PyPI
PyPI is the official, non-profit Python Package Index operated by the Python Software Foundation, enabling Python developers to discover, install, and publish 838,000+ software packages used by 1M+ registered users worldwide.
- Company typePrivate
- Founded2003
- HeadquartersLeicester, United Kingdom
- Headcount11–50
- GTM typeB2C
- OfferingSoftware
What PyPI does
PyPI (the Python Package Index) is the official, community-governed package repository for the Python programming language, operated by the Python Software Foundation, a US 501(c)(3) non-profit. Founded in 2003, the platform enables Python developers to discover, install, and publish software packages, currently hosting 838,703 projects, 9,000,092 releases, 19,691,368 files, and 1,077,306 registered user accounts across 41.5 TB of total package storage. The platform is built on Warehouse, an open-source codebase maintained at github.com/pypi/warehouse, and serves as the default distribution channel integrated into Python packaging tools including pip and uv.
The technical stack has evolved from a basic package index into supply-chain security infrastructure. Core features include Trusted Publishers (OIDC-based publishing that eliminates long-lived API tokens), Digital Attestations implementing PEP 740 with SLSA Provenance verification, and a Secret Reporting API that enables third parties such as GitHub and deps.dev to automatically revoke leaked PyPI API tokens. Data services include BigQuery public datasets (streaming file_downloads and distribution_metadata) and three RSS feeds for monitoring package activity. Multiple REST APIs (JSON, Index PEP 503/691, Upload, Integrity, Stats) expose machine-readable access, and CDN-cached delivery via Fastly supports global downloads at scale.
PyPI operates as a non-commercial service with no pricing model or direct revenue stream. Funding derives from corporate infrastructure sponsorships (AWS for cloud and security, Google for download analytics, Datadog for monitoring, Fastly for CDN, and others) and donations to the PSF Packaging Workgroup. Operating cost allocation per available disclosure is approximately 25% bandwidth, 18% storage, 15% compute, and 12% malware mitigation. The registry's strategic significance has grown with AI/ML adoption: frameworks like LangChain and LiteLLM depend on PyPI, and the platform has faced repeated supply-chain attacks (LiteLLM compromise in March 2026 reaching ~40,000 downloads, Microsoft durabletask SDK compromise in May 2026, Hades campaign in June 2026). In September 2025, PyPI joined seven other major open-source foundations in a joint warning that current funding models for critical package registries are unsustainable.
PyPI firmographics
Firmographics- Name
- PyPI
- Legal name
- Python Software Foundation
- Website
- https://pypi.org
- Company type
- Private
- Founded year
- 2003
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- PyPI is the official, non-profit Python Package Index operated by the Python Software Foundation, enabling Python developers to discover, install, and publish 838,000+ software packages used by 1M+ registered users worldwide.
- Ownership category
- akta.pro rank
PyPI industry classification
Industry- Product category
- Package Repository
- NAICS
- Software Publishers (51321)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
Keywords
Where PyPI is headquartered
LocationHeadquarters
- HQ city
- Leicester
- HQ country
- United Kingdom
- HQ region
- Europe
Markets served
PyPI business model
Business model- GTM type
- B2C
- Offering type
- Software
- Cost components
- Infrastructure, Operations, Technology or R&D, Personnel
Distribution channels4 records
Marketing channels4 records
PyPI product offering
Product offeringCore offering
PyPI is the official repository of software for the Python programming language, hosting 838,703 projects, 9,000,092 releases, and 19,691,368 files totaling 41.5 TB. It enables Python developers to find, install, and publish software packages through the Warehouse platform, supporting trusted publishing workflows, digital attestations (PEP 740), and SLSA provenance verification for supply chain security.
Product overview
PyPI is a unified package hosting platform and repository service for the Python programming language. The core offering is the package index itself, which hosts over 838,000 projects and 9 million releases. Security features include Trusted Publishers (OIDC-based cryptographic publishing workflow), Digital Attestations (PEP 740 implementation), and a Secret Reporting API for automatic token revocation. Data services include BigQuery public datasets, RSS feeds, and multiple REST APIs (JSON, Index, Upload, Integrity, Stats).
Differentiator
Problem solved
Functional benefit
Products and services
- PyPI (Python Package Index) The official repository of Python packages, hosting 838,703 projects, 9,000,092 releases, and 19,691,368 files. PyPI enables Python developers to find, install, and publish software packages through the Warehouse platform.
- Trusted Publishers OpenID Connect (OIDC)-based publishing workflow that eliminates the need for long-lived API tokens, allowing projects to publish from CI/CD systems like GitHub Actions with cryptographic identity verification.
- Digital Attestations PyPI's implementation of PEP 740, providing cryptographic attestations for package releases that bundle provenance information with publisher identity for supply chain security.
- BigQuery Public Datasets Public datasets including file_downloads (streaming download logs from Linehaul) and distribution_metadata (immutable metadata dump of all releases), licensed under Creative Commons Attribution 4.0.
- RSS Feeds Three RSS feeds providing access to newest packages (packages.xml), latest updates (updates.xml), and per-project release feeds for staying current with package changes.
- Secret Reporting API API for third parties (GitHub, deps.dev) to report accidentally exposed PyPI API tokens using ECDSA signatures, enabling automatic token revocation for affected users.
Companies that use PyPI
Customer profileSegments2 records
Ideal customer profiles2 records
PyPI technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
PyPI partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core and supporting.
- AWS (Amazon Web Services)coreAWS provides cloud computing infrastructure sponsorship for PyPI, helping support the massive scale of package distribution (41.5 TB total) and serving millions of downloads.
- GooglecoreGoogle provides download analytics sponsorship and supports PyPI infrastructure, contributing to the sustainability of Python's package ecosystem.
- DatadogcoreDatadog provides monitoring services for PyPI, helping track performance and availability of the package index infrastructure.
- FastlycoreFastly provides CDN services for PyPI, enabling fast global delivery of Python packages to users worldwide.
- DepotsupportingDepot provides continuous integration services sponsorship for PyPI's build and release infrastructure.
- PingdomsupportingPingdom provides monitoring services to track PyPI's uptime and performance status.
- SentrysupportingSentry provides error logging services to help PyPI developers identify and resolve issues in the platform.
- StatusPagesupportingStatusPage provides status page services for PyPI, enabling transparent status communication to users.
- Python Software FoundationcorePSF is the non-profit organization that owns and governs PyPI. The Packaging Workgroup within PSF handles fundraising and disbursement for PyPI, pip, packaging.python.org, setuptools, and cross-project packaging efforts.
Scale indicators6 records
Recent moves6 records
Expansion highlights5 records
PyPI competitors and assessment
Company assessmentDirect peers
- Hex: The official package manager for the Elixir/Erlang ecosystem. Provides the same discover-install-publish workflow as PyPI for Elixir, operating under a small non-profit/community governance model.
- crates.io: The official Rust package registry. Mirrors PyPI's role for the Rust ecosystem: community-hosted packages, package manager integration (Cargo), and developer distribution. Comparable scale and operating model.
- Maven Central: The primary package repository for Java/JVM artifacts. Operates the same registry-plus-search-plus-distribution model as PyPI for the Java ecosystem, currently operated by Sonatype.
- npm: The official package registry for JavaScript/Node.js and the closest analogue to PyPI. Operates the same model — community-governed package hosting, search, install via package managers, supply-chain security features — at even larger scale, making it the most directly comparable package registry peer.
- NuGet: Microsoft's package manager and repository for .NET libraries. Provides the same developer-facing function for the .NET ecosystem that PyPI provides for Python — package discovery, installation, and publishing.
- CPAN: The Comprehensive Perl Archive Network, one of the oldest community-driven package repositories. Same function as PyPI for Perl — community-hosted package distribution — though older and with a different architectural approach.
- pkg.go.dev: The official Go package discovery and documentation site, backed by the Go module proxy. Comparable to PyPI in role — primary distribution and discovery layer for Go modules — though with a different proxy-based architecture.
- RubyGems: The official package hosting service for Ruby gems. Same core function as PyPI — discovery, installation, and distribution of language-specific packages — operated under a similar community/non-profit governance model.
Broad incumbents
- JFrog Artifactory: A commercial universal package management platform supporting many ecosystems including Python. Not a direct competitor to PyPI's free public index, but the dominant enterprise private-registry and binary-repository incumbent that enterprises use alongside PyPI.
Emerging players
- ConanCenter: The package registry for Conan, a C/C++ package manager. Covers an adjacent programming ecosystem with similar registry-plus-distribution mechanics but at smaller scale and with a more commercialized operating model than PyPI.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
PyPI social profiles
Digital presencePyPI financial estimates
Financial estimateRevenue estimate
Valuation estimate
PyPI leadership team
Management profileNumber of profiles
PyPI funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
PyPI M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about PyPI
What does PyPI do?
PyPI is the official repository of software for the Python programming language, hosting 838,703 projects, 9,000,092 releases, and 19,691,368 files totaling 41.5 TB. It enables Python developers to find, install, and publish software packages through the Warehouse platform, supporting trusted publishing workflows, digital attestations (PEP 740), and SLSA provenance verification for supply chain security.
Is PyPI a public or private company?
PyPI is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was PyPI founded?
PyPI was founded in 2003. It employs 11 to 50 people.
Where is PyPI based?
PyPI is headquartered in Leicester, United Kingdom, in the Europe region.
Who are PyPI's main competitors?
Direct peers on record are Hex, crates.io, Maven Central, npm, NuGet, CPAN, pkg.go.dev and RubyGems. JFrog Artifactory is listed as a broad incumbent. ConanCenter is listed as an emerging player.
Does PyPI have an API?
Yes. PyPI offers multiple public API endpoints: JSON API for retrieving project metadata and release information; Index API (PEP 503/691) for listing projects and getting distribution download URLs; Upload API for publishing packages via multipart/form-data; Integrity API for accessing PEP 740 attestations and provenance; Stats API for package size statistics; RSS Feeds for newest packages and latest updates; BigQuery public datasets for download statistics and distribution metadata analysis; Secret reporting API for third-party token disclosure. PyPI's APIs are cached by CDN, require appropriate Accept headers, and should use unique User-Agent headers for bulk requests. No rate limiting at edge but XML-RPC API may be limited. Developer documentation is at docs.pypi.org.
What industry is PyPI in?
PyPI's product category is Package Repository. Its primary akta.pro industry code is HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its NAICS code is 51321 and its SIC code is 7372.