NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1227 most downloaded on PyPI
Microsoft Corporation Key Vault Certificates Client Library for Python
Last release 2 days ago
02 Oct 2026
Release timing varies
gaps range from 2 weeks to 10 months
Nearly every release is documented
notes for 17 of 17 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
33 releases · first in 2019
Fixed a replay bug in the challenge authentication policy where a request copy stashed on the shared policy instance was never cleared, allowing one r
azure-keyvault-keys and azure-keyvault-administration in
#47742.One column per quarter.
Added an experimental PlatformManaged property on CertificatePolicy for Azure Key Vault internal usage. Any calls using this property will fail and it
PlatformManaged property on CertificatePolicy for Azure Key Vault internal usage. Any calls using this property will fail and it is not recommended to be used at this point.2026-03-01-previewReject request URLs containing backslashes in the authority before authentication.
WWW-Authenticate, without retrying authentication.Fixed the challenge authentication policy to cache the authentication challenge only after the challenge resource is verified, so that a rejected chal
Fixed CertificateClient.begin_create_certificate (and its async counterpart) incorrectly raising ValueError when a CertificatePolicy was created with
CertificateClient.begin_create_certificate (and its async counterpart) incorrectly raising
ValueError when a CertificatePolicy was created with only san_ip_addresses or san_uris and no
subject, san_dns_names, san_emails, or san_user_principal_names. IP addresses and URIs are
valid subject alternative name types and are now recognized by the client's policy validator.Added support for service API version 2025-07-01
2025-07-01uris and ip_addresses properties to SubjectAlternativeNamesCertificateClient.(begin_)create_certificate now returns a
CertificateOperation instead of NoneCertificateOperationError will be correctly
serialized instead of raising an exception
(Azure/azure-cli #31764)Code | Docs
Support: Active
Key Vault - Security Domain
azure-keyvault-securitydomain
Added support for service API version 7.6
7.6preserve_order keyword-only argument when creating or importing certificates to
allow preserving a certificate chain's original order, and a corresponding preserve_order property to
CertificateProperties and CertificateOperation models
(#37507)7.6 is now the defaulttyping-extensions version to 4.6.0These changes do not impact the API of stable versions such as 4.9.0. Only code written against a beta version such as 4.10.0b1 may be affected.
preserve_certificate_order keyword-only argument and property to preserve_orderAdded support for service API version 7.6-preview.2
7.6-preview.2preserve_certificate_order keyword-only argument when creating or importing certificates to allow
preserving a certificate chain's original order, and corresponding a preserve_certificate_order property to
CertificateProperties and CertificateOperation models
(#37507)typing-extensions version to 4.6.0Added support for Continuous Access Evaluation (CAE). enable_cae=True is passed to all get_token requests.
enable_cae=True is passed to all get_token requests.azure-core version to 1.31.0Added support for service API version 7.5
7.5These changes do not impact the API of stable versions such as 4.7.0. Only code written against a beta version such as 4.8.0b2 may be affected.
CertificateProperties.x509_thumbprint_string. To get the certificate's thumbprint in hex, use
CertificateProperties.x509_thumbprint.hex() or print the CertificateProperties instance.asyncio is no longer directly referenced by the library
(#33819)7.5 is now the defaultazure-core version to 1.29.5azure-common requirementAdded support for service API version 7.5-preview.1
7.5-preview.17.5-preview.1 is now the defaultAdded CertificateProperties.x509_thumbprint_string to return the hexadecimal string representation of the SHA-1 hash of the certificate
CertificateProperties.x509_thumbprint_string to return the hexadecimal string representation of the SHA-1 hash
of the certificate (#30166)Token requests made during AD FS authentication no longer specify an erroneous "adfs" tenant ID
Added support for service API version 7.4
7.4send_request method that can be used to send custom requests using the
client's existing pipeline (#25172)KeyVaultCertificate.cer and DeletedCertificate.cer are now
Optional[bytearray] instead of Optional[bytes]
(#28959)7.4 is now the defaultazure-core version to 1.24.0msrest requirementisodate>=0.6.1 (isodate was required by msrest)typing-extensions>=4.0.1Clients verify the challenge resource matches the vault domain. This should affect few customers, who can provide verify_challenge_resource=False to c
verify_challenge_resource=False to client constructors to disable.
See https://aka.ms/azsdk/blog/vault-uri for more information.### Other Changes - Documentation improvements
Port numbers are now preserved in the vault_url property of a KeyVaultCertificateIdentifier
vault_url property of a KeyVaultCertificateIdentifier
(#24446)Key Vault API version 7.3 is now the default
azure-identity
1.8.0 or newer (#20698)KeyType now ignores casing during declaration, which resolves a scenario where Key Vault
keys created with non-standard casing could not be fetched with the SDK
(#22797)azure-core version to 1.20.0get_token calls during challenge
authentication requests now pass in a tenant_id keyword argument
(#20698). See
https://aka.ms/azsdk/python/identity/tokencredential for more details on how to integrate
this parameter if get_token is implemented by a custom credential.Python 2.7 is no longer supported. Please use Python version 3.6 or later.
get_token calls during challenge
authentication requests now pass in a tenant_id keyword argument
(#20698)Added support for multi-tenant authentication when using azure-identity 1.7.1 or newer
azure-identity 1.7.1 or newer
(#20698)azure-core version to 1.15.0Key Vault API version 7.3-preview is now the default
This is the last version to support Python 3.5. The next version will require Python 2.7 or 3.6+.
This is the last version to support Python 3.5. The next version will require Python 2.7 or 3.6+.
msrest version to 0.6.21issuer_name parameter for CertificatePolicy is now optionalKeyVaultCertificateIdentifier that parses out a full ID returned by Key Vault,
so users can easily access the certificate's name, vault_url, and version.Correct typing for paging methods
Fixed an AttributeError during get_certificate_version
AttributeError during get_certificate_versionimport_certificate no longer raises AttributeError when the policy
keyword argument isn't passedx-ms-keyvault-region and x-ms-keyvault-service-version headers
are no longer redacted in logging outputazure-core version to 1.7.0CustomHookPolicy through the optional
keyword argument custom_hook_policyx-ms-client-request-idazure-common for multiapi supportSupport for Key Vault API version 7.1-preview
recoverable_days to CertificatePropertiesApiVersion enum identifying Key Vault versions supported by this packageCertificateClient instances have a close method which closes opened sockets. Used as a context manager, a CertificateClient closes opened sockets on e
azure.keyvault.certificates defines __version__
- First GA release
Challenge authentication policy preserves request options
vault_url property to CertificateOperationid, expires_on, not_before, and recover_level properties from CertificatePolicyvault_url property from CertificateIssuervault_url property from IssuerPropertiesUpdated msrest requirement to >=0.6.0
msrest requirement to >=0.6.0get_policy to get_certificate_policyupdate_policy to update_certificate_policycreate_contacts to set_contactsadmin_details of create_issuer and update_issuer to admin_contactsname parameters to include the name of the object whose name we are referring to.
For example, the name parameter of get_certificate is now certificate_nameAdministratorDetails to AdministratorContactekus property of CertificatePolicy to enhanced_key_usagecurve property of CertificatePolicy to key_curve_namesan_upns property of CertificatePolicy to san_user_principal_namessubject_name property of CertificatePolicy a kwarg and renamed it to subjectdeleted_date property of DeletedCertificate to deleted_onissuer_properties property from CertificateIssuer and added the provider property
directly onto CertificateIssueradmin_details of CertificateIssuer to admin_contactsthumbprint property of CertificateProperties to x509_thumbprintWellKnownIssuerNames enum class that holds popular issuer namesSecretContentType enum class to CertificateContentTypeRemoved redundant method get_pending_certificate_signing_request(). A pending CSR can be retrieved via get_certificate_operation().
Removed redundant method get_pending_certificate_signing_request(). A pending CSR can be retrieved via get_certificate_operation().
Renamed the sync method create_certificate to begin_create_certificate
Renamed restore_certificate to restore_certificate_backup
Renamed get_certificate to get_certificate_version
Renamed get_certificate_with_policy to get_certificate
Renamed list_certificates to list_properties_of_certificates
Renamed list_properties_of_issuers to list_properties_of_issuers
Renamed list_certificate_versions to list_properties_of_certificate_versions
create_certificate now has policy as a required parameter
All optional positional parameters besides version have been moved to kwargs
Renamed sync method delete_certificate to begin_delete_certificate
Renamed sync method recover_certificate to begin_recover_deleted_certificate
Renamed async method recover_certificate to recover_deleted_certificate
The sync method begin_delete_certificate and async delete_certificate now return pollers that return a DeletedCertificate
The sync method begin_recover_deleted_certificate and async recover_deleted_certificate now return pollers that return a KeyVaultCertificate
Renamed enum ActionType to CertificatePolicyAction
Renamed Certificate to KeyVaultCertificate
Renamed Contact to CertificateContact
Renamed Issuer to CertificateIssuer
Renamed CertificateError to CertificateOperationError
Renamed expires property of CertificateProperties and CertificatePolicy to expires_on
Renamed created property of CertificateProperties, CertificatePolicy, and CertificateIssuer to created_on
Renamed updated property of CertificateProperties, CertificatePolicy, and CertificateIssuer to updated_on
The vault_endpoint parameter of CertificateClient has been renamed to vault_url
The property vault_endpoint has been renamed to vault_url in all models
CertificatePolicy now has a public class method get_default allowing users to get the default CertificatePolicy
Logging can now be enabled properly on the client level
Enums JsonWebKeyCurveName and JsonWebKeyType have been renamed to KeyCurveName and KeyType, respectively.
Enums JsonWebKeyCurveName and JsonWebKeyType have been renamed to KeyCurveName and KeyType, respectively.
Both async and sync versions of create_certificate now return pollers that return the created Certificate if creation is successful,
and a CertificateOperation if not.
Certificate now has attribute properties, which holds certain properties of the
certificate, such as version. This changes the shape of the Certificate type,
as certain properties of Certificate (such as version) have to be accessed
through the properties property.
update_certificate has been renamed to update_certificate_properties
The vault_url parameter of CertificateClient has been renamed to vault_endpoint
The property vault_url has been renamed to vault_endpoint in all models
Version 4.0.0b3 is the first preview of our efforts to create a user-friendly and Pythonic client library for Azure Key Vault's certificates.
Version 4.0.0b3 is the first preview of our efforts to create a user-friendly and Pythonic client library for Azure Key Vault's certificates.
This library is not a direct replacement for azure-keyvault. Applications
using that library would require code changes to use azure-keyvault-certificates.
This package's
documentation
and
samples
demonstrate the new API.
azure-keyvault:azure-keyvault-certificates contains a client for certificate operationsazure-identity credentials
azure.keyvault.certificates.aio namespace contains an async equivalent of
the synchronous client in azure.keyvault.certificatesYour coding agent can read these notes before it upgrades. Set up the MCP server →