Official agent skill

Azure Keyvault Py

by microsoft in microsoft/skills

Azure Key Vault SDK for Python. An agent skill from microsoft/skills.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Keyvault Py

skills CLI
$ npx skills add microsoft/skills --skill azure-keyvault-py -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-keyvault-py --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-python/skills/azure-keyvault-py .claude/skills/azure-keyvault-py && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-keyvault-py
GitHub stars
3.1k
Token cost
~2.4k tokens
SKILL.md length
340 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Azure Key Vault SDK for Python. An agent skill from microsoft/skills.

  • Works in 10 steps: Pick sync OR async and stay consistent.… → Always use context managers for clients… → Use DefaultAzureCredential for code that… → …
  • Certificates management with secure storage
  • SKILL.md covers Installation, Environment Variables, Authentication & Lifecycle and Secrets, plus 7 more sections
  • Calls pip; reaches learn.microsoft.com; needs AZURE_TOKEN_CREDENTIALS

What it does

Azure Keyvault Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Key Vault SDK for Python. Use for secrets, keys, and certificates management with secure storage. Triggers: "key vault", "SecretClient", "KeyClient", "CertificateClient", "secrets", "encryption keys".

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/capabilities.md` and `references/non-hero-scenarios.md`).

It sits in DevOps & Cloud, covering Secrets management and Cryptography. It works with Azure Key Vault, Python, Microsoft Azure and Visual Studio Code. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • Certificates management with secure storage
  • Tasks that involve Secrets management
  • Tasks that involve Cryptography

Example prompts

  • “key vault”
  • “SecretClient”
  • “KeyClient”
  • “/azure-keyvault-py”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose…
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with…
  3. Use DefaultAzureCredential for code that runs locally. Use a specific token credential for code that runs in Azure.
  4. Use managed identity in Azure-hosted applications
  5. Enable soft-delete for recovery (enabled by default)
  6. Use RBAC over access policies for fine-grained control
  7. Rotate secrets regularly using versioning
  8. Use Key Vault references in App Service/Functions config
  9. Cache secrets appropriately to reduce API calls
  10. Use async clients for high-throughput scenarios

What it can do on your machine

Read from SKILL.md and the folder at commit 354361d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_TOKEN_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Keyvault Py loads about 2.4k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 56 tokens; SKILL.md has 340 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit 354361d, republished under its MIT licence (© microsoft). 340 words, ~2,399 tokens.

Download SKILL.mdSave it as .claude/skills/azure-keyvault-py/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
azure-keyvault-py
description
Azure Key Vault SDK for Python. Use for secrets, keys, and certificates management with secure storage. Triggers: "key vault", "SecretClient", "KeyClient", "CertificateClient", "secrets", "encryption keys".
license
MIT
metadata.author
Microsoft
metadata.version
1.0.0
metadata.package
azure-keyvault-secrets, azure-keyvault-keys, azure-keyvault-certificates

Azure Key Vault SDK for Python

Secure storage and management for secrets, cryptographic keys, and certificates.

Installation

bash
# Secrets
pip install azure-keyvault-secrets azure-identity

# Keys (cryptographic operations)
pip install azure-keyvault-keys azure-identity

# Certificates
pip install azure-keyvault-certificates azure-identity

# All
pip install azure-keyvault-secrets azure-keyvault-keys azure-keyvault-certificates azure-identity

Environment Variables

bash
AZURE_KEYVAULT_URL=https://<vault-name>.vault.azure.net/  # Required for all auth methods
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production

Authentication & Lifecycle

🔑 Two rules apply to every code sample below:

  1. Prefer DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
    • Local dev: DefaultAzureCredential works as-is.
    • Production: set AZURE_TOKEN_CREDENTIALS=prod (or AZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials.
  2. Wrap every client in a context manager so HTTP transports, sockets, and token caches are released deterministically:
    • Sync: with <Client>(...) as client:
    • Async: async with <Client>(...) as client: and async with DefaultAzureCredential() as credential: (from azure.identity.aio)

Snippets may abbreviate this setup, but production code should always follow both rules.

Secrets

SecretClient Setup
python
from azure.identity import DefaultAzureCredential, ManagedIdentityCredential
from azure.keyvault.secrets import SecretClient

# Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>
credential = DefaultAzureCredential(require_envvar=True)
# Or use a specific credential directly in production:
# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes
# credential = ManagedIdentityCredential()
vault_url = "https://<vault-name>.vault.azure.net/"

with SecretClient(vault_url=vault_url, credential=credential) as client:
    # All secret operations go inside this block (see examples below)
    ...
Secret Operations
python
# Set secret
secret = client.set_secret("database-password", "super-secret-value")
print(f"Created: {secret.name}, version: {secret.properties.version}")

# Get secret
secret = client.get_secret("database-password")
print(f"Value: {secret.value}")

# Get specific version
secret = client.get_secret("database-password", version="abc123")

# List secrets (names only, not values)
for secret_properties in client.list_properties_of_secrets():
    print(f"Secret: {secret_properties.name}")

