⚠️ This is an unsupported Microsoft sample. Unlikeartifacts-keyring, this project is a best-effort alternative focused on convenience (more auth auto-detection, reuse of existingazCLI logins) and debuggability (pure Python — no opaque .NET binary). It is not covered by any Microsoft support program — use at your own risk.
Minimal, pure-Python keyring backend for Azure DevOps Artifacts feeds. Replaces
the official artifacts-keyring (which wraps a ~100 MB .NET binary) with a
no-fuss, pure-Python implementation — no .NET required.
Full docs: https://microsoft.github.io/artifacts-keyring-nofuss/
| Page | What's inside |
|---|---|
| Home | Install and a scenario picker. |
| Local development | Install packages locally with an az login. |
| pip & uv setup | Turn on the keyring provider once. |
| GitHub Actions | OIDC installs and the Docker composite action. |
| Docker builds | BuildKit secrets and minting a token without az. |
| GitHub Codespaces | The artifacts-helper devcontainer feature. |
| Managed identity & service principals | MI, service principals, and workload identity. |
| Pre-minted tokens | Supply a bearer token via env var or file. |
| How it works | Auth flows, priority order, security model. |
| Reference | Install options, CLI, env vars, feed URLs, troubleshooting. |
Install keyring plus this backend as an isolated standalone tool:
uv tool install keyring --with artifacts-keyring-nofussThen point your package manager at your private feed — the backend discovers the tenant and obtains credentials automatically:
# pip
pip install --keyring-provider=subprocess \
--index-url https://pkgs.dev.azure.com/{org}/_packaging/{feed}/pypi/simple/ \
my-package
# uv
uv pip install my-package \
--index-url https://__token__@pkgs.dev.azure.com/{org}/_packaging/{feed}/pypi/simple/See the documentation site for CI, Docker, service principal, and Codespaces setups.
pip install -e ".[dev]"Licensed under the MIT License.
See SECURITY.md for how to report security issues.