NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #889 most downloaded on PyPI
Microsoft Corporation Azure Key Vault Keys Client Library for Python
Last release 2 days ago
02 Oct 2026
Release timing varies
gaps range from 1 weeks to 11 months
Nearly every release is documented
notes for 18 of 18 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
44 releases · first in 2019
Added secure_wrap_key and secure_unwrap_key methods for wrap/unwrap operations on keys #47591.
secure_wrap_key and secure_unwrap_key methods for wrap/unwrap operations on keys #47591.KeySecureWrapAlgorithm enum, listing the algorithms supported by the secure wrap/unwrap operations.SecureWrapResult and SecureUnwrapResult model classes wrapping the results of secure_wrap_key and secure_unwrap_key, respectively.One column per quarter.
Added the ExternalKey model and the new KeyClient.create_external_key method for registering a Key Vault key whose material is held in an external HSM
ExternalKey model and the new KeyClient.create_external_key method
for registering a Key Vault key whose material is held in an external HSM #47200.KeyProperties.external_key read-only property.Added support for service API version 2026-01-01-preview #47116.
2026-01-01-preview #47116.KeyProperties.key_size read-only property.2026-01-01-preview is now the default.Reject request URLs containing backslashes in the authority before authentication.
WWW-Authenticate, without retrying authentication.Fixed the challenge authentication policy to cache the authentication challenge only after the challenge resource is verified, so that a rejected chal
Added support for service API version 2025-07-01 #46716
2025-07-01 #467162025-07-01 is now the defaultcryptography version to 44.0.2Added support for service API version 7.6
7.6KeyClient has a get_key_attestation method that can be used to retrieve a key along with its
attestation blob (stored in a new KeyProperties.attestation property) from a managed HSM
#37507KeyVaultRSAPublicKey and KeyVaultRSAPrivateKey were not correctly implementing the cryptography library's RSAPublicKey and RSAPrivateKey interfaces, causing instantiation errors. (#41205)These changes do not impact the API of stable versions such as 4.10.0. Only code written against a beta version such as 4.11.0b1 may be affected.
EncryptionAlgorithm.ckm_aes_key_wrap -> KeyWrapAlgorithm.ckm_aes_key_wrapEncryptionAlgorithm.ckm_aes_key_wrap_pad -> KeyWrapAlgorithm.ckm_aes_key_wrap_pad7.6 is now the defaulttyping-extensions version to 4.6.0Code | Docs
Support: Active
Key Vault - Security Domain
azure-keyvault-securitydomain
Added support for service API version 7.6-preview.2
7.6-preview.2KeyClient has a get_key_attestation method that can be used to retrieve a key along with its attestation blob
(stored in a new KeyProperties.attestation property) from a managed HSM
#37507typing-extensions version to 4.6.0Added support for Continuous Access Evaluation (CAE). enable_cae=True is passed to all get_token requests.
enable_cae=True is passed to all get_token requests.azure-core version to 1.31.0Added support for service API version 7.5
7.5cryptography library's RSAPrivateKey and RSAPublicKey interfaces are now implemented by
KeyVaultRSAPrivateKey and KeyVaultRSAPublicKey classes that can use keys managed by Key VaultCryptographyClient has create_rsa_private_key and create_rsa_public_key methods that return a
KeyVaultRSAPrivateKey and KeyVaultRSAPublicKey, respectivelyKeyProperties.hsm_platform to get the underlying HSM platformasyncio is no longer directly referenced by the library
(#33819)azure-core version to 1.29.5azure-common requirementAdded support for service API version 7.5-preview.1
7.5-preview.1KeyProperties.hsm_platform to get the underlying HSM platform7.5-preview.1 is now the defaultThe cryptography library's RSAPrivateKey and RSAPublicKey interfaces are now implemented by KeyVaultRSAPrivateKey and KeyVaultRSAPublicKey classes tha
cryptography library's RSAPrivateKey and RSAPublicKey interfaces are now implemented by
KeyVaultRSAPrivateKey and KeyVaultRSAPublicKey classes that can use keys managed by Key VaultCryptographyClient has create_rsa_private_key and create_rsa_public_key methods that return a
KeyVaultRSAPrivateKey and KeyVaultRSAPublicKey, respectivelyToken requests made during AD FS authentication no longer specify an erroneous "adfs" tenant ID
Added support for service API version 7.4
7.4send_request method that can be used to send custom requests using the
client's existing pipeline (#25172)These changes do not impact the API of stable versions such as 4.7.0. Only code written against a beta version such as 4.8.0b2 may be affected.
7.4 is now the defaultazure-core version to 1.24.0msrest version to 0.7.1msrest requirementsix requirementisodate>=0.6.1 (isodate was required by msrest)typing-extensions>=4.0.1Added support for service API version 7.4-preview.1
7.4-preview.1KeyClient has a create_okp_key method to create an octet key pair (OKP) on Managed HSMeddsa to SignatureAlgorithm enum to support signing and verifying using an
Edwards-Curve Digital Signature Algorithm (EdDSA) on Managed HSMokp and okp_hsm to KeyType enum for octet key pairsed25519 to KeyCurveName enum to support use of the Ed25519 Edwards curve7.4-preview.1 is now the defaultmsrest requirementsix requirementisodate>=0.6.1 (isodate was required by msrest)typing-extensions>=4.0.1An attempt will be made to generate an IV if one isn't provided for local encryption
azure-core version to 1.24.0msrest version to 0.7.1Clients verify the challenge resource matches the vault domain. This should affect few customers, who can provide verify_challenge_resource=False to c
verify_challenge_resource=False to client constructors to disable.
See https://aka.ms/azsdk/blog/vault-uri for more information.An attempt will be made to generate an IV if one isn't provided for local encryption
azure-core version to 1.24.0### Other Changes - Documentation improvements
If a key's ID contains a port number, this port will now be preserved in the vault URL of a CryptographyClient instance created from this key
CryptographyClient instance created from this key
(#24446)
vault_url property of a KeyVaultKeyIdentifierFixed error that could occur when fetching a key rotation policy that has no defined lifetime_actions.
lifetime_actions.Key Vault API version 7.3 is now the default
azure-identity
1.8.0 or newer (#20698)KeyClient has a get_random_bytes method for getting a requested number of
random bytes from a managed HSMrelease_key method to KeyClient for releasing the private component of a keyexportable and release_policy keyword-only arguments to key creation and import
methodsKeyExportEncryptionAlgorithm enum for specifying an encryption algorithm to be used
in key releaseKeyClient.get_cryptography_client, which provides a simple way to
create a CryptographyClient for a key, given its name and optionally a version
(#20621)KeyClient.rotate_key to rotate a key on-demandKeyClient.update_key_rotation_policy to update a key's automated rotation policyimmutable keyword-only argument and property to KeyReleasePolicy to
support immutable release policies. Once a release policy is marked as immutable, it can no
longer be modified.These changes do not impact the API of stable versions such as 4.4.0. Only code written against a beta version such as 4.5.0b1 may be affected.
KeyClient.update_key_rotation_policy accepts a required policy argument
(#22981)version parameter in KeyClient.release_key is now a keyword-only argument
(#22981)name parameter in KeyClient.get_key_rotation_policy and
KeyClient.update_key_rotation_policy to key_name
(#22981)azure-keyvault-keys are now uniformly lower-cased
(#22981)KeyType now ignores casing during declaration, which resolves a scenario where Key Vault
keys created with non-standard casing could not be fetched with the SDK
(#22797)azure-core version to 1.20.0CryptographyClient no longer requires a key version when providing a key ID to its constructor
(though providing a version is still recommended)get_token calls during challenge
authentication requests now pass in a tenant_id keyword argument
(#20698). See
https://aka.ms/azsdk/python/identity/tokencredential for more details on how to integrate
this parameter if get_token is implemented by a custom credential.KeyProperties model's managed, exportable, and
release_policy properties (#22368)Added immutable keyword-only argument and property to KeyReleasePolicy to support immutable release policies. Once a release policy is marked as immut
immutable keyword-only argument and property to KeyReleasePolicy to support immutable
release policies. Once a release policy is marked as immutable, it can no longer be modified.These changes do not impact the API of stable versions such as 4.4.0. Only code written against a beta version such as 4.5.0b1 may be affected.
data in KeyReleasePolicy's constructor to
encoded_policyazure-core version to 1.20.0KeyProperties model's managed, exportable, and release_policy
properties (#22368)get_token calls during challenge
authentication requests now pass in a tenant_id keyword argument
(#20698)Added support for multi-tenant authentication when using azure-identity 1.7.1 or newer
azure-identity 1.7.1 or newer
(#20698)These changes do not impact the API of stable versions such as 4.4.0. Only code written against a beta version such as 4.5.0b1 may be affected.
