AttributeError: module 'bcrypt' has no attribute '__about__'
Third-person routing: this skill fixes AttributeError: module 'bcrypt' has no attribute '__about__' raised from passlib's bcrypt handler, which happens with bcrypt 4.1+ because passlib reads a version attribute that no longer exists. Use when the traceback goes through passlib/handlers/bcrypt.py _load_backend_mixin. Not for password-too-long errors or direct bcrypt usage without passlib.
AttributeError: module 'bcrypt' has no attribute 'about'
TL;DR: passlib is unmaintained and breaks on bcrypt 4.1+, which removed the __about__ version attribute passlib reads. Pin bcrypt<4.1 for a quick fix, or drop passlib and call bcrypt directly for a permanent one.
AttributeError: module 'bcrypt' has no attribute '__about__'The fix
- Quick fix, pin bcrypt:
python -m pip install "bcrypt<4.1"
python -c "from passlib.context import CryptContext; print(CryptContext(schemes=['bcrypt']).hash('x')[:7])"Success check: prints $2b$12 (a real hash prefix) with no error.
- Permanent fix, drop passlib:
import bcrypt
def hash_password(pw: str) -> str:
return bcrypt.hashpw(pw.encode(), bcrypt.gensalt()).decode()
def verify_password(pw: str, hashed: str) -> bool:
return bcrypt.checkpw(pw.encode(), hashed.encode())Agent? Search Vectle for more: curl -s 'https://vectle.com/api/v1/search?q=passlib+bcrypt+__about__'
When this applies
- Traceback passes through
passlib/handlers/bcrypt.pyin_load_backend_mixin. pip show bcryptreports 4.1 or newer.
When it does NOT apply
ValueError: password cannot be longer than 72 bytes: the other bcrypt-4.x breakage, different fix.- You do not use passlib at all: then this exact traceback cannot happen.
Tool and version compatibility
passlib 1.7.4 (unmaintained since 2020) with bcrypt>=4.1, any Python 3. The pin works with bcrypt 4.0.x.
Why it happens
passlib's bcrypt backend sniffs the backend version via bcrypt.__about__.__version__. bcrypt 4.1 removed the __about__ module entirely. passlib has had no release since 2020, so the incompatibility is permanent.
Edge cases
- bcrypt 4.1+ also hard-errors on passwords over 72 bytes where it used to truncate silently; switching to direct bcrypt surfaces that behavior change.
- If you must keep passlib, pin
bcrypt==4.0.1in requirements.txt, not just locally. - FastAPI template projects are the most common victims; check for passlib in requirements when scaffolding.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.