4.3.0b1 may be affected.
KeyVaultSettingsClient.update_setting now accepts a single setting argument (a KeyVaultSetting instance)
instead of a name and valueKeyVaultSetting model's type parameter and attribute have been renamed to setting_typeSettingType enum has been renamed to KeyVaultSettingType7.4 is now the defaultazure-core version to 1.24.0msrest requirementsix requirementisodate>=0.6.1 (isodate was required by msrest)typing-extensions>=4.0.1Added sync and async KeyVaultSettingsClients for getting and updating Managed HSM settings.
KeyVaultSettingsClients for getting and updating Managed HSM settings.7.4-preview.17.4-preview.1 is now the defaultazure-core version to 1.24.0msrest requirementsix requirementisodate>=0.6.1 (isodate was required by msrest)typing-extensions>=4.0.1Clients verify the challenge resource matches the vault domain. This should affect few customers, who can provide verify_challenge_resource=False to c
verify_challenge_resource=False to client constructors to disable.
See https://aka.ms/azsdk/blog/vault-uri for more information.### Other Changes - Documentation improvements
Key Vault API version 7.3 is now the default
azure-identity
1.8.0 or newer (#20698)azure-core version to 1.20.0get_token calls during challenge
authentication requests now pass in a tenant_id keyword argument
(#20698). See
https://aka.ms/azsdk/python/identity/tokencredential for more details on how to integrate
this parameter if get_token is implemented by a custom credential.Python 2.7 is no longer supported. Please use Python version 3.6 or later.
azure-core version to 1.20.0get_token calls during challenge
authentication requests now pass in a tenant_id keyword argument
(#20698)Added support for multi-tenant authentication when using azure-identity 1.7.1 or newer
azure-identity 1.7.1 or newer
(#20698)azure-core version to 1.15.0Key Vault API version 7.3-preview is now the default
Key Vault API version 7.2 is now the default
KeyVaultAccessControlClient.delete_role_assignment and
.delete_role_definition no longer raise an error when the resource to be
deleted is not foundKeyVaultAccessControlClient.set_role_definition accepts an optional
assignable_scopes keyword-only argumentKeyVaultAccessControlClient.delete_role_assignment and
.delete_role_definition return NoneKeyVaultAccessControlClient.set_role_definition.
permissions is now an optional keyword-only argumentBackupOperation to KeyVaultBackupResult, and removed all but
its folder_url propertyRestoreOperation and SelectiveKeyRestoreOperation classesKeyVaultBackupClient.begin_selective_restore. To restore a
single key, pass the key's name to KeyVaultBackupClient.begin_restore:# before (4.0.0b3):
client.begin_selective_restore(folder_url, sas_token, key_name)
# after:
client.begin_restore(folder_url, sas_token, key_name=key_name)
KeyVaultBackupClient.get_backup_status and .get_restore_status. Use
the pollers returned by KeyVaultBackupClient.begin_backup and .begin_restore
to check whether an operation has completedKeyVaultRoleAssignment's principal_id, role_definition_id, and scope
are now properties of a properties property# before (4.0.0b3):
print(KeyVaultRoleAssignment.scope)
# after:
print(KeyVaultRoleAssignment.properties.scope)
KeyVaultPermission properties:
allowed_actions -> actionsdenied_actions -> not_actionsallowed_data_actions -> data_actionsdenied_data_actions -> denied_data_actionsrole_assignment_name to name in
KeyVaultAccessControlClient.create_role_assignment, .delete_role_assignment,
and .get_role_assignmentrole_definition_name to name in
KeyVaultAccessControlClient.delete_role_definition and .get_role_definitionrole_scope to scope in KeyVaultAccessControlClient methodsKeyVaultAccessControlClient supports managing custom role definitions
KeyVaultAccessControlClient supports managing custom role definitionsKeyVaultBackupClient.begin_full_backup() to .begin_backup()KeyVaultBackupClient.begin_full_restore() to .begin_restore()BackupOperation.azure_storage_blob_container_uri to .folder_urlid property of BackupOperation, RestoreOperation, and
SelectiveKeyRestoreOperation to job_idblob_storage_uri parameters of KeyVaultBackupClient.begin_restore()
and .begin_selective_restore() to folder_urlfolder_name parameter from
KeyVaultBackupClient.begin_restore() and .begin_selective_restore() (the
folder_url parameter contains the folder name)KeyVaultPermission attributes:
actions -> allowed_actionsdata_actions -> allowed_data_actionsnot_actions -> denied_actionsnot_data_actions -> denied_data_actionsKeyVaultRoleAssignment.assignment_id to .role_assignment_idKeyVaultRoleScope enum values:
global_value -> GLOBALkeys_value -> KEYSKeyVaultBackupClient.get_backup_status and .get_restore_status enable checking the status of a pending operation by its job ID
KeyVaultBackupClient.get_backup_status and .get_restore_status enable
checking the status of a pending operation by its job ID
(#13718)role_assignment_name parameter of
KeyVaultAccessControlClient.create_role_assignment is now an optional
keyword-only argument. When this argument isn't passed, the client will
generate a name for the role assignment.
(#13512)KeyVaultAccessControlClient performs role-based access control operations
KeyVaultAccessControlClient performs role-based access control operationsKeyVaultBackupClient performs full vault backup and full and selective
restore operationsYour coding agent can read these notes before it upgrades. Set up the MCP server →