Library / SDK
goldmansachs/gs-quant avatar
goldmansachs/gs-quant

GS Quant: Goldman Sachs publishes its institutional Python quant toolkit

Python toolkit for quantitative finance

12,994 stars1,754 forksPythonApache-2.0

At a glance

What is it?
GS Quant is an Apache 2.0 licensed Python package of statistical and financial primitives built by quants at Goldman Sachs, with the API access side reserved for institutional clients holding a client id and secret.
Who is it for?
GS Quant is two things at once, and the distinction decides whether it is useful to you. As a library of pricing, statistics and time series primitives it is unusually well maintained, Apache 2.0 licensed, publicly documented and installable in one line, and the release cadence shows it: release-2.1.16 shipped on 2026-09-16 after two in the same week.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 20 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 21, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Installing a package that most people cannot fully use

The install is the shortest line in the README:

bash
pip install gs-quant

The stated requirements are Python 3.9 or greater and access to the pip package manager. There is a small discrepancy worth knowing about: the repository's own `pyproject.toml` declares `requires-python = ">=3.10"` and lists classifiers for Python 3.10 through 3.13, so the packaging metadata is one release newer than the prose. Trust the metadata, since that is what pip reads.

Now the sentence that defines who this is for. The README states that to access the APIs you need a client id and secret, that these are available to institutional clients of Goldman Sachs, and that you should speak to your sales coverage or Marquee Sales. That is the boundary, stated once and plainly. Everything the package exposes for local analysis is available to anyone; the paths that talk to Goldman Sachs infrastructure are not.

What is public is the code, the documentation and the licence. The README calls it a Python toolkit for quantitative finance created on top of one of the world's most powerful risk transfer platforms, and states that it is created and maintained by quantitative developers at Goldman Sachs, with the framing of 25 years of experience navigating global markets. That is a claim about provenance rather than a feature list, and it is the reason a lot of people look at this package at all.

Derivative structuring, trading and risk, or plain statistics

The README offers two ways to think about what the package is for, and the second is the one that matters for most readers. It can be used to facilitate derivative structuring, trading and risk management, or as a set of statistical packages for data analytics applications. Read that as an honest admission that the numerical core is usable on its own, without any credentials.

The dependency list in `pyproject.toml` is the best available inventory of what is actually inside, and it is a serious one: numpy constrained above 1.17.0 and below 2.4.0, pandas at or above 1.4, scipy at or above 1.2.0, statsmodels at or above 0.14.5, lmfit for curve fitting, dataclasses_json, msgpack, pyyaml, tqdm, requests and httpx for transport, websockets for streaming, python-dateutil, and both opentelemetry-api and opentelemetry-sdk. Nest-asyncio and pydash below 7.0.0 are there too.

That is worth pausing on. statsmodels and lmfit in the same dependency tree tells you the package does real statistical work rather than only instrument arithmetic, and the OpenTelemetry pair tells you the session layer emits traces. If you already have a data stack, these dependencies are the actual integration surface you are signing up for, and the numpy upper bound below 2.4.0 is a constraint that will matter if your own code has already moved.

The optional extras extend that picture. A `notebook` group brings jupyter, matplotlib, seaborn and treelib for analysis work, a `test` group brings pytest with several plugins, freezegun, ruff and nbformat, a `develop` group brings sphinx and its theme, and an `internal` group references a separate `gs-quant-internal` package with a version constraint, which is the clearest hint in the tree about how the open and internal halves relate.

Packaging, versioning and what the repository tree reveals

The packaging story is modern but has both paths present. `pyproject.toml` is the real configuration: it requires setuptools 61 or newer together with versioneer 0.28, uses the setuptools build backend, marks the version as dynamic, and names Goldman Sachs as the author with a [email protected] contact. `setup.py` still exists alongside it and does nothing but hand control to versioneer, which is how the version number gets stamped from the repository rather than hardcoded.

Version stamping matters here because the tags do not look like ordinary semantic versions. The three most recent releases are named `release-2.1.16`, `release-2.1.15` and `release-2.1.14`, published on 2026-09-16, 2026-09-14 and 2026-09-09 respectively. So the project ships frequently, at least twice in the week before that, and all three release bodies are empty. There are no published upgrade notes for any of them, which means you cannot tell what changed between 2.1.14 and 2.1.16 from the releases page, and pinning a specific version is the safer choice than tracking the branch.

