🌐
GitHub
github.com › pyca › cryptography › blob › main › src › cryptography › fernet.py
cryptography/src/cryptography/fernet.py at main · pyca/cryptography
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. - cryptography/src/cryptography/fernet.py at main · pyca/cryptography
Author: pyca
Discussions

python - Is the Fernet cryptography module safe, and can I do AES encryption with that module? - Stack Overflow
Can I do AES encryption with the Fernet cryptography module? What is Fernet, and is it safe like AES encryption? More on stackoverflow.com
🌐 stackoverflow.com
Is Fernet Still a Good Choice?
You might find this interesting: https://soatok.blog/2020/05/13/why-aes-gcm-sucks/ More on reddit.com
🌐 r/crypto
19
27
May 5, 2021
Does anyone know if Fernet's python encryption is secure?
Fernet is a different use case, it's a library along the lines of libsodium. It's certainly harder to misuse than OpenSSL's libraries, but still quite doable. Fernet, per the user guide, takes a raw AES key for encryption. There's an awful lot of room for you to generate a string of null bytes, or do the classic "my key was a base64 string". There are instructions on how to password auth but then it's just to copy paste a PBKDF snippet, which again, you could do well, or not so well. More on reddit.com
🌐 r/crypto
26
15
July 10, 2021
Encrypting strings in code: Fernet still acceptable in 2024?
I'll generate a key and store this key in a text file This is not really much different than storing your secret directly in the code. It's just one extra step to get your secret. You could just as easily make your script only readable by the user and put your secrets in there and not much changes, in terms of security. More on reddit.com
🌐 r/learnpython
5
6
May 14, 2024
🌐
Medium
medium.com › @rahulgosavi.94 › fernet-encryption-and-decryption-2101f0e3097a
Encryption and Decryption with Fernet in Python | by Rahul Gosavi | Medium
October 7, 2024 - One of the user-friendly and secure ... part of the Cryptography library in Python, Fernet offers a simple and effective way to encrypt and decrypt messages using symmetric encryption....
🌐
GeeksforGeeks
geeksforgeeks.org › python › fernet-symmetric-encryption-using-cryptography-module-in-python
Fernet (symmetric encryption) using Cryptography module in Python - GeeksforGeeks
September 28, 2020 - Python supports a cryptography package that helps us encrypt and decrypt data. The fernet module of the cryptography package has inbuilt functions for the generation of the key, encryption of plaintext into ciphertext, and decryption of ciphertext ...
🌐
DEV Community
dev.to › anishde12020 › cryptography-with-python-using-fernet-40o3
Cryptography with Python using Fernet - DEV Community
April 10, 2021 - Let us look at how to encrypt text and files using Python. For this we are going to be using Fernet which is a part of python's cryptography package
🌐
PyPI
pypi.org › project › cryptography
cryptography · PyPI
Our goal is for it to be your “cryptographic standard library”. It supports Python 3.9+ and PyPy3 7.3.11+. cryptography includes both high level recipes and low level interfaces to common cryptographic algorithms such as symmetric ciphers, message digests, and key derivation functions. For example, to encrypt something with cryptography’s high level symmetric encryption recipe: >>> from cryptography.fernet import Fernet >>> # Put this somewhere safe!
🌐
TutorialsPoint
tutorialspoint.com › article › fernet-symmetric-encryption-using-a-cryptography-module-in-python
Fernet (Symmetric Encryption) using a Cryptography Module in Python
August 10, 2023 - from cryptography.fernet import Fernet # Generate a key key = Fernet.generate_key() fernet = Fernet(key) # Original message message = "This is a confidential message" print("Original Message:", message) # Encrypt the message encrypted_message = fernet.encrypt(message.encode()) print("Encrypted Message:", encrypted_message) # Decrypt the message decrypted_message = fernet.decrypt(encrypted_message) print("Decrypted Message:", decrypted_message.decode())
🌐
Comparitech
comparitech.com › home › blog › information security › what is fernet encryption?
What is Fernet? Secure data encryption in Python
July 6, 2026 - Fernet is a specification for symmetric authenticated encryption that forms part of the PyCa cryptography library — the Python Cryptographic Authority’s actively maintained cryptography package for Python developers.
Find elsewhere
🌐
Anishde
blog.anishde.dev › cryptography-with-python-using-fernet
Cryptography with Python using Fernet - AnishDe12020
September 14, 2021 - Let us look at how to encrypt text and files using Python. For this we are going to be using Fernet which is a part of python's cryptography package
🌐
Bytescrum
blog.bytescrum.com › encrypting-and-decrypting-data-with-fernet-in-python
Encrypting and Decrypting Data with Fernet in Python
May 8, 2024 - Let's dive into the Python code to see how Fernet can be used to protect your data. ... you need a secret key. This key is crucial, as it's used for both encryption and decryption. Here's how you can generate a unique encryption key: from cryptography.fernet import Fernet from getpass import getpass def generate_key(secret_key): return Fernet.generate_key() + secret_key.encode()
🌐
Pythonista Planet
pythonistaplanet.com › fernet
A Deep Dive Into Fernet Module in Python – Pythonista Planet
August 8, 2022 - Fernet is a Python module under the Cryptography package which uses a unique key to encrypt and decrypt the data. In this article, we will…
🌐
8gWiFi
8gwifi.org › home › cryptography › fernet encrypt & decrypt online - key generator
Fernet Encrypt & Decrypt Online - Key Generator | 8gwifi.org
January 1, 2024 - This Fernet encryption/decryption tool is maintained by Anish Nath. It implements the standard Fernet specification as defined by the Python cryptography library.
🌐
Tech Couch
tech-couch.com › post › encrypting-data-in-python-with-fernet
Encrypting data in python with fernet - Tech Couch
November 1, 2025 - Consider the fernet_files module for file encryption, which takes care of encrypting file contents in chunks, together with a secure storage format and resistance against chunk reordering and similar attacks.
🌐
YouTube
youtube.com › watch
Fernet in Python: Encrypt & Decrypt Files (Beginner Tutorial) - YouTube
Have you ever wanted to protect your sensitive files with a strong password? In this video, we're diving into the world of cryptography to build a simple, ye...
Published: June 9, 2025
🌐
SecValley
secvalley.com › home › insights › fernet encryption in python: a practical guide
Fernet Encryption in Python: A Practical Guide | SecValley
January 23, 2026 - Fernet is part of Python's cryptography library. It handles symmetric encryption - meaning you use the same key to encrypt and decrypt. But it's not just a thin wrapper around AES.
      » pip install python-cryptography-fernet-wrapper
    
