Azure Keyvault Py

by microsoft354361d83247MITListed Oct 8, 2026Updated Oct 8, 2026

Azure Key Vault SDK for Python. Use for secrets, keys, and certificates management with secure storage. Triggers: "key vault", "SecretClient", "KeyClient", "CertificateClient", "secrets", "encryption keys".

FeaturedInstructions onlySoftware DevelopmentSecurity
AI-generated overview

Instructions for using the Azure Key Vault Python SDK to manage secrets, keys, and certificates.

What it does
This skill provides guidance and code samples for working with the Azure Key Vault SDK for Python. It covers client setup for SecretClient, KeyClient, CryptographyClient, and CertificateClient, along with operations such as setting and retrieving secrets, creating RSA and EC keys, encrypting, decrypting, signing, verifying, and managing certificates. It also documents authentication with DefaultAzureCredential, async clients, error handling, and best practices.
When to use it
Use this skill when writing Python code that stores or retrieves secrets, manages cryptographic keys, or handles certificates in Azure Key Vault. It is suited to developers who need setup patterns, operation examples, or authentication guidance for the Azure Key Vault SDK.
Requirements
Requires Python and the azure-keyvault-secrets, azure-keyvault-keys, azure-keyvault-certificates, and azure-identity packages. Needs an Azure Key Vault URL and Azure credentials, such as DefaultAzureCredential or managed identity, plus network access to Azure. Ships no scripts; it is instructions only.

Azure Key Vault SDK for Python

Secure storage and management for secrets, cryptographic keys, and certificates.

Installation

bash
# Secretspip install azure-keyvault-secrets azure-identity
# Keys (cryptographic operations)pip install azure-keyvault-keys azure-identity
# Certificatespip install azure-keyvault-certificates azure-identity
# Allpip install azure-keyvault-secrets azure-keyvault-keys azure-keyvault-certificates azure-identity

Environment Variables

bash
AZURE_KEYVAULT_URL=https://<vault-name>.vault.azure.net/  # Required for all auth methodsAZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production

Authentication & Lifecycle

🔑 Two rules apply to every code sample below:

  1. Prefer DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
    • Local dev: DefaultAzureCredential works as-is.
    • Production: set AZURE_TOKEN_CREDENTIALS=prod (or AZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials.
  2. Wrap every client in a context manager so HTTP transports, sockets, and token caches are released deterministically:
    • Sync: with <Client>(...) as client:
    • Async: async with <Client>(...) as client: and async with DefaultAzureCredential() as credential: (from azure.identity.aio)

Snippets may abbreviate this setup, but production code should always follow both rules.

Secrets

SecretClient Setup

python
from azure.identity import DefaultAzureCredential, ManagedIdentityCredentialfrom azure.keyvault.secrets import SecretClient
# Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>credential = DefaultAzureCredential(require_envvar=True)# Or use a specific credential directly in production:# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes# credential = ManagedIdentityCredential()vault_url = "https://<vault-name>.vault.azure.net/"
with SecretClient(vault_url=vault_url, credential=credential) as client:    # All secret operations go inside this block (see examples below)    ...

Secret Operations

python
# Set secretsecret = client.set_secret("database-password", "super-secret-value")print(f"Created: {secret.name}, version: {secret.properties.version}")
# Get secretsecret = client.get_secret("database-password")print(f"Value: {secret.value}")
# Get specific versionsecret = client.get_secret("database-password", version="abc123")
# List secrets (names only, not values)for secret_properties in client.list_properties_of_secrets():    print(f"Secret: {secret_properties.name}")
# List versionsfor version in client.list_properties_of_secret_versions("database-password"):    print(f"Version: {version.version}, Created: {version.created_on}")
# Delete secret (soft delete)poller = client.begin_delete_secret("database-password")deleted_secret = poller.result()
# Purge (permanent delete, if soft-delete enabled)client.purge_deleted_secret("database-password")
# Recover deleted secretclient.begin_recover_deleted_secret("database-password").result()

Keys

KeyClient Setup

python
from azure.identity import DefaultAzureCredentialfrom azure.keyvault.keys import KeyClient
credential = DefaultAzureCredential()vault_url = "https://<vault-name>.vault.azure.net/"
with KeyClient(vault_url=vault_url, credential=credential) as client:    # All key operations go inside this block (see examples below)    ...