The tree also shows a project with real infrastructure around the package. There is a `.gitlab-ci.yml` alongside a `.github/` directory, both pre-commit configuration and a CODE_OF_CONDUCT.md, a CONTRIBUTING.md, and `conftest.py` at the root for pytest. `docs/` holds the documentation sources, `gs_quant/` the package itself, and `dco/` a developer certificate of origin directory, which tells you commits are signed off. `MANIFEST.in`, `setup.cfg`, `requirements.txt` and `versioneer.py` round out the build files, and there are two notice files, `NOTICE` and `NOTICE.txt`.

The `.gs-project.yml` file at the root is the one to look at if you want to understand how the internal and public repositories are related, and `.claude/` at the top of the tree suggests some tooling has been added for AI assisted development work on the repository itself.

Documentation lives off the repository, and licence terms are explicit

The README is short and everything else is a link. Examples, guides and tutorials are on Goldman Sachs Developer at developer.gs.com/docs/gsquant/, and the project homepage is developer.gs.com/discover/products/gs-quant. There is a documentation directory in the repository too, but the README's own guidance is to read the published site.

For questions there is an address rather than an issue tracker discussion: `[email protected]` is given for questions, comments and feedback. Whether the repository's issue tracker is the right channel for a bug is left unstated in the README, which is a mild gap for anyone expecting open source norms, though the presence of `CONTRIBUTING.md` and a code of conduct suggests the process exists.

The licence is Apache 2.0 and the attribution requirements are taken seriously enough to have two notice files. `setup.py` carries a full Apache License 2.0 header with the 2018 Goldman Sachs copyright, `NOTICE` and `NOTICE.txt` sit alongside the LICENSE file, and the pyproject metadata declares `license = {text = "Apache-2.0"}` with an Apache Software License classifier.

That combination is the practically useful part of this repository for someone outside Goldman Sachs. Apache 2.0 with a NOTICE file is about as permissive a licence as a commercial institution releases, and it permits use inside a proprietary product. If your legal team has opinions about depending on code originating in a bank's codebase, the answer here is that the licence was chosen to make that possible, and the notice file is what you keep.

Editorial conclusion

GS Quant is two things at once, and the distinction decides whether it is useful to you. As a library of pricing, statistics and time series primitives it is unusually well maintained, Apache 2.0 licensed, publicly documented and installable in one line, and the release cadence shows it: release-2.1.16 shipped on 2026-09-16 after two in the same week. As a client for Goldman Sachs services it is closed to anyone without institutional credentials, which the README states in two sentences without further elaboration. So read the dependency list before you install, because scipy, statsmodels, lmfit, pandas and numpy define what you already had installed. Start with the public API surface and the statistical packages, use the client id and secret path only if you are an institutional client, and pin a version rather than tracking master, since releases carry no published notes.

Frequently asked questions

Do I need a Goldman Sachs account to use GS Quant?

Not for the library itself, which installs from pip under an Apache 2.0 licence and contains statistical and derivative pricing code. The README states that accessing the APIs requires a client id and secret available to institutional clients, obtained through sales coverage or Marquee Sales.

What are the system requirements for installing GS Quant?

The README lists Python 3.9 or greater and access to pip. The repository's pyproject.toml is stricter and declares requires-python of 3.10 or greater, with classifiers for 3.10 through 3.13, so 3.10 is the version to plan around.

How is GS Quant versioned and how often does it release?

Tags are named release-2.1.14 and upward rather than using plain semantic version tags, and versioneer stamps the version from the repository rather than a hardcoded value. The three most recent releases, 2.1.14, 2.1.15 and 2.1.16, were published on 2026-09-09, 2026-09-14 and 2026-09-16, and all three have empty release bodies.

What licence does GS Quant ship under?

Apache 2.0. The metadata in pyproject.toml declares it, setup.py carries the full licence header with 2018 Goldman Sachs copyright, and the repository carries both a LICENSE file and two NOTICE files to preserve attribution.

Official sources

  1. goldmansachs/gs-quant on GitHub
  2. License: Apache-2.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/goldmansachs-gs-quant.svg)](https://hysenlabs.com/projects/goldmansachs-gs-quant)