Published: Jul 10, 2021
Version: 1.0.4
Top answer
1 of 2
38

Fernet made more sense before GCM came around, as correctly implementing CBC + HMAC by yourself is difficult, and the CBC mode requires padding to 16 byte blocks.

It is still safe but I would not recommend it for new systems because AES256-GCM combines encryption and authentication into the same standard protocol, which can be en/decrypted by browsers (Javascript subtle crypto API) and all other crypto libraries and tools, not just the Python cryptography module. The GCM mode is also a lot faster, reaching several gigabytes per second with AES-NI.

It is unfortunate that it is hidden deep inside the hazmat module:

import secrets
from cryptography.hazmat.primitives.ciphers.aead import AESGCM

# Generate a random secret key (AES256 needs 32 bytes)
key = secrets.token_bytes(32)

# Encrypt a message
nonce = secrets.token_bytes(12)  # GCM mode needs 12 fresh bytes every time
ciphertext = nonce + AESGCM(key).encrypt(nonce, b"Message", b"")

# Decrypt (raises InvalidTag if using wrong key or corrupted ciphertext)
msg = AESGCM(key).decrypt(ciphertext[:12], ciphertext[12:], b"")

Even with the same key and the same message, the ciphertext will always be completely different (because of a different nonce). Do note that ciphertext is always exactly 28 bytes longer than the message, so if the message length needs to be hidden, you could pad all messages to same length before encryption.

2 of 2
16

As Scott Arciszewski answered in a comment, Fernet is basically AES128 in CBC mode with a SHA256 HMAC message authentication code.

A full specification of the Fernet construction can be found here.

🌐
Medium
parthibanmarimuthu.medium.com › securely-encrypting-sensitive-data-in-python-with-fernet-dd50638bde0f
Securely Encrypting Sensitive Data in Python with Fernet | by Parthiban Marimuthu | Medium
March 14, 2025 - Here’s a straightforward way to secure these using Python. ... You can generate a consistent encryption key from a strong passphrase. Here’s how: from cryptography.fernet import Fernet import hashlib, base64 passphrase = "your_secure_passphrase" key = base64.urlsafe_b64encode(hashlib.sha256(passphrase.encode()).digest()) print("Your Fernet Key:", key.decode())
🌐
Hashnode
aythedataguy.hashnode.dev › writing-an-encryption-script-using-fernet-cryptography-in-python
Cryptography In Python using Fernet - Ayobami Alaran
July 16, 2023 - The encode() method is used the convert the string data to a binary representation for Fernet and decode() is used to convert the binary data back to a string for the user. Now, let's add the logic to encrypt or decrypt from the command line ...