# List versions
for version in client.list_properties_of_secret_versions("database-password"):
    print(f"Version: {version.version}, Created: {version.created_on}")

# Delete secret (soft delete)
poller = client.begin_delete_secret("database-password")
deleted_secret = poller.result()

# Purge (permanent delete, if soft-delete enabled)
client.purge_deleted_secret("database-password")

# Recover deleted secret
client.begin_recover_deleted_secret("database-password").result()

Keys

KeyClient Setup
python
from azure.identity import DefaultAzureCredential
from azure.keyvault.keys import KeyClient

credential = DefaultAzureCredential()
vault_url = "https://<vault-name>.vault.azure.net/"

with KeyClient(vault_url=vault_url, credential=credential) as client:
    # All key operations go inside this block (see examples below)
    ...
Key Operations
python
from azure.keyvault.keys import KeyType

# Create RSA key
rsa_key = client.create_rsa_key("rsa-key", size=2048)

# Create EC key
ec_key = client.create_ec_key("ec-key", curve="P-256")

# Get key
key = client.get_key("rsa-key")
print(f"Key type: {key.key_type}")

# List keys
for key_properties in client.list_properties_of_keys():
    print(f"Key: {key_properties.name}")

# Delete key
poller = client.begin_delete_key("rsa-key")
deleted_key = poller.result()
Cryptographic Operations
python
from azure.keyvault.keys.crypto import CryptographyClient, EncryptionAlgorithm

# Get crypto client for a specific key
# crypto_client = CryptographyClient(key, credential=credential)
# Or from key ID
with CryptographyClient(
    "https://<vault>.vault.azure.net/keys/<key-name>/<version>",
    credential=credential
) as crypto_client:
    # Encrypt
    plaintext = b"Hello, Key Vault!"
    result = crypto_client.encrypt(EncryptionAlgorithm.rsa_oaep, plaintext)
    ciphertext = result.ciphertext

    # Decrypt
    result = crypto_client.decrypt(EncryptionAlgorithm.rsa_oaep, ciphertext)
    decrypted = result.plaintext

    # Sign
    from azure.keyvault.keys.crypto import SignatureAlgorithm
    import hashlib

    digest = hashlib.sha256(b"data to sign").digest()
    result = crypto_client.sign(SignatureAlgorithm.rs256, digest)
    signature = result.signature

    # Verify
    result = crypto_client.verify(SignatureAlgorithm.rs256, digest, signature)
    print(f"Valid: {result.is_valid}")

Certificates

CertificateClient Setup
python
from azure.identity import DefaultAzureCredential
from azure.keyvault.certificates import CertificateClient, CertificatePolicy

credential = DefaultAzureCredential()
vault_url = "https://<vault-name>.vault.azure.net/"

with CertificateClient(vault_url=vault_url, credential=credential) as client:
    # All certificate operations go inside this block (see examples below)
    ...
Certificate Operations
python
# Create self-signed certificate
policy = CertificatePolicy.get_default()
poller = client.begin_create_certificate("my-cert", policy=policy)
certificate = poller.result()

# Get certificate
certificate = client.get_certificate("my-cert")
print(f"Thumbprint: {certificate.properties.x509_thumbprint.hex()}")

# Get certificate with private key (as secret)
from azure.keyvault.secrets import SecretClient
with SecretClient(vault_url=vault_url, credential=credential) as secret_client:
    cert_secret = secret_client.get_secret("my-cert")
    # cert_secret.value contains PEM or PKCS12

# List certificates
for cert in client.list_properties_of_certificates():
    print(f"Certificate: {cert.name}")

# Delete certificate
poller = client.begin_delete_certificate("my-cert")
deleted = poller.result()

Client Types Table

ClientPackagePurpose
SecretClientazure-keyvault-secretsStore/retrieve secrets
KeyClientazure-keyvault-keysManage cryptographic keys
CryptographyClientazure-keyvault-keysEncrypt/decrypt/sign/verify
CertificateClientazure-keyvault-certificatesManage certificates

Async Clients

python
from azure.identity.aio import DefaultAzureCredential
from azure.keyvault.secrets.aio import SecretClient

async def get_secret():
    async with DefaultAzureCredential() as credential:
        async with SecretClient(vault_url=vault_url, credential=credential) as client:
            secret = await client.get_secret("my-secret")
            print(secret.value)

import asyncio
asyncio.run(get_secret())

Error Handling

python
from azure.core.exceptions import ResourceNotFoundError, HttpResponseError

try:
    secret = client.get_secret("nonexistent")
except ResourceNotFoundError:
    print("Secret not found")
except HttpResponseError as e:
    if e.status_code == 403:
        print("Access denied - check RBAC permissions")
    raise

Best Practices

  1. Pick sync OR async and stay consistent. Do not mix azure.xxx sync clients with azure.xxx.aio async clients in the same call path. Choose one mode per module.
  2. Always use context managers for clients and async credentials. Wrap every client in with Client(...) as client: (sync) or async with Client(...) as client: (async). For async DefaultAzureCredential from azure.identity.aio, also use async with credential: so tokens and transports are cleaned up.
  3. Use DefaultAzureCredential for code that runs locally. Use a specific token credential for code that runs in Azure.
  4. Use managed identity in Azure-hosted applications
  5. Enable soft-delete for recovery (enabled by default)
  6. Use RBAC over access policies for fine-grained control
  7. Rotate secrets regularly using versioning
  8. Use Key Vault references in App Service/Functions config
  9. Cache secrets appropriately to reduce API calls
  10. Use async clients for high-throughput scenarios

Reference Files

FileContents
references/capabilities.mdAdditional non-hero capabilities, operation-group coverage, and production checklists.
references/non-hero-scenarios.mdDedicated non-hero examples for secondary/advanced scenarios.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .github/plugins/azure-sdk-python/skills/azure-keyvault-py of microsoft/skills.

  • SKILL.md
  • references/capabilities.md
  • references/non-hero-scenarios.md

Open the folder on GitHubat commit 354361d

Compare with similar skills

Azure Keyvault Py next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Keyvault Py compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Keyvault Py this skillmicrosoft/skills3.1k—~2.4kAutomated safety check: PassMIT
Pki Designvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Azure Key VaultKilo-Org/kilo-marketplace1901 repos~1.9kAutomated safety check: PassMIT
Apex Azure Compliancejonathan-vella/apex217—~1.6kAutomated safety check: PassMIT
Managing Workflow Secretsbitwarden/ai-plugins154—~4kAutomated safety check: PassCustom licence
Azure Keyvaultsickn33/agentic-awesome-skills47k2 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • Pki Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    190 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Apex Azure Compliance

    jonathan-vella/apex

    ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation.

    217 GitHub stars~1.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    154 GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure Keyvault

    sickn33/agentic-awesome-skills

    Manage secrets and certificates in Azure Key Vault. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.2k tokens
    DevOps & CloudAuto-check passed
  • Azure Usage

    fcakyon/claude-codex-settings

    This skill should be used when user asks to "query Azure resources", "list storage accounts", "manage Key Vault secrets", "work with Cosmos DB", "check AKS clusters", "use Azure MCP", or interact…

    1.2k GitHub starsUsed in 1 repo~461 tokens
    DevOps & CloudAuto-check passed

More from microsoft/skills

All 150 skills in this repo
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub starsUsed in 6 repos~2.8k tokens
    Auto-check passed
  • Official

    Python guidance for the Azure AI Search SDK covering vector, hybrid and semantic search, index management and indexers, with Entra ID authentication preferred over keys.

    3.1k GitHub starsUsed in 6 repos~4.4k tokens
    Auto-check passed
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 6 repos~496 tokens
    Auto-check passed
  • DebugView CLI

    microsoft/skills

    Official

    Captures and filters Windows user-mode and kernel debug output from the command line with the Sysinternals DebugView CLI, including bounded runs suited to agents.

    3.1k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed

Questions about Azure Keyvault Py

What does Azure Keyvault Py do?

Azure Key Vault SDK for Python. An agent skill from microsoft/skills. Azure Keyvault Py is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Key Vault SDK for Python.

When should I use Azure Keyvault Py?

Azure Keyvault Py fits situations like: certificates management with secure storage; tasks that involve Secrets management; tasks that involve Cryptography.

How do I install Azure Keyvault Py in Claude Code?

Run `npx skills add microsoft/skills --skill azure-keyvault-py -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-keyvault-py in microsoft/skills) into .claude/skills/azure-keyvault-py in your project. Claude Code loads it when a task matches its description.

How do I install Azure Keyvault Py in Codex?

Run `npx skills add microsoft/skills --skill azure-keyvault-py -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-python/skills/azure-keyvault-py in microsoft/skills) into .agents/skills/azure-keyvault-py in your project. Codex loads it when a task matches its description.

Can I use Azure Keyvault Py in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-keyvault-py -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-keyvault-py, .gemini/skills/azure-keyvault-py, .github/skills/azure-keyvault-py and .opencode/skills/azure-keyvault-py in your project.

What does Azure Keyvault Py need to run?

Going by SKILL.md and its folder, Azure Keyvault Py needs the command-line tools its instructions call (pip) and credentials named AZURE_TOKEN_CREDENTIALS. Our summary lists: Python 3.

Does Azure Keyvault Py access the network?

SKILL.md names 1 domain. In commands or code: learn.microsoft.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Azure Keyvault Py safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Keyvault Py use?

Azure Keyvault Py is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Keyvault Py use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 587 tokens, read only when the agent opens those files.

What are the alternatives to Azure Keyvault Py?

Skills that share tags, products or a category with Azure Keyvault Py: Pki Design (vinayaklatthe/microsoft-security-skills, 175 stars), Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars), Apex Azure Compliance (jonathan-vella/apex, 217 stars) and Managing Workflow Secrets (bitwarden/ai-plugins, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Keyvault Py?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,091 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.