Paramiko: The Python Library for Low-Level SSH Access
The leading native Python SSHv2 protocol library.
At a glance
- What is it?
- Paramiko is a pure-Python implementation of the SSHv2 protocol, providing both client and server functionality as a low-level library. It is the foundation for the higher-level Fabric library, but its direct use is intended for developers who need raw SSH primitives or want to run an SSH server written in Python.
- Who is it for?
- Paramiko belongs in any Python codebase that needs direct, low-level control over SSH sessions, SFTP transfers, or an in-process SSH server. It is the wrong choice for developers who simply want to run remote shell commands or transfer files from Python: the README explicitly recommends using Fabric for those common cases.
- Can I use it commercially?
- Yes, with conditions. LGPL-2.1 is a weak copyleft licence: you can use it inside commercial and closed-source software, but if you distribute changes to its own files, you must publish those changes under the same licence.
- Is it still maintained?
- Yes. The repository last received commits 31 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Paramiko Is and Who Uses It
Paramiko is a pure-Python implementation of the SSHv2 protocol. It handles the cryptographic handshake, key exchange, channel multiplexing, and authentication that SSH requires, then exposes those mechanisms through a Python API. The name is documented on the project website at paramiko.org rather than in the README, which states only that the library implements SSHv2.
The README is direct about who should use Paramiko directly: users who need advanced or low-level primitives, or who want to run an in-Python SSH server. For the common case, meaning running shell commands on a remote machine or transferring files, the README recommends Fabric, which is a higher-level library built on top of Paramiko. This is an unusual positioning for an open-source library: the primary README actively redirects most users to a different project.
The practical consequence is that Paramiko's direct users tend to be infrastructure automation authors, security tooling developers, and library authors who are building SSH-based tools of their own. Deployment automation platforms, network management frameworks, and SSH gateways commonly depend on Paramiko as a foundational layer.
SSHv2 Protocol Implementation: Client and Server Roles
Paramiko implements both sides of the SSH protocol. The client side handles connecting to a remote SSH server, authenticating, opening channels, executing commands, and managing SFTP sessions. The server side allows Python code to act as an SSH server that accepts connections from SSH clients.
The cryptographic operations in Paramiko do not rely on Python's standard library alone. The library delegates crypto work to the cryptography package, which uses C and Rust extensions. This means Paramiko itself is pure Python in the sense that no C extension code lives in the paramiko package, but the dependency chain includes compiled code. The README notes that many precompiled options for the cryptography package are available, which simplifies installation in most environments.
OpenSSH is Paramiko's primary reference implementation. When the Paramiko developers encounter ambiguous behavior or gaps in the specification, they consult how OpenSSH handles the situation. The README links to OpenSSH's RFC specification page as a resource. This gives Paramiko a practical compatibility baseline that is widely deployed and broadly understood.
Installing Paramiko and Connecting to a Remote Server
Paramiko is available on PyPI. The standard installation is:
pip install paramikoThe package is at version 5.0.0 and supports Python 3.9 through 3.13. Its direct dependencies as declared in pyproject.toml are bcrypt (3.2 or later), cryptography (3.3 or later), invoke (2.0 or later), and pynacl (1.5 or later). These are pulled automatically by pip.
For Windows-specific setups, a Dockerfile.i386 is present in the repository for i386 environments, suggesting the project has historically supported that architecture. The main project website at paramiko.org and the versioned API docs at docs.paramiko.org contain installation instructions that cover edge cases and platform-specific notes that the README does not reproduce.
Paramiko vs. Fabric: When to Use Each
Fabric is built on Paramiko and provides a higher-level API designed for tasks like running shell commands, uploading files, and orchestrating remote operations across multiple hosts. The README recommends Fabric for "common client use-cases such as running remote shell commands or transferring files."
Choosing between them comes down to abstraction level. If the task is running a deploy script, rsync-ing files, or checking server status, Fabric handles the boilerplate. If the task is implementing a custom SSH proxy, handling raw channel data, implementing a nonstandard authentication scheme, or building a server that accepts SSH connections, Paramiko is the correct layer to work at.
There is also a maintenance consideration. Paramiko is the lower-level dependency, and changes to it propagate to Fabric. If a project upgrades Paramiko and Fabric has not yet updated to match, there can be compatibility friction. Projects that use Paramiko directly have more direct control over which version they are running.
Limitations and Known Pain Points
Paramiko does not implement the full SSHv2 specification. The README acknowledges this directly: "There are always some gaps, but we do our best to reconcile them when possible." Teams working with less common SSH configurations or edge cases in the protocol may encounter missing features or subtle behavior differences compared to OpenSSH.
The library's low-level API surface is large and requires understanding of SSH concepts to use correctly. Authentication failure messages, key format requirements, and host key verification all need explicit handling. Developers accustomed to high-level SSH clients may find that getting a working connection requires more code than expected.
The LGPL-2.1 license means that modifications to Paramiko itself must be released under the same license, but code that merely uses Paramiko as a library can remain under a different license. The distinction matters for developers embedding Paramiko in a larger application rather than distributing a modified version of the library. Legal interpretation of LGPL in specific distribution scenarios requires independent review.
Security Model and Cryptographic Dependencies
SSH security depends on correct host key verification, and Paramiko puts the responsibility on the caller to verify host keys. A connection that skips host key verification is vulnerable to man-in-the-middle attacks. The project's SECURITY.md is present in the repository for reporting vulnerabilities.
The cryptographic backend is the cryptography package, which uses C and Rust extensions compiled against OpenSSL or a compatible library. pynacl, a dependency that provides NaCl-based cryptography for modern key types, is also required. These dependencies cover modern key exchange algorithms and ciphers, but the exact set of supported algorithms in a given Paramiko version should be verified against the versioned documentation at docs.paramiko.org rather than assumed from general knowledge.
Bcrypt is required for SSH private key encryption support. Its presence as a hard dependency means any environment running Paramiko must have bcrypt installed, even in scenarios where encrypted private keys are not used.
License, Maintenance, and Version Support
Paramiko is licensed under LGPL-2.1. Version 5.0.0 is the current release, with Python support spanning 3.9 through 3.13 as declared in pyproject.toml. The changelog is maintained at paramiko.org/changelog.html.
The last push to the repository was on 2026-08-29. The repository has no GitHub releases currently listed, but the project website hosts the changelog and installation documentation independently. CircleCI is configured as the CI system, with coverage tracked via Codecov.
The dev tooling includes flake8 for linting, black 22.12.0 as the pinned formatter, codespell for spelling checks, and pytest-relaxed for testing. The tasks.py file in the repository root handles common developer workflows through the invoke library, which is also listed as a hard runtime dependency.
Editorial conclusion
Paramiko belongs in any Python codebase that needs direct, low-level control over SSH sessions, SFTP transfers, or an in-process SSH server. It is the wrong choice for developers who simply want to run remote shell commands or transfer files from Python: the README explicitly recommends using Fabric for those common cases. Before adding Paramiko to a project, verify that LGPL-2.1 is compatible with your distribution model, since the license imposes requirements that differ from permissive licenses like MIT or Apache-2.0.
Frequently asked questions
What is Paramiko used for?
Paramiko is used for low-level SSH access from Python: connecting to remote servers, opening channels, performing SFTP transfers, running commands programmatically, and building in-process SSH servers. For higher-level tasks like running deploy scripts, the README recommends using Fabric, which is built on Paramiko.
Is Paramiko deprecated?
The README does not indicate deprecation. Version 5.0.0 is the current release supporting Python 3.9 through 3.13, and the last push to the repository was on 2026-08-29. The project website at paramiko.org and versioned documentation at docs.paramiko.org remain active.
How do I install Paramiko?
Run `pip install paramiko` to install the package from PyPI. It requires Python 3.9 or later and pulls bcrypt, cryptography, invoke, and pynacl as automatic dependencies. For platform-specific notes, see the installation page at paramiko.org.
How do I use Paramiko to connect over SSH from Python?
Paramiko provides an SSHClient class for client connections. The API documentation at docs.paramiko.org covers connecting, authenticating with passwords or keys, running commands, and opening SFTP sessions. The README directs common use cases toward Fabric for a higher-level interface.
Is Paramiko good?
Paramiko is at version 5.0.0 with support for Python 3.9 through 3.13 and is the documented foundation for the Fabric library. It implements SSHv2 with OpenSSH as the reference implementation. The README acknowledges gaps in specification coverage, which is a known limitation.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/paramiko-paramiko)