NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #597 most downloaded on PyPI
A Python SOAP client
Last release 3 months ago
18 Jun 2026
Release timing varies
gaps range from 2 weeks to 1.9 years
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
69 releases · first in 2016
Wire up the forbid_external setting (previously defined but unused since the move off defusedxml in 4.0). When enabled, zeep refuses to transitively f
forbid_external setting (previously defined but unused since the move off defusedxml in 4.0). When enabled, zeep refuses to transitively fetch http/https resources via xsd:import, xsd:include, wsdl:import or lxml entity resolution, raising zeep.exceptions.ExternalReferenceForbidden. The user-supplied entry-point WSDL/schema URL is still loaded. The default remains False to preserve existing behaviour; enable it when loading WSDLs from untrusted sources to mitigate SSRF via attacker-controlled import targets.forbid_external setting (previously defined but unused
since the move off defusedxml in 4.0). When enabled it refuses to
transitively fetch http/https resources via xsd:import,
xsd:include, wsdl:import or lxml entity resolution, raising
zeep.exceptions.ExternalReferenceForbidden. The user-supplied
entry-point WSDL/schema URL is still loaded. The default remains
False to preserve existing behaviour; enable when loading WSDLs from
untrusted sources to mitigate SSRF via attacker-controlled import
targets.One column per quarter.
Update proxy argument in httpx Client/AsyncClient by @aschollmeier-gcmlp in #1447
Full Changelog: 4.3.1...4.3.2
Fix regression in parsing xsd:Date with negative timezone
Replace deprecated datetime.datetime.utcnow()
datetime.datetime.utcnow()Fix error regarding closing session in async transport
Fix error regarding closing session in async transport (#1347)
Fix httpx DeprecationWarning for post data
Remove dependency on defusedxml (deprecated)
six (#1250)platformdirs instead of the appsdirs dependency (#1244)defusedxml (deprecated) (#1179)undo incorrect version bump
undo incorrect version bump
zeep.transports.AsyncTransport which is based on httpx. Note that
loading wsdl files is still a sync process but operations can be executed via
async.support for milliseconds
support for milliseconds
Bump version: 3.3.1 → 3.4.0
Bump version: 3.3.1 → 3.4.0
Fix issue with empty xsd:import statements on Python 2.7
Extend the force_https flag to also force loading xsd files from https when a http url is encountered from a https domain
Fix abstract message check for NoneType before attempting to access parts
Fix SSL issue on with TornadoAsyncTransport
TornadoAsyncTransport (#792)This is a major release, and contains a number of backwards incompatible changes to the API.
This is a major release, and contains a number of backwards incompatible changes to the API.
Fix AnyType value rendering by guessing the xsd type for the value
Add support for tornado async transport via gen.coroutine (#530, Kateryna Burda)
The XML send to the server is no longer using pretty_print=True
pretty_print=True (#484)Automatically import the soap-encoding schema if it is required
Fix previous release, it contained an incorrect dependency (Mock 2.1.) due to bumpversion :-(
Fix recursion error while creating the signature for a global element when it references itself (via ref attribute).
This is a major release, and contains a number of backwards incompatible changes to the API.
This is a major release, and contains a number of backwards incompatible changes to the API.
Default values of optional elements are not set by default anymore (#423)
Refactor the implementation of wsdl:arrayType too make the API more pythonic (backwards incompatible).
The call signature for Client.create_message() was changed. It now requires the service argument:
Client.create_message(service, operation_name, *args, **kwargs)
Choice elements now only work with keyword arguments and raise an exception if positional arguments are passed (#439)
Implement initial multiref support for SOAP RPC (#326). This was done using really good real-world tests from vstoykov (thanks!)
Fix exception on empty SOAP response (#442)
Fix XSD default values for boolean types (Bartek Wójcicki, #386)
Implement ValueObject.__json__ for json serialization
Fix issue where values of indicators (sequence/choice/all) would write to the same internal dict.
zeep.xsd.Nil (#424)The previous release (1.4.0) contained an incorrect dependency due to bumpversion moving all 1.3.0 versions to 1.4.0. This fixes it.
Hardcode the xml prefix to the xml namespace as defined in the specs
Client.raw_response option to let zeep return the raw
transport response (requests.Response) instead of trying to parse it.Add support for nested xsd:choice elements
Add flag to disable strict mode in the Client. This allows zeep to better work with non standard compliant SOAP Servers. See the documentation for usa
zeep.CachingClient() which enables the SqliteCache by defaultFix an attribute error when an complexType used xsd:anyType as base restriction
Use cgi.parse_header() to extract media_type for multipart/related checks
Add support for SOAP attachments (multipart responses). (Dave Wapstra, #302)
This release again introduces some backwords incompatibilties. The next release will hopefully be 1.0 which will introduce semver.
This release again introduces some backwords incompatibilties. The next release will hopefully be 1.0 which will introduce semver.
requests.Session() object instead of http_auth and verify. This
allows for more flexibility.zeep.xsd.SkipValue which instructs the serialize to ignore the
element.Important: Add basic validation against the xsd. It currently will only validate the minOccurs/maxOccurs but this will be extended in the future.
Don't fail the parsing of responses if an xsi:type references an non-existing type. Instead log a message
Add Client.set_default_soapheaders() to set soapheaders which are to be used on all operations done via the client object.
Fix reversed() error (jaceksnet)
Force the soap:address / http:address to HTTPS when the wsdl is loaded from a https url
Don't error on empty xml namespaces declarations in inline schema's
operation_timeout kwarg to the Transport class to set timeouts for
operations. The default is still no timeout (#140)Major performance improvements / lower memory usage. Zeep now no longer copies data and alters it in place but instead uses a set to keep track of mod
backwards-incompatible: If the WSDL defines that the endpoint returns soap:header elements and/or multple soap:body messages then the return signature
- PyPi release error
Fix parsing Any elements by using the namespace map of the response node instead of the namespace map of the wsdl. (#184, #164)
Add improvements to resolving phase so that all objects are resolved.
Fix error when rendering choice elements with have sequences as children, see #150
All wsdl documents and xsd schemas are now globally available for eachother. While this is not correct according to the (messy) soap specifications, i
Global attributes are now always correctly handled as qualified.
Use warnings.warn() for duplicate target namespaces instead of raising an exception. This better matches with what lxml does.
persistent kwarg is removed from the
SqliteCache.init() call. Use the new InMemoryCache() instead when you
don't want to persist data. This was required to make the SqliteCache
backend thread-safe since we now open/close the db when writing/reading
from it (with an additional lock).backwards-incompatible: Choice elements are now unwrapped if maxOccurs=1. This results in easier operation definitions when choices are used.
python -mzeep <wsdl>.backwards-incompatible: The kwarg name for Any and Choice elements are renamed to generic _value_N names.
_value_N names.logger.debug() calls around Transport.post() to allow capturing the
content send/received from the serverMake global elements / types truly global by refactoring the Schema parsing. Previously the lookups where non-transitive, but this should only be the
Quote the SOAPAction header value (Derek Harland)
Use the appdirs module to retrieve the OS cache path. Note that this results in an other default cache path then previous releases! See https://github
Use the operation name for the xml element which wraps the parameters in for soap RPC messages
Add ability to override the soap endpoint via Client.set_address()
Client.set_address()Fix regression with handling wsdl:import statements for messages
Add support HTTP authentication (mcordes). This adds a new attribute to the Transport client() which passes the http_auth value to requests.
Add missing name attributes to xsd.QName and xsd.NOTATION
name attributes to xsd.QName and xsd.NOTATION (#15)Client.get_port(), use Client.bind().backwards incompatible: Make cache part of the transport object instead of the client. This changes the call signature of the Client() class. (Marek W…
application/soap+xml as content-type in the Soap 1.2 bindingverify kwarg to the Transport object to disable ssl certificate
verification. (Marek Wywiał)Add defusedxml module for XML security issues
Correctly handle recursion in WSDL and XSD files
Your coding agent can read these notes before it upgrades. Set up the MCP server →