NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #189 most downloaded on PyPI
Store and access your passwords safely.
Last release 10 months ago
16 Nov 2025
Release timing varies
gaps range from 9 days to 11 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
17 years old
203 releases · first in 2009
* #417: Fix TypeError when backend fails to initialize.
#417: Fix TypeError when backend fails to initialize.
Extracted keyring.testing package to contain supporting functionality for plugin backends. keyring.tests has been removed from the package.
Extracted keyring.testing package to contain supporting functionality for plugin backends. keyring.tests has been removed from the package.
One column per quarter.
Switch to importlib.metadata _ for loading entry points. Removes one dependency on Python 3.8.
Switch to importlib.metadata for loading entry points. Removes one dependency on Python 3.8.
Added new KeyringBackend.set_properties_from_env.
#382: Add support for alternate persistence scopes for Windows backend. Set .persist to "local machine" or "session" to enable the alternate scopes or "enterprise" to use the default scope.
#404: Improve import times when a backend is specifically configured by lazily calling get_all_keyring.
Add support for get_credential() with the SecretService backend.
Add support for get_credential() with the SecretService backend.
* #369: macOS Keyring now honors a KEYCHAIN_PATH environment variable. If set, Keyring will use that keychain instead of the default.
#369: macOS Keyring now honors a KEYCHAIN_PATH environment variable. If set, Keyring will use that keychain instead of the default.
* Refresh package skeleton. * Adopt black _ code style.
Refresh package skeleton.
Adopt black code style.
* Merge with 18.0.1.
Merge with 18.0.1.
* #383: Drop support for EOL Python 2.7 - 3.4.
#383: Drop support for EOL Python 2.7 - 3.4.
* #386: ExceptionInfo no longer retains a reference to the traceback.
#386: ExceptionInfo no longer retains a reference to the traceback.
* #375: On macOS, the backend now raises a KeyringLocked when access to the keyring is denied (on get or set) instead of PasswordSetError or KeyringEr
#375: On macOS, the backend now raises a KeyringLocked when access to the keyring is denied (on get or set) instead of PasswordSetError or KeyringError. Any API users may need to account for this change, probably by catching the parent KeyringError. Additionally, the error message from the underlying error is now included in any errors that occur.
* #368: Update packaging technique to avoid 0.0.0 releases.
#368: Update packaging technique to avoid 0.0.0 releases.
* #366: When calling keyring.core.init_backend, if any limit function is supplied, it is saved and later honored by the ChainerBackend as well.
#366: When calling keyring.core.init_backend, if any limit function is supplied, it is saved and later honored by the ChainerBackend as well.
* #345: Remove application attribute from stored passwords using SecretService, addressing regression introduced in 10.5.0 (#292). Impacted Linux keyr
#345: Remove application attribute from stored passwords using SecretService, addressing regression introduced in 10.5.0 (#292). Impacted Linux keyrings will once again prompt for a password for "Python program".
* #362: Fix error on import due to circular imports on Python 3.4.
#362: Fix error on import due to circular imports on Python 3.4.
Refactor ChainerBackend, introduced in 16.0 to function as any other backend, activating when relevant.
Refactor ChainerBackend, introduced in 16.0 to function as any other backend, activating when relevant.
* #319: In Windows backend, trap all exceptions when attempting to import pywin32.
#319: In Windows backend, trap all exceptions when attempting to import pywin32.
* #357: Once again allow all positive, non-zero priority keyrings to participate.
#357: Once again allow all positive, non-zero priority keyrings to participate.
* #323: Fix race condition in delete_password on Windows. * #352: All suitable backends (priority 1 and greater) are allowed to participate.
#323: Fix race condition in delete_password on Windows.
#352: All suitable backends (priority 1 and greater) are allowed to participate.
* #350: Added new API for get_credentials, for backends that can resolve both a username and password for a service.
#350: Added new API for get_credentials, for backends that can resolve both a username and password for a service.
* #340: Add the Null keyring, disabled by default. * #340: Added --disable option to command-line interface. * #340: Now honor a PYTHON_KEYRING_BACKEN
#340: Add the Null keyring, disabled by default.
#340: Added --disable option to command-line interface.
#340: Now honor a PYTHON_KEYRING_BACKEND environment variable to select a backend. Environments may set to keyring.backends.null.Keyring to disable keyring.
Removed deprecated keyring.util.escape module.
Removed deprecated keyring.util.escape module.
Fixed warning about using deprecated Abstract Base Classes from collections module.
* #335: Fix regression in command line client.
#335: Fix regression in command line client.
Keyring command-line interface now reads the password directly from stdin if stdin is connected to a pipe.
Keyring command-line interface now reads the password directly from stdin if stdin is connected to a pipe.
* #329: Improve output of keyring --list-backends.
#329: Improve output of keyring --list-backends.
* #327: In kwallet backend, if the collection or item is locked, a KeyringLocked exception is raised. Clients expecting a None response from get_passw
#327: In kwallet backend, if the collection or item is locked, a KeyringLocked exception is raised. Clients expecting a None response from get_password under this condition will need to catch this exception. Additionally, an InitError is now raised if the connection cannot be established to the DBus.
#298: In kwallet backend, when checking an existing handle, verify that it is still valid or create a new connection.
Fixed issue in SecretService. Ref #226.
Fixed issue in SecretService. Ref #226.
Deprecated keyring.util.escape module. If you use this module or encounter the warning (on the latest release of your packages), please file a ticket…
#322: Fix AttributeError when escape.__builtins__ is a dict.
Deprecated keyring.util.escape module. If you use this module or encounter the warning (on the latest release of your packages), please file a ticket.
Unpin SecretStorage on Python 3.5+. Requires that Setuptools 17.1 be used. Note that the special handling will be unnecessary once Pip 9 can be assume
Unpin SecretStorage on Python 3.5+. Requires that Setuptools 17.1 be used. Note that the special handling will be unnecessary once Pip 9 can be assumed (as it will exclude SecretStorage 3 in non-viable environments).
* Pin SecretStorage to 2.x.
Pin SecretStorage to 2.x.
* #314: No changes except to rebuild.
#314: No changes except to rebuild.
For most users, this release will be fully compatible. Some users may experience compatibility issues if entrypoints is not installed (as declared) or
#310: Keyring now loads all backends through entry points.
For most users, this release will be fully compatible. Some users may experience compatibility issues if entrypoints is not installed (as declared) or the metadata on which entrypoints relies is unavailable. For that reason, the package is released with a major version bump.
* #312: Use entrypoints instead of pkg_resources to avoid performance hit loading pkg_resources. Adds a dependency on entrypoints.
#312: Use entrypoints instead of pkg_resources to avoid performance hit loading pkg_resources. Adds a dependency on entrypoints.
* #294: No longer expose keyring.__version__ (added in 8.1) to avoid performance hit loading pkg_resources.
#294: No longer expose keyring.__version__ (added in 8.1) to avoid performance hit loading pkg_resources.
* #299: Keyring exceptions are now derived from a base keyring.errors.KeyringError.
#299: Keyring exceptions are now derived from a base keyring.errors.KeyringError.
* #296: Prevent AttributeError on import when Debian has created broken dbus installs.
#296: Prevent AttributeError on import when Debian has created broken dbus installs.
Removed logger from keyring. See #291 for related request.
#287: Added --list-backends option to command-line interface.
Removed logger from keyring. See #291 for related request.
#292: Set the appid for SecretService & KWallet to something meaningful.
* #279: In Kwallet, pass mainloop to SessionBus. * #278: Unpin pywin32-ctypes, but blacklist known incompatible versions.
#279: In Kwallet, pass mainloop to SessionBus.
#278: Unpin pywin32-ctypes, but blacklist known incompatible versions.
* #278: Pin to pywin32-ctypes 0.0.1 to avoid apparent breakage introduced in 0.1.0.
#278: Pin to pywin32-ctypes 0.0.1 to avoid apparent breakage introduced in 0.1.0.
* #267: More leniently unescape lowercased characters as they get re-cased by ConfigParser.
#267: More leniently unescape lowercased characters as they get re-cased by ConfigParser.
* #266: Use private compatibility model rather than six to avoid the dependency.
#266: Use private compatibility model rather than six to avoid the dependency.
* #264: Implement devpi hook for supplying a password when logging in with devpi _ client. * #260: For macOS, added initial API support for internet p
#264: Implement devpi hook for supplying a password when logging in with devpi client.
#260: For macOS, added initial API support for internet passwords.
* #259: Allow to set a custom application attribute for SecretService backend.
#259: Allow to set a custom application attribute for SecretService backend.
* #253: Backends now expose a '.name' attribute suitable for identifying each backend to users.
#253: Backends now expose a '.name' attribute suitable for identifying each backend to users.
* #247: Restored console script.
#247: Restored console script.
Update readme to reflect test recommendations.
Update readme to reflect test recommendations.
Test suite now uses tox instead of pytest-runner. Test requirements are now defined in tests/requirements.txt.
Drop support for Python 3.2.
Test suite now uses tox instead of pytest-runner. Test requirements are now defined in tests/requirements.txt.
Link to the new Gitter chat room is now in the readme.
Link to the new Gitter chat room is now in the readme.
Issue #235: kwallet backend now returns string objects instead of dbus.String objects, for less surprising reprs.
Minor doc fixes.
Issue #161: In SecretService backend, unlock individual entries.
Issue #161: In SecretService backend, unlock individual entries.
Issue #230: Don't rely on dbus-python and instead defer to SecretStorage to describe the installation requirements.
Issue #230: Don't rely on dbus-python and instead defer to SecretStorage to describe the installation requirements.
Issue #231 via #233: On Linux, secretstorage is now a declared dependency, allowing recommended keyring to work simply after installation.
Issue #231 via #233: On Linux, secretstorage is now a declared dependency, allowing recommended keyring to work simply after installation.
Issue #83 via #229: kwallet backend now stores the service name as a folder name in the backend rather than storing all passwords in a Python folder.
Issue #83 via #229: kwallet backend now stores the service name as a folder name in the backend rather than storing all passwords in a Python folder.
Issue #217: Once again, the OS X backend uses the Framework API for invoking the Keychain service. As a result, applications utilizing this API will b
Issue #217: Once again, the OS X backend uses the Framework API for invoking the Keychain service. As a result, applications utilizing this API will be authorized per application, rather than relying on the authorization of the 'security' application. Consequently, users will be prompted to authorize the system Python executable and also new Python executables, such as those created by virtualenv. #260: No longer does the keyring honor the store attribute on the keyring. Only application passwords are accessible.
Changelog now links to issues and provides dates of releases.
Changelog now links to issues and provides dates of releases.
Nothing published for this version
Issue #217: Add warning in OS Keyring when 'store' is set to 'internet' to determine if this feature is used in the wild.
Issue #217: Add warning in OS Keyring when 'store' is set to 'internet' to determine if this feature is used in the wild.
Pull Request #216: Kwallet backend now has lower priority than the preferred SecretService backend, now that the desktop check is no longer in place.
Pull Request #216: Kwallet backend now has lower priority than the preferred SecretService backend, now that the desktop check is no longer in place.
Issue #168: Now prefer KF5 Kwallet to KF4. Users relying on KF4 must use prior releases.
Issue #168: Now prefer KF5 Kwallet to KF4. Users relying on KF4 must use prior releases.
Nothing published for this version
Pull Request #209: Better error message when no backend is available (indicating keyrings.alt as a quick workaround).
Pull Request #209: Better error message when no backend is available (indicating keyrings.alt as a quick workaround).
Pull Request #208: Fix pywin32-ctypes package name in requirements.
Issue #207: Library now requires win32ctypes on Windows systems, which will be installed automatically by Setuptools 0.7 or Pip 6 (or later).
Issue #207: Library now requires win32ctypes on Windows systems, which will be installed automatically by Setuptools 0.7 or Pip 6 (or later).
Actually removed QtKwallet, which was meant to be dropped in 8.0 but somehow remained.
Your coding agent can read these notes before it upgrades. Set up the MCP server →