NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #191 most downloaded on PyPI
Store and access your passwords safely.
Last release 10 months ago
16 Nov 2025
Release timing varies
gaps range from 9 days to 11 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
17 years old
203 releases · first in 2009
Improved support for KWallet 6.
Improved support for KWallet 6. (#728)
Removed cruft from Python 3.8. (#722)
Avoid logging a warning when config does not specify a backend.
Avoid logging a warning when config does not specify a backend. (#682)
When parsing keyring_path from the config, the home directory is now expanded from ~.
One column per quarter.
When parsing keyring_path from the config, the home directory is now expanded from ~. (#696)
In get_credential, now returns None when the indicated username is not found. (#698)
Fixed ValueError for AnonymousCredentials in CLI.
Fixed ValueError for AnonymousCredentials in CLI. (#694)
Refined type spec and interfaces on credential objects. Introduced AnonymousCredential to model a secret without a username.
Refined type spec and interfaces on credential objects. Introduced AnonymousCredential to model a secret without a username. (#689)
Deprecated support for empty usernames. Now all backends will reject an empty string as input for the 'username' field when setting a password. Later…
Deprecated support for empty usernames. Now all backends will reject an empty string as input for the 'username' field when setting a password. Later this deprecation will become a more visible user warning and even later an error. If this warning is triggered in your environment, please consider using a static value (even 'username') or comment in the issue and describe the use-case that demands support for empty usernames. (#668)
Bugfixes -------- - Fix typo in CLI creds mode.
Fix typo in CLI creds mode. (#681)
Added options for 'keyring get' command to support credential retrieval and emit as JSON.
Added options for 'keyring get' command to support credential retrieval and emit as JSON. (#678)
Replace ExceptionRaisedContext with ExceptionTrap.
Replace ExceptionRaisedContext with ExceptionTrap.
When completion is unavailable, exit with non-zero status and emit message to stderr.
When completion is unavailable, exit with non-zero status and emit message to stderr. (#671)
Removed check for config in XDG_DATA_HOME on Linux systems.
Removed check for config in XDG_DATA_HOME on Linux systems. (#99)
In platform config support, remove support for Windows XP, now 10 years sunset.
Minor fixes to account for emergent typing and linter concerns.
Minor fixes to account for emergent typing and linter concerns.
Features -------- - Added bash completion support.
Added bash completion support. (#643)
Features -------- - Require Python 3.8 or later.
Require Python 3.8 or later.
Restore support for reading from a config file (with regression test).
Restore support for reading from a config file (with regression test). (#638)
Avoid logging warning when no config file is present.
Avoid logging warning when no config file is present. (#635)
Include all operations in the error message if no operation was supplied. (#636)
Correct name of macOS backend in README. (#637)
Misc ---- -
* #633: Added diagnose command with basic support. * #487: Removed keyring.backends.OS_X module. * #593: Removed keyring.util.properties module.
#633: Added diagnose command with basic support.
#487: Removed keyring.backends.OS_X module.
#593: Removed keyring.util.properties module.
* #573: Fixed failure in macOS backend when attempting to set a password after previously setting a blank password, including a test applying to all b
#573: Fixed failure in macOS backend when attempting to set a password after previously setting a blank password, including a test applying to all backends.
* #608: Added support for tab completion on the keyring command if the completion extra is installed (keyring[completion]).
#608: Added support for tab completion on the keyring command if the completion extra is installed (keyring[completion]).
* #612: Prevent installation of pywin32-ctypes 0.1.2 with broken use2to3 directive.
#612: Prevent installation of pywin32-ctypes 0.1.2 with broken use2to3 directive.
* #603: In libsecret, check that the service is available before declaring viability.
#603: In libsecret, check that the service is available before declaring viability.
* #526: Bump requirement on importlib_metadata to pull in fix for improperly-normalized names on egg-info.
#526: Bump requirement on importlib_metadata to pull in fix for improperly-normalized names on egg-info.
* #596: Add workaround for devpi_client hook with wrapped implementation.
#596: Add workaround for devpi_client hook with wrapped implementation.
* #597: Fixed wrong name in compatibility logic for properties (masked by the compatibility fallback).
#597: Fixed wrong name in compatibility logic for properties (masked by the compatibility fallback).
* #593: Restore keyring.util.properties with deprecation warning for backward compatibility.
#593: Restore keyring.util.properties with deprecation warning for backward compatibility.
* #588: Project now depends on jaraco.classes for class property support.
#588: Project now depends on jaraco.classes for class property support.
* #581: Corrected regression in libsecret tests (.collection property).
#581: Corrected regression in libsecret tests (.collection property).
* #587: Fix regression in libsecret.
#587: Fix regression in libsecret.
.with_keychain method on macOS is superseded by .with_properties and so is now deprecated.
#448: SecretService and libsecret backends now support a new SelectableScheme, allowing the keys for "username" and "service" to be overridden for compatibility with other schemes such as KeePassXC.
Introduced a new .with_properties method on backends to produce a new keyring with different properties. Use for example to get a keyring with a different keychain (macOS) or scheme (SecretService/libsecret). e.g.:
keypass = keyring.get_keyring().with_properties(scheme='KeePassXC')
.with_keychain method on macOS is superseded by .with_properties and so is now deprecated.
* #582: Suppress KeyringErrors for devpi client.
#582: Suppress KeyringErrors for devpi client.
* #575: Only require importlib_metadata on older Pythons. * #579: Add .with_keychain method on macOS for easy reference to alternate keychains.
#575: Only require importlib_metadata on older Pythons.
#579: Add .with_keychain method on macOS for easy reference to alternate keychains.
The correct config root is now used on Windows.
The correct config root is now used on Windows.
* Require Python 3.7 or later.
Require Python 3.7 or later.
* #551: Fixed docs warnings.
#551: Fixed docs warnings.
* #549: EnvironCredential now allows for equality comparison.
#549: EnvironCredential now allows for equality comparison.
* #529: macOS backend is no longer viable if the API module cannot be loaded. Prevents "symbol not found" errors on macOS 11 (Big Sur) and later when
#529: macOS backend is no longer viable if the API module cannot be loaded. Prevents "symbol not found" errors on macOS 11 (Big Sur) and later when a "universal2" binary is not used (available for Python 3.8.7 and later).
#547: Tests no longer attempt to run macOS backends even on macOS when the backend is non-viable.
#542: Change get_credential to return generic Credential.
* #530: In libsecret tests, use a session collection to allow tests to pass on Debian.
#530: In libsecret tests, use a session collection to allow tests to pass on Debian.
* #521: Add libsecret backend.
#521: Add libsecret backend.
* #519: macOS backend APIs updated to newer, non-legacy APIs.
#519: macOS backend APIs updated to newer, non-legacy APIs.
* #504: Better error with invalid parameter to init_keyring. * #505: Nicer documentation for headless Docker.
#504: Better error with invalid parameter to init_keyring.
#505: Nicer documentation for headless Docker.
Backends now all invoke set_properties_from_env on self in the initializer. Derived backends should be sure to invoke super().__init__().
Backends now all invoke set_properties_from_env on self in the initializer. Derived backends should be sure to invoke super().__init__().
Use new entry points API from importlib_metadata 3.6.
Use new entry points API from importlib_metadata 3.6.
Added redundant type declarations for accessor functions in keyring.core.
Added redundant type declarations for accessor functions in keyring.core.
* #487: Restored Keyring in OS_X module with deprecation warning for users specifying the backend by name.
#487: Restored Keyring in OS_X module with deprecation warning for users specifying the backend by name.
Added type declaration for keyring.core.get_keyring().
Added type declaration for keyring.core.get_keyring().
* #486: Restored keyring.backends.OS_X module (with no functionality) to mask errors when older keyring versions are present until underlying issue is
#486: Restored keyring.backends.OS_X module (with no functionality) to mask errors when older keyring versions are present until underlying issue is addressed and available in importlib_metadata.
Renamed macOS backend from OS_X to macOS. Any users specifying the backend by name will need to use the new name keyring.backends.macOS.
Renamed macOS backend from OS_X to macOS. Any users specifying the backend by name will need to use the new name keyring.backends.macOS.
* #438: For better interoperability with other applications, Windows backend now attempts to decode passwords using UTF-8 if UTF-16 decoding fails. Pa
#438: For better interoperability with other applications, Windows backend now attempts to decode passwords using UTF-8 if UTF-16 decoding fails. Passwords are still stored as UTF-16.
* #437: Package now declares typing support.
#437: Package now declares typing support.
* #403: Keyring no longer eagerly initializes the backend on import, but instead defers the backend initialization until a keyring is accessed. Any ca
#403: Keyring no longer eagerly initializes the backend on import, but instead defers the backend initialization until a keyring is accessed. Any callers reliant on this early initialization behavior may need to call keyring.core.init_backend() to explicitly initialize the detected backend.
* #474: SecretService and KWallet backends are now disabled if the relevant names are not available on D-Bus. Keyring should now be much more responsi
#474: SecretService and KWallet backends are now disabled if the relevant names are not available on D-Bus. Keyring should now be much more responsive in these environments.
#463: Fixed regression in KWallet get_credential where a simple string was returned instead of a SimpleCredential.
* #431: KWallet backend now supports get_credential.
#431: KWallet backend now supports get_credential.
* #445: Suppress errors when sys.argv is not a list of at least one element.
#445: Suppress errors when sys.argv is not a list of at least one element.
* #440: Keyring now honors XDG_CONFIG_HOME as ~/.config. * #452: SecretService get_credential now returns None for unmatched query.
#440: Keyring now honors XDG_CONFIG_HOME as ~/.config.
#452: SecretService get_credential now returns None for unmatched query.
* #426: Restored lenience on startup when entry point metadata is missing. * #423: Avoid RecursionError when initializing backends when a limit is sup
#426: Restored lenience on startup when entry point metadata is missing.
#423: Avoid RecursionError when initializing backends when a limit is supplied.
* #372: Chainer now deterministically resolves at a lower priority than the Fail keyring (when there are no backends to chain). * #372: Fail keyring n
#372: Chainer now deterministically resolves at a lower priority than the Fail keyring (when there are no backends to chain).
#372: Fail keyring now raises a NoKeyringError for easier selectability.
#405: Keyring now logs at DEBUG rather than INFO during backend startup.
* Refreshed package metadata.
Refreshed package metadata.
* #380: In SecretService backend, close connections after using them.
#380: In SecretService backend, close connections after using them.
* Require Python 3.6 or later.
Require Python 3.6 or later.
Your coding agent can read these notes before it upgrades. Set up the MCP server →