Key Operations

python
from azure.keyvault.keys import KeyType
# Create RSA keyrsa_key = client.create_rsa_key("rsa-key", size=2048)
# Create EC keyec_key = client.create_ec_key("ec-key", curve="P-256")
# Get keykey = client.get_key("rsa-key")print(f"Key type: {key.key_type}")
# List keysfor key_properties in client.list_properties_of_keys():    print(f"Key: {key_properties.name}")
# Delete keypoller = client.begin_delete_key("rsa-key")deleted_key = poller.result()

Cryptographic Operations

python
from azure.keyvault.keys.crypto import CryptographyClient, EncryptionAlgorithm
# Get crypto client for a specific key# crypto_client = CryptographyClient(key, credential=credential)# Or from key IDwith CryptographyClient(    "https://<vault>.vault.azure.net/keys/<key-name>/<version>",    credential=credential) as crypto_client:    # Encrypt    plaintext = b"Hello, Key Vault!"    result = crypto_client.encrypt(EncryptionAlgorithm.rsa_oaep, plaintext)    ciphertext = result.ciphertext
    # Decrypt    result = crypto_client.decrypt(EncryptionAlgorithm.rsa_oaep, ciphertext)    decrypted = result.plaintext
    # Sign    from azure.keyvault.keys.crypto import SignatureAlgorithm    import hashlib
    digest = hashlib.sha256(b"data to sign").digest()    result = crypto_client.sign(SignatureAlgorithm.rs256, digest)    signature = result.signature
    # Verify    result = crypto_client.verify(SignatureAlgorithm.rs256, digest, signature)    print(f"Valid: {result.is_valid}")

Certificates

CertificateClient Setup

python
from azure.identity import DefaultAzureCredentialfrom azure.keyvault.certificates import CertificateClient, CertificatePolicy
credential = DefaultAzureCredential()vault_url = "https://<vault-name>.vault.azure.net/"
with CertificateClient(vault_url=vault_url, credential=credential) as client:    # All certificate operations go inside this block (see examples below)    ...

Certificate Operations

python
# Create self-signed certificatepolicy = CertificatePolicy.get_default()poller = client.begin_create_certificate("my-cert", policy=policy)certificate = poller.result()
# Get certificatecertificate = client.get_certificate("my-cert")print(f"Thumbprint: {certificate.properties.x509_thumbprint.hex()}")
# Get certificate with private key (as secret)from azure.keyvault.secrets import SecretClientwith SecretClient(vault_url=vault_url, credential=credential) as secret_client:    cert_secret = secret_client.get_secret("my-cert")    # cert_secret.value contains PEM or PKCS12
# List certificatesfor cert in client.list_properties_of_certificates():    print(f"Certificate: {cert.name}")
# Delete certificatepoller = client.begin_delete_certificate("my-cert")deleted = poller.result()

Client Types Table

ClientPackagePurpose
SecretClientazure-keyvault-secretsStore/retrieve secrets
KeyClientazure-keyvault-keysManage cryptographic keys
CryptographyClientazure-keyvault-keysEncrypt/decrypt/sign/verify
CertificateClientazure-keyvault-certificatesManage certificates

Async Clients

python
from azure.identity.aio import DefaultAzureCredentialfrom azure.keyvault.secrets.aio import SecretClient
async def get_secret():    async with DefaultAzureCredential() as credential:        async with SecretClient(vault_url=vault_url, credential=credential) as client:            secret = await client.get_secret("my-secret")            print(secret.value)
import asyncioasyncio.run(get_secret())

Error Handling

python
from azure.core.exceptions import ResourceNotFoundError, HttpResponseError
try:    secret = client.get_secret("nonexistent")except ResourceNotFoundError:    print("Secret not found")except HttpResponseError as e:    if e.status_code == 403:        print("Access denied - check RBAC permissions")    raise

Best Practices

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose one mode per module.
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with Client(...) as client: (async). For async DefaultAzureCredential from azure.identity.aio, also use async with credential: so tokens and transports are cleaned up.
  3. Use DefaultAzureCredential for code that runs locally. Use a specific token credential for code that runs in Azure.
  4. Use managed identity in Azure-hosted applications
  5. Enable soft-delete for recovery (enabled by default)
  6. Use RBAC over access policies for fine-grained control
  7. Rotate secrets regularly using versioning
  8. Use Key Vault references in App Service/Functions config
  9. Cache secrets appropriately to reduce API calls
  10. Use async clients for high-throughput scenarios

Reference Files

FileContents
references/capabilities.md [blocked]Additional non-hero capabilities, operation-group coverage, and production checklists.
references/non-hero-scenarios.md [blocked]Dedicated non-hero examples for secondary/advanced scenarios.

Source and attribution

Source:microsoft/skillsin.github/plugins/azure-sdk-python/skills/azure-keyvault-pyat commit354361d

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal