Hacker News new | past | comments | ask | show | jobs | submit login

Implementor here. Yep, this is correct: 2FA (TOTP currently, WebAuthn is in the pipeline[1]) will protect sign-ons in the PyPI web interface, and we (Trail of Bits) will be adding support for scoped API keys for uploads.

[1]: https://github.com/pypa/warehouse/pull/5795




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: