NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #776 most downloaded on PyPI
HashiCorp Vault API client
Last release 11 months ago
30 Oct 2025
Release timing varies
gaps range from 6 weeks to 1.4 years
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
73 releases · first in 2015
add audience param to kubernetes role creation ( GH-1224 )
Thanks to @EmFl, @briantist, @deamen, @dependabot[bot], @evan-cohen, @roshan-baladhanvi and dependabot[bot] for their lovely contributions.
One column per quarter.
Implement the /sys/wrapping/wrap endpoint ( GH-1172 )
Thanks to @briantist, @clealb, @dependabot, @dependabot[bot] and @tot19 for their lovely contributions.
Add new exception types for HTTP status 405 and 412 ( GH-1148 )
iam_metadata and ec2_metadata params (GH-1125)Thanks to @JordanStopford, @briantist, @cognifloyd, @danholodak, @dependabot, @dependabot[bot], @ewanoomen, @loqs, @mweigel, @valleedelisle and @yan12125 for their lovely contributions.
Add support for sys/policies endpoint ( GH-1100 )
Client.write_data - remove potentially dangerous default (GH-1120)Thanks to @Ousret, @briantist, @mweigel and @tot19 for their lovely contributions.
This release makes a number of breaking changes. Most notably, dropping support for Python 3.6 & 3.7, dropping support for Vault versions 1.6.x throug…
This release makes a number of breaking changes. Most notably, dropping support for Python 3.6 & 3.7, dropping support for Vault versions 1.6.x through 1.10.x, and removing previously deprecated methods and code paths. Most of the other breaking changes are fairly minor or only affect specific use cases, but please review all changes carefully.
There are also several other deprecations and announcements to be aware of. We hope to have a more rapid release schedule going forward.
In accordance with our supported Python version policy we will continue to drop Python versions as they become end-of-life. These may not be announced in advance, but will be done in major versions.
Client.write method breaking changes 2.0.0 (GH-1089)sys.initialize parameters secret_shares and secret_threshold (GH-1063)client attributes (GH-1062)session is user-supplied, do not overwrite session options with Client/Adapter options (GH-1021)pyhcl optional again (GH-1060)Client.write method (GH-1034)raise_on_deleted_version will change from True to False in v3.0.0 (GH-955)certificate parameter for create_ca_certificate_role will stop accepting file paths in v3.0.0 (GH-914)sys.initialize parameters secret_shares and secret_threshold (GH-1063)safety_buffer argument in AWS auth (GH-1068)rotate_static_credentials method, docs updates, unit tests (GH-1069)plaintext and ciphertext optional for batch operations (GH-1049)sys.initialize parameters secret_shares and secret_threshold (GH-1063)session is user-supplied, do not overwrite session options with Client/Adapter options (GH-1021)rotate_static_credentials method, docs updates, unit tests (GH-1069)typos linter to CI (GH-1057)Thanks to @Tylerlhess, @amiewei, @briantist, @cibinmathew and @dosisod for their lovely contributions.
This release fixes an inaccuracy in a warning message but does not otherwise change functionality.
This release fixes an inaccuracy in a warning message but does not otherwise change functionality.
Thanks to @briantist and @iTrooz for their lovely contributions.
Breaking changes coming to Client.write method ( GH-1034 )
This is the last expected release before v2.0.0.
configure params by vault api names (GH-975)Client.write method (GH-1034)v2.0.0 (GH-877)MFA class in v2.0.0 (GH-1026)Client.write_data method (GH-1028)configure params by vault api names (GH-975)disable_local_ca_jwt in the Kubernetes auth method (GH-997)Client.write_data method (GH-1028)sys.take_raft_snapshot method (GH-771)__getattr__): non-existent attribute lookup (GH-982)Thanks to @M0NsTeRRR, @amiewei, @briantist, @ceesios, @crimsonvulture, @deidax, @dekimsey, @dependabot, @dependabot[bot], @fad3t, @ferenc-hechler, @intgr, @m4dh4t, @michael-diggin, @mimato, @mweigel and @robbat2 for their lovely contributions.
fix wrapped response for auth.token.create ( GH-966 )
auth.token.create (GH-966)Thanks to @briantist for their lovely contributions.
Remove deprecated python syntax ( GH-909 )
v3.0.0 - The certificate parameter for create_ca_certificate_role will stop accepting file paths (GH-914)hvac intends to drop support for EoL Python versions (GH-877)v3.0.0 - The default value of raise_on_deleted_version will change from True to False (GH-955)generate_credentials for STS endpoint (GH-934)auto_rotate_period on transit key management (GH-903)wrap_ttl (GH-782)generate_credentials for STS endpoint (GH-934)Thanks to @BrandonHoffman, @Prividen, @WilkenSteiner, @aberenshtein, @adammike, @bendem, @briantist, @colin-pm, @dereckson, @dhuckins, @gmsantos, @jackcasey-visier, @localden, @nneul, @rhowe and @sebglon for their lovely contributions.
Update dependencies. GH-897
Add role_name parameter to auth.token.create_orphan. GH-891
role_name parameter to auth.token.create_orphan. GH-891Remove deprecated methods. GH-868
Breakfix release to revert some unintended post-1.0 requirements changes.
Breakfix release to revert some unintended post-1.0 requirements changes.
six & requests Requirements Changes . GH-768Note: This is _actually and truly_ (😝) intended to by the last hvac release supporting Python 2.7.
Note: This is actually and truly (😝) intended to by the last hvac release supporting Python 2.7.
Starting with hvac version 1.0.0, Python versions >=3.6 will be the only explictly supported versions.
Requirements - Cleanup & Upgrades (install_requires => requests>=2.25.1 ). GH-741
use_token param. GH-746cert Parameter From Client into Adapter Class. GH-743verify Behavior . GH-745Thanks to @Tylerlhess, @anhdat, @ayav09, @bobmshannon, @bpatterson971, @briantist, @cmanfre4, @jeffwecan, Chris Manfre and tyhess for their lovely contributions..
Add deprecation notices for Client() k8s methods. GH-732
Note: This is intended to by the last hvac release supporting Python 2.7.
Starting with hvac version 1.0.0, Python versions >=3.6 will be the only explicitly supported versions.
Userpass: Add use_token param on login(), Accept passthrough **kwargs on create user . GH-733
create_or_update_user(). GH-714token_ttl & token_max_ttl Arguments to ldap.configure(). GH-707Client() k8s methods. GH-732Client() approle methods. GH-731Client() Methods. GH-730python_requires='>=2.7' to setuptools Metadata. GH-727black Formatting + Updated PR Actions Workflow. GH-726Thanks to @el-deano, @intgr, @jeffwecan, @pjaudiomv, @tp6783 and tyhess for their lovely contributions.
Python 2.7: Drop Trailing Comma In Cert.login(). GH-712
Cert.login(). GH-712Refactor Cert.login() Conditional for Python 2.7 Syntax Support. GH-708
Cert.login() Conditional for Python 2.7 Syntax Support. GH-708Thanks to @jeffwecan for their lovely contributions.
Add default to group_type argument in update_group and create_or_update_group_by_name. GH-703
group_type argument in update_group and create_or_update_group_by_name. GH-703Thanks to @Tylerlhess, @jeffwecan, @matusf, @mblau-leaffilter and tyhess for their lovely contributions.
Expand Transform class to include new(ish) tokenization methods. GH-696
delete_version_after KvV2 Param - configure() / `update_metadata(). GH-694Thanks to @jeffwecan for their lovely contributions.
Set daemon attribute instead of using setDaemon method that was deprecated in Python 3.10. GH-688
policies Parameter to Userpass create_or_update_user() Method. GH-562read_secret() Method for KVv2 Class. GH-686Thanks to @jeffwecan, @mblau-leaffilter, @nicholaswold, @sshishov, @tirkarthi, @tomwerneruk and @vamshideveloper for their lovely contributions.
Send AppRole generate_secret_id Method Metadata Parameter as String. GH-680
Thanks to @JPoser, @fhemberger, @jeffwecan, @lperdereau and jposer for their lovely contributions.
K8s Auth: Allow wildcards for service account and namespace. GH-669
Thanks to @blag, @devlounge, @jeffwecan and @jonZlotnik for their lovely contributions.
Support database secrets static roles. GH-662
Thanks to @jeffwecan, @krish7919 and Krish for their lovely contributions.
Enable response wrapping of PKI secrets. GH-649
Thanks to @Angeall, @JJCella, @briantist, @derBroBro, @discogestalt, @dogfish182, @el-deano, @ghTravis, @godara01, @jeffwecan, @leongyh, @phickey, @tienthanh2509, @tmcolby and @trixpan for their lovely contributions.
Add JWT/OIDC Authentication Method Classes. GH-613
Thanks to @akdor1154, @jeffwecan, @ns-jshilkaitis and @trishankatdatadog for their lovely contributions.
Extract "renew_self_token" from "renew_token". GH-598
Thanks to @jeffwecan, @jm96441n and @pnijhara for their lovely contributions.
Add Support For use_token_groups In LDAP Auth Method. GH-591
Thanks to @finarfin and @jeffwecan for their lovely contributions.
Add vault rekey verification methods. GH-586
Thanks to @TerryHowe, @and-semakin, @jeffwecan, @jschlyter, @jzck, @mdelaney and @scarabeusiv for their lovely contributions.
Make returned responses more consistent. GH-537
Note: GH-537 changes some methods' return types from None to a request.Response
instance. For instance the client.secrets.identity.lookup_entity now returns a Response[204] (truthy) value instead of
None (falsy) when the lookup returns no results.
This change was made to simplify maintenance of response parsing within the hvac code base.
Thanks to @jeffwecan, @llamasoft and @msuszko for their lovely contributions.
Retained argument position to prevent being a breaking change
Note: GH-533 includes fundamental behavior involving sending parameters to API requests to Vault. Many hvac method parameters that would have been sent with default arguments no longer are included in requests to Vault. Notably, the following behavioral changes should be expected (copied from the related PR comments):
Azure:
create_role parameter policies now accepts CSV string or list of stringsDatabase:
create_role documentation updated to something meaningful 🙃GCP:
configure parameter google_certs_endpoint is deprecatedcreate_role parameter project_id is deprecated by bound_projects (list)GitHub:
configure is missing a lot of parametersLDAP:
configure parameters user_dn and group_dn made optional
hvac/constants/ldap.py file removed as it is no longer usedMFA:
Okta:
configure parameter base_url default value now differs from API documentation
register_user, read_user, and delete_user duplicate URL parameter username in JSON payload
delete_group, but register_group and list_group correctly omit itPKI:
sign_data and verify_signed_data optional parameter marshaling_algorithm addedRADIUS:
configure is missing a lot of parametersregister_user attempted to convert username string into a CSV list (?!) for POST data
username is extracted from URL path in Vault serverregister_user parameter policies never actually passed as parameterSystem Backend:
enable_auth_method parameter plugin_name is deprecatedenable_audit_device optional parameter local was addedinitialize provides default for required API parameters secret_shares and secret_thresholdstart_root_token_generation parameter otp is deprecatedMisc:
**kwargs (e.g. hvac/api/system_backend/auth.py)*args and **kwargs (e.g. hvac/api/secrets_engines/active_directory.py)hvac/api/secrets_engines/pki.py uses extra_params={}hvac/api/auth_methods/ldap.py configure uses user_dn instead of userdnhvac/api/system_backend/auth.py configure uses method_type instead of typettl, max_ttl, policies, period, num_uses and a few other fields are deprecated as of Vault version 1.2.0
Thanks to @findmyname666, @llamasoft, @moisesguimaraes, @philherbert and Adrian Eib for their lovely contributions.
Added userpass auth method. GH-519
Thanks to @DaveDeCaprio, @Dowwie, @drewmullen, @jeffwecan, @llamasoft and @vamshideveloper for their lovely contributions.
Add Active Directory Secrets Engine Support. GH-508
Thanks to @jeffwecan and @vamshideveloper for their lovely contributions.
Add delete_namespace Method and Establish Namespace Documentation. GH-500
Thanks to @Tylerlhess, @drewmullen and @jeffwecan for their lovely contributions.
Add Create and List Namespace System Backend Methods. GH-489
generate_credentials request method to GET. GH-475Thanks to @donjar, @fhemberger, @jeffwecan, @stevefranks and @stevenmanton for their lovely contributions.
Fix kubernetes auth method list roles method. GH-466
BUG FIXES:
IMPROVEMENTS:
enable_auth_method(), tune_auth_method(), enable_secrets_engine(), tune_mount_configuration() system backend method now take arbitrary **kwargs parameters to provide greater support for variations in accepted parameters in the underlying Vault plugins.num_uses, change bound_location -> bound_locations and bound_resource_group_names -> bound_resource_groups. GH-452MISCELLANEOUS:
Thanks to @denisvll, @Dudesons, and @drewmullen for their lovely contributions.
Support for the PKI secrets engine. GH-436
Update path to azure.login() GH-429
BUG FIXES:
IMPROVEMENTS:
MISCELLANEOUS:
Thanks to @paulcaskey, @stevenmanton, @brad-alexander, @yoyomeng2, @JadeHayes, @Dudesons for their lovely contributions.
Fix priority of client url and VAULT_ADDR environment variable. GH-423
Fix initialize() method recovery_shares and recovery_threshold parameter validation regression. GH-416
BUG FIXES:
initialize() method recovery_shares and recovery_threshold parameter validation regression. GH-416BACKWARDS COMPATIBILITY NOTICE:
BACKWARDS COMPATIBILITY NOTICE:
Client() class constructor now behaves similarly to Vault CLI in that it uses the VAULT_ADDR environmental variable for the Client URL when that variable is set. Along the same lines, when no token is passed into the Client() constructor, it will attempt to load a token from the VAULT_TOKEN environmental variable or the ~/.vault-token file where available. GH-411IMPROVEMENTS:
BUG FIXES:
recovery_threshold and recovery_shares during initialization. GH-398generate_credentials() method. GH-403n_bytes -> bytes) for Transit secrets engine generate_random_bytes() method. GH-377Thanks to @engstrom, @viralpoetry, @bootswithdefer, @steved, @kserrano, @spbsoluble, @uepoch, @singuliere, @frgaudet, @jsporna, & @mrsiesta for their lovely contributions.
Support for the AWS secrets engine. GH-370
Support for the Okta auth method. GH-341
IMPROVEMENTS:
BUG FIXES:
Adapter class to fix issues following location headers with fully qualified URLs. Note: hvac now converts // to / within any paths. GH-348read_health_status() system backend method can be retrieved without exceptions being raised. GH-347read_seal_status() in Client class's seal_status property. GH-354DOCUMENTATION UPDATES:
login() call with google-api-python-client usage added: Example with google-api-python-client Usage. GH-350MISCELLANEOUS:
develop is the main integration branch for the hvac project. The master branch is now intended to capture the state of the most recent release.create_or_update_policy system backend method now supports a "pretty_print" argument for different JSON formatting. This allows create more viewable policy documents when retrieve existing policies (e.g., from within the Vault UI interface). GH-342All auth method classes are now accessible under the auth property on the hvac.Client class. GH-310. (E.g. the github, ldap, and mfa Client properties
DEPRECATION NOTICES:
auth property on the hvac.Client class. GH-310. (E.g. the github, ldap, and mfa Client properties' methods are now accessible under Client.auth.github, etc.)secrets property on the hvac.Client class. GH-311 (E.g. the kv, Client property's methods are now accessible under Client.secrets.kv)sys property on the hvac.Client class. GH-314 ([GH-314] through [GH-325]) E.g. methods such as enable_secret_backend() under the Client class are now accessible under Client.sys.enable_secrets_engine(), etc.IMPROVEMENTS:
Thanks to @tiny-dancer, @jacquat, @deejay1, @MJ111, @jasonarewhy, and @alexandernst for their lovely contributions.
New KV secret engine-related classes added. See the KV documentation under hvac's readthedocs.io site for usage / examples. GH-257 / GH-260
IMPROVEMENTS:
MISCELLANEOUS:
Client.renew_token method. GH-250Client.get_policy method. GH-254config and plugin_name parameters added to the Client.enable_auth_backend method. GH-253Thanks to @ijl, @rastut, @seuf, @downeast for their lovely contributions.
The auth_github() method within the hvac.Client class has been marked as deprecated and will be removed in hvac v0.8.0 (or later). Please update any c…
DEPRECATION NOTICES:
auth_github() method within the hvac.Client class has been marked as deprecated and will be removed in hvac v0.8.0 (or later). Please update any callers of this method to use the hvac.Client.github.login() instead.auth_ldap() method within the hvac.Client class has been marked as deprecated and will be removed in hvac v0.8.0 (or later). Please update any callers of this method to use the hvac.Client.ldap.login() instead.IMPROVEMENTS:
auth_aws_iam() method updated to include "region" parameter for deployments in different AWS regions. GH-243DOCUMENTATION UPDATES:
Client class to leverage self-signed certificates / private CA bundles has been added at: Making Use of Private CA. GH-230verify Client parameter corrected and expanded. GH-238MISCELLANEOUS:
Thanks to @otakup0pe, @FabianFrank, @andrewheald for their lovely contributions.
BACKWARDS COMPATIBILITY NOTICE:
BACKWARDS COMPATIBILITY NOTICE:
hvac.adapters.Request class, request kwargs can no longer be directly modified via the _kwargs attribute on the Client class. If runtime modifications to this dictionary are required, callers either need to explicitly pass in a new adapter instance with the desired settings via the adapter propery on the Client class or access the _kwargs property via the adapter property on the Client class.See the Advanced Usage section of this module's documentation for additional details.
IMPROVEMENTS:
tune_secret_backend() parameters now accepted. GH-215read_lease() method GH-218Request class to abstract HTTP requests away from the Client class. GH-223Thanks to @bbayszczak, @jvanbrunschot-coolblue for their lovely contributions.
Update unwrap() method to match current Vault versions [GH-149]
IMPROVEMENTS:
unwrap() method to match current Vault versions [GH-149]BUG FIXES:
https://example.com/vault) [GH-212].Thanks to @mracter, @cdsf, @SiN, @seanmalloy, for their lovely contributions.
BACKWARDS COMPATIBILITY NOTICE:
BACKWARDS COMPATIBILITY NOTICE:
IMPROVEMENTS:
BUG FIXES:
Thanks to @freimer, @ramiamar, @marcoslopes, @ianwestcott, @marc-sensenich, @sunghyun-lee, @jnaulty, @sijis, @Myles-Steinhauser-Bose, @oxmane, @ltm, @bchannak, @tkinz27, @crmulliner, for their lovely contributions.
Added disallowed_policies parameter to create_token_role method [GH-169]
IMPROVEMENTS:
disallowed_policies parameter to create_token_role method [GH-169]Thanks to @morganda for their lovely contribution.
Add support for the period parameter on token creation [GH-167]
IMPROVEMENTS:
period parameter on token creation [GH-167]cidr_list parameter for approle secrets [GH-114]BUG FIXES:
Thanks to @ti-mo, @dhoeric, @RAbraham, @lhdumittan, @ahsanali for their lovely contributions.
This is just the highlights, there have been a bunch of changes!
This is just the highlights, there have been a bunch of changes!
IMPROVEVEMENTS:
BUG FIXES
Thanks to @ianwestcott, @s3u, @mracter, @intgr, @jkdihenkar, @gaelL, @henriquegemignani, @bfeeser, @nicr9, @mwielgoszewski, @mtougeron for their contributions!
Add support for Python 2.6 [GH-92]
IMPROVEMENTS:
BUG FIXES:
Thanks to @otakup0pe, @nicr9, @marcoslopes, @caiotomazelli, and @blarghmatey for their contributions!
Thanks to @otakup0pe, @nicr9, @marcoslopes, @caiotomazelli, and @blarghmatey for their contributions!
IMPROVEMENTS:
BUG FIXES:
no_default_policy parameter in create_token [GH-65]Thanks to @blarghmatey, @stevenmanton, and @ahlinc for their contributions!
Thanks to @blarghmatey, @stevenmanton, and @ahlinc for their contributions!
IMPROVEMENTS:
create_userpass [GH-60]BUG FIXES:
is_authenticated now handles new error type for Vault 0.6.0Fix improper URL being used when leader redirection occurs [GH-56]
BUG FIXES:
Add support for Requests sessions [GH-53]
IMPROVEMENTS:
BUG FIXES:
Add support for increment in renewel of secret [GH-48]
IMPROVEMENTS:
increment in renewel of secret [GH-48]BUG FIXES:
Nothing published for this version
Add support for list operation [GH-47]
IMPROVEMENTS:
Add support for nonce during rekey operation [GH-42]
IMPROVEMENTS:
Your coding agent can read these notes before it upgrades. Set up the MCP server →