CLI tool
ktbyers/netmiko avatar
ktbyers/netmiko

Netmiko: show commands and config changes, minus the regex scraping

Multi-vendor library to simplify Paramiko SSH connections to network devices

4,300 stars1,387 forksPythonMIT

At a glance

What is it?
Netmiko is Kirk Byers' MIT-licensed multi-vendor Python library that simplifies Paramiko SSH connections to network devices, gathering show command output and making configuration changes across a very broad set of platforms while hiding the low-level prompt and pattern handling. It runs on Python 3.10 through 3.14, ships five CLI tools, and its current release is 4.8.0 from September 2026.
Who is it for?
Use Netmiko when Python automation needs to talk CLI to routers, switches and firewalls across vendors, since its device abstraction turns two operations, show output and configuration, into method calls instead of expect scripts. Prefer NAPALM or an API based approach where the platform exposes structured interfaces rather than a CLI, since Netmiko's whole premise is wrapping the legacy path.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 12 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 3, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Two operations, every vendor, no expect scripts

The why is stated narrowly and well, network automation to screen-scraping devices is primarily concerned with gathering output from show commands and with making configuration changes, and Netmiko aims to accomplish both across a very broad set of platforms. The part that earns the library its following is the second clause, doing it while abstracting away low-level state control, eliminating low-level regex pattern matching to the extent practical. Anyone who has maintained an expect script that breaks when a vendor changes a prompt string understands what is being eliminated, the per device negotiation of prompts, paging and modes that makes raw Paramiko sessions to network gear tedious. Netmiko absorbs that state machine per platform and leaves the caller with two verbs.

A dictionary, a handler, two methods

The getting started flow is three short steps. First a dictionary describing the device, with device_type selecting the driver, here cisco_ios, and host, username and password, plus optional port defaulting to 22 and secret defaulting to empty:

py
from netmiko import ConnectHandler

cisco_881 = {
    "device_type": "cisco_ios",
    "host": "10.10.10.10",
    "username": "test",
    "password": "password",
    "port": 8022,  # optional, defaults to 22
    "secret": "secret",  # optional, defaults to ''
}

Then a connection, net_connect = ConnectHandler(**cisco_881), and then the two verbs, send_command("show ip int brief") returning the show output as text, and send_config_set with a list of commands, which automatically enters configuration mode, applies them and exits, the documented example flipping logging buffered settings and echoing the router's config session verbatim. The device dictionary pattern scales into inventories naturally, the examples include conn_multiple_dev.py showing several devices in sequence and conn_with_dict_cm.py using the connection as a context manager for guaranteed cleanup, small variations that cover the two ways scripts actually grow.

Paramiko underneath, with version pins to choose

The relationship to Paramiko is compositional, Netmiko builds on Paramiko's SSH implementation rather than replacing it, and its dependency list shows the supporting cast, paramiko at 3.5.1 or later, scp for secure copy, pyyaml, textfsm with ntc-templates for structured parsing, pyserial for serial connections, and rich for terminal output. Because Paramiko's major versions have compatibility consequences, the project offers explicit choices, a par4 extra pinning paramiko at 4.x for Paramiko 4 compatibility, installed with pip install "netmiko[par4]", and a paramiko5 dependency group for testing against the next major. Installation itself is pip install netmiko, with the bulk-encrypt extra adding the bulk encryption CLI and its ruamel.yaml dependency. Python support spans 3.10 through 3.14. The dev tooling mirrors the care, ruff for format, mypy for types, pytest with coverage, and bandit with pip-audit on the security side, sensible additions for a library whose entire job is holding credentials and opening connections.

Autodetect, redispatch, and the dispatcher table

Three entries in the API's handy classes list solve the discovery problems of heterogeneous fleets. SSH Autodetect, the SSHDetect class, probes a device to infer its type when you do not know it. The SSH Dispatcher is the registry itself, the CLASS_MAPPER keys in ssh_dispatcher.py enumerating every supported device_type, which is the authoritative platform list to consult before writing a dictionary. And Redispatch changes an existing connection's driver mid session, the companion to autodetect, connecting generically, detecting, then switching to the right driver without tearing down the SSH session. The examples directory shows the pattern in files for autodetect over SSH and over SNMP including v3, alongside session logging, delay factor tuning and enable mode handling.

Structured output through TextFSM and friends

Show output as raw text is half a solution, and Netmiko integrates the parsing layers that make it data. The textfsm and ntc-templates dependencies provide template based parsing of show commands into lists of dictionaries, and the examples cover three more parsers, Genie for the Cisco pyATS style parsers, TTP for template based extraction, and command_prompting variants for interactive commands. Secure copy has its own example and tutorial, as does operating through an SSH proxy, and a dedicated tutorial covers what constitutes done, the surprisingly deep question of when a CLI command has actually finished on a slow device. The tutorials live on the author's Python for Network Engineers blog, matching the course context the library grew out of. The session_log example deserves a mention too, logging the entire raw session to a file, which is the debugging tool that shows exactly what the library sent and what the device answered when a script misbehaves.

Five CLI tools, including bulk encryption

Beyond the library, the package installs five command line tools, netmiko-grep for searching across device output, netmiko-show for running show commands, netmiko-cfg for configuration, and netmiko-encrypt plus netmiko-bulk-encrypt for credential handling, the last requiring the bulk-encrypt extra. The existence of an encryption toolchain points at a real operational concern, device passwords in configuration files and inventory sources, and a dedicated ENCRYPTION_HANDLING.md documents the approach for teams that need it. The netmiko-grep entry in particular shows the library's floor, grep across network devices is the two word summary of what network engineers do all day, and here it is an installed command.

Add a vendor, bring test data

The contribution rules are protective of quality in a specific way, before contributing a new vendor or platform device type, remember that any code added needs to be supported in some fashion, and a new driver must include test data to be merged into develop, following VENDOR.md for the outline and TESTING.md for the flow. All code contributions must pass ruff format or they fail the CI checks, stated as a flat requirement. Questions route to the #netmiko channel in the pynet Slack workspace, with issues reserved for bugs and feature requests rather than usage questions. The project is authored by Kirk Byers of Python for Network Engineers, sponsored in 2025 by Slurpit and NetPicker, and releases steadily, 4.6.0 in June 2025, 4.7.0 in May 2026 and 4.8.0 on 2026-09-21, the same day as the last push.

Editorial conclusion

Use Netmiko when Python automation needs to talk CLI to routers, switches and firewalls across vendors, since its device abstraction turns two operations, show output and configuration, into method calls instead of expect scripts. Prefer NAPALM or an API based approach where the platform exposes structured interfaces rather than a CLI, since Netmiko's whole premise is wrapping the legacy path. Before deploying, check PLATFORMS.md for your device type, read COMMON_ISSUES.md for the known sharp edges, choose the Paramiko version pin deliberately through the par4 extra if compatibility demands it, and look at EXAMPLES.md first, the project's own advice in bold, before writing anything from scratch.

Frequently asked questions

What is Netmiko used for?

Netmiko is used for network automation over CLI connections, gathering output from show commands and making configuration changes across a very broad set of platforms. It abstracts away low-level state control, eliminating regex pattern matching against device prompts to the extent practical.

What is the relationship between Netmiko and Paramiko?

Netmiko is built on top of Paramiko, the SSH library, simplifying its use for network devices. Paramiko provides the SSH transport, while Netmiko adds the multi-vendor device handling, and a par4 extra exists to install with Paramiko 4 compatibility pinned.

How do I install Netmiko?

Run pip install netmiko, optionally with pip install "netmiko[par4]" for Paramiko 4 compatibility or pip install "netmiko[bulk-encrypt]" for the bulk-encryption CLI. It requires Python 3.10 through 3.14.

how to use netmiko in python?

Create a dictionary with device_type, host, username and password, pass it to ConnectHandler to establish the SSH connection, then call send_command for show commands and send_config_set for configuration changes, which automatically enters config mode. Supported device_type values are the CLASS_MAPPER keys in ssh_dispatcher.py.

Official sources

  1. Issues
  2. ktbyers/netmiko on GitHub
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/ktbyers-netmiko.svg)](https://hysenlabs.com/projects/ktbyers-netmiko)