NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3177 most downloaded on PyPI
A multi-language, cross-platform library that provides cryptographic APIs that are secure, easy to use correctly, and hard(er) to misuse.
Last release 1 months ago
13 Aug 2026
Release timing varies
gaps range from 2 weeks to 11 months
Most releases are documented
notes for 12 of 17 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
17 releases · first in 2020
One column per quarter.
The complete list of changes since 1.16.0 can be found here.
This is Tink Python 1.16.1
The complete list of changes since 1.16.0 can be found here.
Dependency updates:
pyasn1 -> 0.6.4To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.16.1
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.16.1
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.16.1
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.16.1
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.16.1
Tink Python can be used in a Bazel project as a pip dependency using
rules_python's pip_parse macro.
The complete list of changes since 1.15.0 can be found here.
This is Tink Python v1.16.0
The complete list of changes since 1.15.0 can be found here.
RSAECDSAML-DSA (pure and external-mu)SLH-DSA (pure and pre-hash)new_client function to create a Tink KmsClient from
an existing KeyManagementServiceClient.protobuf==5.29.5.pip (26.1.2)requests (2.33.0)tink-cc (2.8.0)rules_python (2.2.0)rules_cc (0.2.22)abseil-cpp (20260526.0)pybind11_bazel (3.0.1)platforms (1.1.0)google-crc32c (1.8.0)google-cloud-kms (3.16.0)To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.16.0
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.16.0
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.16.0
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.16.0
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.16.0
Tink Python can be used in a Bazel project as a pip dependency using
rules_python's pip_parse macro.
The complete list of changes since 1.14.1 can be found here.
This is Tink Python 1.15.0
The complete list of changes since 1.14.1 can be found here.
pip (26.1)requests (2.33.0)tink-cc (2.6.0)rules_python (2.0.1)abseil-cpp (20260107.1)platforms (1.1.0)To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.15.0
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.15.0
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.15.0
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.15.0
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.15.0
The complete list of changes since 1.14.0 can be found here.
This is Tink Python 1.14.1
The complete list of changes since 1.14.0 can be found here.
To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.14.0
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.14.0
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.14.0
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.14.0
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.14.0
Tink Python can be used in a Bazel project as a pip dependency using rules_python's pip_parse macro.
The complete list of changes since 1.13.0 can be found here.
This is Tink Python 1.14.0
The complete list of changes since 1.13.0 can be found here.
pip (26.0)protobuf (6.33.5)urllib3 (2.6.3)wheel (0.46.2)To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.14.0
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.14.0
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.14.0
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.14.0
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.14.0
Tink Python can be used in a Bazel project as a pip dependency using rules_python's pip_parse macro.
The complete list of changes since 1.13.1 can be found here.
Tink Python 1.13.1
The complete list of changes since 1.13.1 can be found here.
To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.13.1
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.13.1
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.13.1
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.13.1
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.13.1
Tink Python can be used in a Bazel project as a pip dependency using rules_python's pip_parse macro.
The complete list of changes since 1.12.0 can be found here.
Tink Python 1.13.0
The complete list of changes since 1.12.0 can be found here.
GcpKmsClient is instantiated with a CryptoKeyVersion, performing
decryption will now raise an error. This mirrors the behavior of the KMS
service, which only allows specifying the version for encrypt operations.GcpKmsClient a context manager; when used in a with statement it
properly closes the underlying gRPC channel.protobuf to accept >=5.29.3
(https://github.com/tink-crypto/tink-py/issues/47).8.4.2)abseil-cpp (20250814.1)rules_cc (0.2.14)rules_cc (0.2.14)pybind11_bazel (3.0.0)platforms (1.0.0)To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.13.0
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.13.0
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.13.0
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.13.0
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.13.0
Tink Python can be used in a Bazel project as a pip dependency using rules_python's pip_parse macro.
Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
This is Tink Python 1.12
The complete list of changes since 1.11.0 can be found here.
ciphertext_destination in streamingaead. This prevents segmentation faults if the underlying stream reports back too many bytes written. See https://github.com/tink-crypto/tink-py/issues/43.pip install for the sdist (source distribution) uses Bazel, this impacts how Tink is built for people using sdist.To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==<VERSION>
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==<VERSION>
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==<VERSION>
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==<VERSION>
# Core Tink + all the KMS extensions.
pip3 install tink[all]==<VERSION>
Tink Python can be used in a Bazel project as a pip dependency using rules_python’s pip_parse macro.
Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
This is Tink Python 1.12
The complete list of changes since 1.11.0 can be found here.
ciphertext_destination in streamingaead. This prevents segmentation faults if the underlying stream reports back too many bytes written. See #43.pip install for the sdist (source distribution) uses Bazel, this impacts how Tink is built for people using sdist.To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==<VERSION>
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==<VERSION>
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==<VERSION>
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==<VERSION>
# Core Tink + all the KMS extensions.
pip3 install tink[all]==<VERSION>
Tink Python can be used in a Bazel project as a pip dependency using rules_python’s pip_parse macro.
Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
Tink is a multi-language, cross-platform library that provides simple and
misuse-proof APIs for common cryptographic tasks.
This is Tink Python 1.11.0
The complete list of changes since 1.10.0 can be found
here.
To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.11.0
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.11.0
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.11.0
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.11.0
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.11.0
Tink Python can be used in a Bazel project as a pip dependency using rules_python’s pip_parse macro.
Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
This is Tink Python 1.10.0
This is the first release from https://github.com/tink-crypto/tink-py.
The complete list of changes since 1.9.0 can be found here.
hcvault.new_aead API to create an AEAD that interacts with a Vault server.keyset_info metadata in encrypted keysets produced with tink.BinaryKeysetWriter and tink.proto_keyset_format.serialize_encrypted is not written anymore. This results in smaller keysets. tink.JsonKeysetWriter and tink.json_proto_keyset_format.serialize_encrypted are unchanged and still output keyset_info.tink-cc => 2.1.3pybind11_bazel => v2.11.1.bzl.1hvac>=1.1.1 (when using the hcvault extras)rules_python => 0.31.0__getstate__ and __setstate__ raise a TinkError; this intends to prevent unintentional serialization of keyset handles which may leak keys. To serialize the KeysetHandle, use tink.proto_keyset_format or tink.json_proto_keyset_format. If this breaks your code, please file an issue on https://github.com/tink-crypto/tink-python.tink_py_deps() to include all direct dependenciestink_py_testonly_deps() to include test-only dependenciesTo see what we're working towards, check our project roadmap.
To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.10.0
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.10.0
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.10.0
# Core Tink + HashiCorp Vault KMS extension.
pip3 install tink[hcvault]==1.10.0
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.10.0
Tink Python can be used in a Bazel project as a pip dependency using rules_python’s pip_parse macro
Alternatively, tink-py can be added as a Bazel build dependency to your WORKSPACE file:
load("@bazel_tools//tools/build_defs/repo:http.bzl", "http_archive")
http_archive(
name = "tink_py",
urls = ["https://github.com/tink-crypto/tink-py/releases/download/v1.10.0/tink-py-1.10.0.zip"],
strip_prefix = "tink-py-1.10.0",
sha256 = "767453aae4aad6de4fbb4162992184aa427b7b27864fe9912c270b24c673e1cc",
)
load("@tink_py//:tink_py_deps.bzl", "tink_py_deps")
tink_py_deps()
// New
load("@rules_python//python:repositories.bzl", "py_repositories")
// New
py_repositories()
load("@tink_py//:tink_py_deps_init.bzl", "tink_py_deps_init")
tink_py_deps_init("tink_py")Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
This is Tink Python 1.9.0
This is the first release from https://github.com/tink-crypto/tink-py.
The complete list of changes since 1.8.0 can be found here.
register_kms_client publicjson_proto_keyset_format and proto_keyset_format APIs to
serialize/deserialize keysetsexpected_*() functions in tink.jwt.JwtValidator.To see what we're working towards, check our project roadmap.
To get started using Tink, see the setup guide.
# Core Tink.
pip3 install tink==1.9.0
# Core Tink + Google Cloud KMS extension.
pip3 install tink[gcpkms]==1.9.0
# Core Tink + AWS KMS extension.
pip3 install tink[awskms]==1.9.0
# Core Tink + all the KMS extensions.
pip3 install tink[all]==1.9.0
Tink Python can be used in a Bazel project as a pip dependency using rules_python’s pip_parse macro, or tink-py can be added as a Bazel build dependency to your WORKSPACE file:
load("@bazel_tools//tools/build_defs/repo:http.bzl", "http_archive")
http_archive(
name = "tink_py",
urls = ["https://github.com/tink-crypto/tink-py/releases/download/v1.9.0/tink-py-1.9.0.zip"],
strip_prefix = "tink-py-1.9.0",
sha256 = "c5f9a7b58b79ef0e1b957154672f766489ea0ac956ad187941f950f2dc262e71",
)
load("@tink_py//:tink_py_deps.bzl", "tink_py_deps")
tink_py_deps()
load("@tink_py//:tink_py_deps_init.bzl", "tink_py_deps_init")
tink_py_deps_init("tink_py")
# ...
Use ranges for requirements and exclude known vulnerable protobuf version (commits: #1, #2; issues: #1, #2)
Tink is a multi-language, cross-platform library that provides simple and misuse-proof APIs for common cryptographic tasks.
This is Tink Python 1.8.0
This is the first release from https://github.com/tink-crypto/tink-py.
The complete list of changes since 1.7.0 can be found here.
To see what we're working towards, check our project roadmap.
To get started using Tink, see the setup guide.
pip3 install tink==1.8.0
Tink Python can be used in a Bazel project as a pip dependency using rules_python’s pip_parse macro, or tink-py can be added as a Bazel build dependency to your WORKSPACE file:
load("@bazel_tools//tools/build_defs/repo:http.bzl", "http_archive")
http_archive(
name = "tink_py",
urls = ["https://github.com/tink-crypto/tink-py/releases/download/v1.8.0/tink-py-1.8.0.tar.gz"],
strip_prefix = "tink-py-1.8.0",
sha256 = "1309f1d5d14062cd3ab623957e74bb17e98b49643d2799f33c441da06c3a61f7",
)
load("@tink_py//:tink_py_deps.bzl", "tink_py_deps")
tink_py_deps()
load("@tink_py//:tink_py_deps_init.bzl", "tink_py_deps_init")
tink_py_deps_init("tink_py")
# ...
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →