NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #483 most downloaded on PyPI
Microsoft Corporation Key Vault Secrets Client Library for Python
Last release 3 days ago
02 Oct 2026
Ships fairly regularly
a new release about every 4 months
Nearly every release is documented
notes for 16 of 16 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
28 releases · first in 2019
Reject request URLs containing backslashes in the authority before authentication.
WWW-Authenticate, without retrying authentication.WWW-Authenticate, returning that response without an authentication retry.
If no newer challenge remains, the next request rediscovers it, which can add an unauthenticated request even when
resource verification is disabled.One column per quarter.
Fixed the challenge authentication policy to cache the authentication challenge only after the challenge resource is verified, so that a rejected chal
Fixed a replay bug in the challenge authentication policy where a request copy stashed on the shared policy instance was never cleared, allowing one r
azure-keyvault-keys and azure-keyvault-administration in
#47742.Added support for service API version 2025-07-01
2025-07-01
out_content_typeprevious_version property to SecretProperties2025-07-01 is now the defaultCode | Docs
Support: Active
Key Vault - Security Domain
azure-keyvault-securitydomain
Added support for service API version 7.6
7.67.6 is now the defaulttyping-extensions version to 4.6.0Added support for service API version 7.6-preview.2
7.6-preview.2typing-extensions version to 4.6.0Added support for Continuous Access Evaluation (CAE). enable_cae=True is passed to all get_token requests.
enable_cae=True is passed to all get_token requests.azure-core version to 1.31.0Added support for service API version 7.5
7.5asyncio is no longer directly referenced by the library
(#33819)azure-core version to 1.29.5azure-common requirementAdded support for service API version 7.5-preview.1
7.5-preview.17.5-preview.1 is now the defaultToken requests made during AD FS authentication no longer specify an erroneous "adfs" tenant ID
Added support for service API version 7.4
7.4send_request method that can be used to send custom requests using the
client's existing pipeline (#25172)7.4 is now the defaultazure-core version to 1.24.0msrest requirementisodate>=0.6.1 (isodate was required by msrest)typing-extensions>=4.0.1Clients verify the challenge resource matches the vault domain. This should affect few customers, who can provide verify_challenge_resource=False to c
verify_challenge_resource=False to client constructors to disable.
See https://aka.ms/azsdk/blog/vault-uri for more information.### Other Changes - Documentation improvements
Port numbers are now preserved in the vault_url property of a KeyVaultSecretIdentifier
vault_url property of a KeyVaultSecretIdentifier
(#24446)Key Vault API version 7.3 is now the default
azure-identity
1.8.0 or newer (#20698)managed property to SecretPropertiesazure-core version to 1.20.0get_token calls during challenge
authentication requests now pass in a tenant_id keyword argument
(#20698). See
https://aka.ms/azsdk/python/identity/tokencredential for more details on how to integrate
this parameter if get_token is implemented by a custom credential.Added managed property to SecretProperties
managed property to SecretPropertiesget_token calls during challenge
authentication requests now pass in a tenant_id keyword argument
(#20698)Added support for multi-tenant authentication when using azure-identity 1.7.1 or newer
azure-identity 1.7.1 or newer
(#20698)azure-core version to 1.15.0Key Vault API version 7.3-preview is now the default
This is the last version to support Python 3.5. The next version will require Python 2.7 or 3.6+.
This is the last version to support Python 3.5. The next version will require Python 2.7 or 3.6+.
msrest version to 0.6.21KeyVaultSecretIdentifier that parses out a full ID returned by Key Vault,
so users can easily access the secret's name, vault_url, and version.Values of x-ms-keyvault-region and x-ms-keyvault-service-version headers are no longer redacted in logging output
x-ms-keyvault-region and x-ms-keyvault-service-version headers
are no longer redacted in logging outputazure-core version to 1.7.0CustomHookPolicy through the optional
keyword argument custom_hook_policyx-ms-client-request-idazure-common for multiapi supportSupport for Key Vault API version 7.1-preview
recoverable_days to CertificatePropertiesApiVersion enum identifying Key Vault versions supported by this packageSecretClient instances have a close method which closes opened sockets. Used as a context manager, a SecretClient closes opened sockets on exit.
azure.keyvault.secrets defines __version__
Moved optional parameters of two methods into kwargs ( docs detail the new keyword arguments):
set_secret now has positional parameters name and valueupdate_secret_properties now has positional parameters name and
(optional) versionlist_secrets to list_properties_of_secretslist_secret_versions to list_properties_of_secret_versionsdelete_secret to begin_delete_secretbegin_delete_secret and async delete_secret now return pollers that return a DeletedSecretSecret to KeyVaultSecretKeyVaultSecret properties created, expires, and updated renamed to created_on,
expires_on, and updated_onvault_endpoint parameter of SecretClient has been renamed to vault_urlvault_endpoint has been renamed to vault_url in all modelsSecret now has attribute properties, which holds certain properties of the secret, such as version. This changes the shape of the returned Secret type
Secret now has attribute properties, which holds certain properties of the
secret, such as version. This changes the shape of the returned Secret type,
as certain properties of Secret (such as version) have to be accessed
through the properties property.
update_secret has been renamed to update_secret_properties
The vault_url parameter of SecretClient has been renamed to vault_endpoint
The property vault_url has been renamed to vault_endpoint in all models
list_secrets and list_secret_versions return the correct typeThis release includes only internal changes.
This release includes only internal changes.
Removed azure.core.Configuration from the public API in preparation for a revamped configuration API. Static create_config methods have been renamed _
azure.core.Configuration from the public API in preparation for a
revamped configuration API. Static create_config methods have been renamed
_create_config, and will be removed in a future release.azure-core 1.0.0b2
pip install azure-core==1.0.0b1 azure-keyvault-secrets==4.0.0b1Version 4.0.0b1 is the first preview of our efforts to create a user-friendly and Pythonic client library for Azure Key Vault. For more information ab
Version 4.0.0b1 is the first preview of our efforts to create a user-friendly and Pythonic client library for Azure Key Vault. For more information about preview releases of other Azure SDK libraries, please visit https://aka.ms/azure-sdk-preview1-python.
This library is not a direct replacement for azure-keyvault. Applications
using that library would require code changes to use azure-keyvault-secrets.
This package's
documentation
and
samples
demonstrate the new API.
azure-keyvaultazure-keyvault-secrets contains a client for secret operations,
azure-keyvault-keys contains a client for key operationsazure.keyvault.secrets.aio namespace contains an async equivalent of
the synchronous client in azure.keyvault.secretsazure-identity credentials
azure-keyvault features not implemented in this libraryYour coding agent can read these notes before it upgrades. Set up the MCP server →