The leading native Python SSHv2 protocol library.
Python Groff
Latest commit 833d9f7 Jul 25, 2016 @bitprophet bitprophet Merge branch '2.0'
Failed to load latest commit information.
demos Use modern api to check if event is set. Dec 17, 2014
images [project @… Apr 18, 2005
paramiko Cut 2.0.2 Jul 26, 2016
sites Cut 2.0.2 Jul 26, 2016
tests Merge branch '1.17' into 2.0 Jun 12, 2016
.bzrignore [project @] Jul 6, 2008
.gitignore Merge branch 'master' into gssapi-py3-support Mar 26, 2014
.travis.yml Enabling caching of pip downloads and wheels Apr 25, 2016
ChangeLog.0 [project @… May 21, 2005
ChangeLog.1 [project @… May 21, 2005
LICENSE Fix FSF address Sep 23, 2012 [project @] Oct 31, 2006
NEWS Nuke sphinx-changelogg'd material Jan 30, 2014
NOTES [project @] Mar 9, 2004
README.rst Merge branch '1.17' Apr 29, 2016
TODO Take ownership of TODO file Sep 23, 2012
dev-requirements.txt Update tasks to use Invoke/Invocations 0.13 Jul 25, 2016
setup.cfg Omit _winapi from coverage, as it won't be invoked on Unix and is tes… Jul 22, 2016 Use a more recent cryptography and call a function Apr 28, 2016 Restore Python 2.6 compatibility for `python {s,b}dist' Sep 9, 2015 Update tasks to use Invoke/Invocations 0.13 Jul 25, 2016 Make NoValidConnectionsError picklable correctly Apr 24, 2016
tox-requirements.txt Use a more recent cryptography and call a function Apr 28, 2016
tox.ini removed references to python 3.2, which has basically no usage Aug 1, 2015


Paramiko:Python SSH module
Copyright:Copyright (c) 2003-2009 Robey Pointer <>
Copyright:Copyright (c) 2013-2016 Jeff Forcier <>
API docs:


"Paramiko" is a combination of the Esperanto words for "paranoid" and "friend". It's a module for Python 2.6+/3.3+ that implements the SSH2 protocol for secure (encrypted and authenticated) connections to remote machines. Unlike SSL (aka TLS), SSH2 protocol does not require hierarchical certificates signed by a powerful central authority. You may know SSH2 as the protocol that replaced Telnet and rsh for secure access to remote shells, but the protocol also includes the ability to open arbitrary channels to remote services across the encrypted tunnel (this is how SFTP works, for example).

It is written entirely in Python (though it depends on third-party C wrappers for low level crypto; these are often available precompiled) and is released under the GNU Lesser General Public License (LGPL).

The package and its API is fairly well documented in the docs folder that should have come with this archive.


For most users, the recommended method to install is via pip:

pip install paramiko

For more detailed instructions, see the Installing page on the main Paramiko website.

Portability Issues

Paramiko primarily supports POSIX platforms with standard OpenSSH implementations, and is most frequently tested on Linux and OS X. Windows is supported as well, though it may not be as straightforward.

Bugs & Support

Bug Reports:Github
Mailing (see the LibreList website for usage details).
IRC:#paramiko on Freenode

Kerberos Support

Paramiko ships with optional Kerberos/GSSAPI support; for info on the extra dependencies for this, see the GSS-API section on the main Paramiko website.


Several demo scripts come with Paramiko to demonstrate how to use it. Probably the simplest demo of all is this:

import paramiko, base64
key = paramiko.RSAKey(data=base64.decodestring('AAA...'))
client = paramiko.SSHClient()
client.get_host_keys().add('', 'ssh-rsa', key)
client.connect('', username='strongbad', password='thecheat')
stdin, stdout, stderr = client.exec_command('ls')
for line in stdout:
    print '... ' + line.strip('\n')

This prints out the results of executing ls on a remote server. The host key 'AAA...' should of course be replaced by the actual base64 encoding of the host key. If you skip host key verification, the connection is not secure!

The following example scripts (in demos/) get progressively more detailed: invoke_shell() and emulates a terminal/TTY through which you can execute commands interactively on a remote server. Think of it as a poor man's SSH command-line client. as, but allows you to authenticate using a private key, attempts to use an SSH agent if present, and uses the long form of some of the API calls. script to set up port-forwarding across an SSH transport. an SFTP session and does a few simple file operations. SSH server that listens on port 2200 and accepts a login for 'robey' (password 'foo'), and pretends to be a BBS. Meant to be a very simple demo of writing an SSH server. key generator similar to OpenSSH ssh-keygen(1) program with Paramiko keys generation and progress functions.


The demo scripts are probably the best example of how to use this package. There is also a lot of documentation, generated with Sphinx autodoc, in the doc/ folder.

There are also unit tests here:

$ python ./

Which will verify that most of the core components are working correctly.