The hvac library is the standard Python client for HashiCorp Vault, and it works fully with OpenBao because OpenBao preserves the Vault API. This page shows how to authenticate, read, write, and list secrets using hvac.
1. Install the HVAC client
NOTE: you should use a an environment before installing packages, for example with uv or virtualenv.
pip install hvac
2. Download your token from the OpenBao UI
In the OpenBao UI:
- Copy token from your profile
Save it securely in your machine (e.g.,
~/.openbao-token).
3. Connect to OpenBao using the downloaded token
import hvac
# Read the token you downloaded from the UI
with open("/home/francesco/.openbao-token") as f:
token = f.read().strip()
client = hvac.Client(
url="https://secrets.europeanweather.cloud",
token=token,
namespace="my-tenancy",
verify=True
)
print("Authenticated:", client.is_authenticated())
4. Write a secret (KV v2)
client.secrets.kv.v2.create_or_update_secret(
path="myapp/config",
secret={
"username": "service",
"password": "example"
}
)
5. Read a secret
result = client.secrets.kv.v2.read_secret_version(
path="myapp/config"
)
print(result["data"]["data"])
6. List secrets
client.secrets.kv.v2.list_secrets(path="myapp/")
7. Delete a secret
client.secrets.kv.v2.delete_metadata_and_all_versions(
path="myapp/config"
)