KeyClient.get_random_bytes now returns bytes instead of RandomBytes. The RandomBytes class
has been removedversion keyword-only argument in KeyClient.get_cryptography_client to
key_versionKeyReleasePolicy.data to KeyReleasePolicy.encoded_policytarget parameter in KeyClient.release_key to target_attestation_tokenazure-core version to 1.15.0Added KeyClient.get_cryptography_client, which provides a simple way to create a CryptographyClient for a key, given its name and optionally a version
KeyClient.get_cryptography_client, which provides a simple way to create a
CryptographyClient for a key, given its name and optionally a version
(#20621)KeyClient.rotate_key to rotate a key on-demandKeyClient.update_key_rotation_policy to update a key's automated rotation policyCryptographyClient no longer requires a key version when providing a key ID to its constructor
(though providing a version is still recommended)Updated type hints to fix mypy errors
Added support for secure key release from a Managed HSM
release_key method to KeyClient for releasing the private component of a keyexportable and release_policy keyword-only arguments to key creation and import
methodsKeyExportEncryptionAlgorithm enum for specifying an encryption algorithm to be used
in key releaseThese changes do not impact the API of stable versions such as 4.4.0. Only code written against a beta version such as 4.5.0b1 may be affected.
KeyClient.get_random_bytes now returns a RandomBytes model with bytes in a value
property, rather than returning the bytes directly
(#19895)Beginning with this release, this library requires Python 2.7 or 3.6+.
Beginning with this release, this library requires Python 2.7 or 3.6+.
KeyClient has a get_random_bytes method for getting a requested number of random
bytes from a managed HSMThis is the last version to support Python 3.5. The next version will require Python 2.7 or 3.6+.
This is the last version to support Python 3.5. The next version will require Python 2.7 or 3.6+.
msrest version to 0.6.21KeyClient has a create_oct_key method for creating symmetric keysKeyClient's create_key and create_rsa_key methods now accept a public_exponent
keyword-only argument (#18016)oct_hsm to KeyTypeEncryptionAlgorithmKeyWrapAlgorithmCryptographyClient's encrypt method accepts iv and
additional_authenticated_data keyword argumentsCryptographyClient's decrypt method accepts iv,
additional_authenticated_data, and authentication_tag keyword argumentsiv, aad, and tag properties to EncryptResultCryptographyClient will perform all operations locally if initialized with
the .from_jwk factory method
(#16565)six>=1.12.0CryptographyClient can perform AES-CBCPAD encryption and decryption locally
(#17762)These changes do not impact the API of stable versions such as 4.3.1. Only code written against a beta version such as 4.4.0b1 may be affected.
parse_key_vault_key_id and KeyVaultResourceId have been replaced by a
KeyVaultKeyIdentifier class, which can be initialized with a key IDCryptographyClient can perform AES-CBCPAD encryption and decryption locally
CryptographyClient can perform AES-CBCPAD encryption and decryption locally
(#17762)CryptographyClient will perform all operations locally if initialized with the .from_jwk factory method
CryptographyClient will perform all operations locally if initialized with
the .from_jwk factory method
(#16565)API versions older than 7.2-preview no longer raise ImportError when performing async operations
ImportError when
performing async operations (#16680)Key Vault API version 7.2-preview is now the default
oct_hsm to KeyTypeEncryptionAlgorithmKeyWrapAlgorithmCryptographyClient's encrypt method accepts iv and
additional_authenticated_data keyword argumentsCryptographyClient's decrypt method accepts iv,
additional_authenticated_data, and authentication_tag keyword argumentsiv, aad, and tag properties to EncryptResultparse_key_vault_key_id that parses out a full ID returned by
Key Vault, so users can easily access the key's name, vault_url, and version.CryptographyClient operations no longer raise AttributeError when the client was constructed with a key ID
CryptographyClient operations no longer raise AttributeError when
the client was constructed with a key ID
(#15608)CryptographyClient can perform decrypt and sign operations locally
CryptographyClient can perform decrypt and sign operations locally
(#9754)Values of x-ms-keyvault-region and x-ms-keyvault-service-version headers are no longer redacted in logging output
x-ms-keyvault-region and x-ms-keyvault-service-version headers
are no longer redacted in logging outputCryptographyClient will no longer perform encrypt or wrap operations when
its key has expired or is not yet validazure-core version to 1.7.0CustomHookPolicy through the optional
keyword argument custom_hook_policyx-ms-client-request-idazure-common for multiapi supportSupport for Key Vault API version 7.1-preview
import_key to KeyOperationrecoverable_days to CertificatePropertiesApiVersion enum identifying Key Vault versions supported by this packageKeyClient instances have a close method which closes opened sockets. Used as a context manager, a KeyClient closes opened sockets on exit.
azure.keyvault.keys defines __version__
azure.keyvault.keys defines __version__msrest requirement to >=0.6.0KeyVaultErrorException
(#9690)AttributeError in async CryptographyClient when verifying signatures remotely
(#9734)Removed KeyClient.get_cryptography_client() and CryptographyClient.get_key()
KeyClient.get_cryptography_client() and CryptographyClient.get_key()create_key now has positional parameters name and key_typecreate_ec_key and create_rsa_key now have one positional parameter, nameupdate_key_properties now has two positional parameters, name and
(optional) versionimport_key now has positional parameters name and keyCryptographyClient operations return class instances instead of tuples and renamed the following
properties
decrypted_bytes property of DecryptResult to plaintextunwrapped_bytes property of UnwrapResult to keyresult property of VerifyResult to is_validUnwrapKeyResult and WrapKeyResult classes to UnwrapResult and WrapResultlist_keys to list_properties_of_keyslist_key_versions to list_properties_of_key_versionsdelete_key to begin_delete_keybegin_delete_key and async delete_key now return pollers that return a DeletedKeyKey to KeyVaultKeyKeyVaultKey properties created, expires, and updated renamed to created_on,
expires_on, and updated_onvault_endpoint parameter of KeyClient has been renamed to vault_urlvault_endpoint has been renamed to vault_url in all modelsCryptographyClient returns include key_id and algorithm propertiesEnums JsonWebKeyCurveName, JsonWebKeyOperation, and JsonWebKeyType have been renamed to KeyCurveName, KeyOperation, and KeyType, respectively.
Enums JsonWebKeyCurveName, JsonWebKeyOperation, and JsonWebKeyType have
been renamed to KeyCurveName, KeyOperation, and KeyType, respectively.
Key now has attribute properties, which holds certain properties of the
key, such as version. This changes the shape of the returned Key type,
as certain properties of Key (such as version) have to be accessed
through the properties property.
update_key has been renamed to update_key_properties
The vault_url parameter of KeyClient has been renamed to vault_endpoint
The property vault_url has been renamed to vault_endpoint in all models
key argument to import_key should be an instance of azure.keyvault.keys.JsonWebKey
(#7590)CryptographyClient methods wrap and unwrap are renamed wrap_key and unwrap_key, respectively.
CryptographyClient methods wrap and unwrap are renamed wrap_key and
unwrap_key, respectively.CryptographyClient performs encrypt, verify and wrap operations locally
when its key's public material is available (i.e., when it has keys/get
permission).Removed azure.core.Configuration from the public API in preparation for a revamped configuration API. Static create_config methods have been renamed _
azure.core.Configuration from the public API in preparation for a
revamped configuration API. Static create_config methods have been renamed
_create_config, and will be removed in a future release.wrap_key and unwrap_key from KeyClient. These are now available
through CryptographyClient.azure-core 1.0.0b2
pip install azure-core==1.0.0b1 azure-keyvault-keys==4.0.0b1CryptographyClient, a client for performing cryptographic operations
(encrypt/decrypt, wrap/unwrap, sign/verify) with a key.Version 4.0.0b1 is the first preview of our efforts to create a user-friendly and Pythonic client library for Azure Key Vault. For more information ab
Version 4.0.0b1 is the first preview of our efforts to create a user-friendly and Pythonic client library for Azure Key Vault. For more information about preview releases of other Azure SDK libraries, please visit https://aka.ms/azure-sdk-preview1-python.
This library is not a direct replacement for azure-keyvault. Applications
using that library would require code changes to use azure-keyvault-keys.
This package's
documentation
and
samples
demonstrate the new API.
azure-keyvaultazure-keyvault-keys contains a client for key operations,
azure-keyvault-secrets contains a client for secret operationsazure.keyvault.keys.aio namespace contains an async equivalent of
the synchronous client in azure.keyvault.keysazure-identity credentials
azure-keyvault features not implemented in this releaseYour coding agent can read these notes before it upgrades. Set up the MCP server →