Py2Native Compile custom Python into native machine code to protect proprietary code

← All posts

2026-10-01

Is Py2Native Worth It? A Cost-Benefit Analysis for Python Developers

Is Py2Native Worth It? A Cost-Benefit Analysis for Python Developers
python compiler cython code protection open source

Is Py2Native Worth It? A Cost-Benefit Analysis for Python Developers

Every Python file you ship is plain text. If your application contains pricing logic, activation checks, proprietary algorithms, or data-processing secrets, anyone with a text editor can read it. Py2Native changes that equation: you write plain Python, run a single uv command, and get native machine code instead of readable .py files.

But is Py2Native worth it? That depends on what you need to protect, how you distribute your software, and whether you need license enforcement. In this article, I’ll break down what you get at each tier, what it costs, and where the return on investment actually comes from.

The Purchase Decision: Why Consider Py2Native?

If you ship proprietary Python software, you have probably considered a few options: obfuscation, freezing, manual Cython builds, or hand-written C extensions. Most of those add friction. Py2Native takes a different route: it compiles your custom Python code into native machine code while leaving third-party libraries untouched.

That distinction matters. You do not have to rewrite your code, learn Cython syntax, maintain .pyx/.pxd files by hand, or write C extensions. Py2Native uses Cython under the hood, but it hides the machinery behind a single CLI.

For a basic build, the workflow looks like this:

uv run py2native build main.py "src/**/*.py" --embed dist/myapp

The question is not just “does it work?” but “is the protection worth adding another build step?” Let’s look at what you actually get.

What You Get at Each Tier

Py2Native comes in two editions:

Tier Package License What you get
Community py2native MIT Full compilation pipeline, executable and library modes, wheel creation, uv embedding, Windows/macOS/Linux support
Pro py2nativepro Proprietary JWT license verification, string compression, keygen/sign/show commands

Community Edition: py2native

The open-source Community Edition is the core compiler. It includes the entire pipeline from Python sources to native output:

  • Executable mode with --embed
  • Library mode with --library
  • Wheel creation with --wheel
  • Cross-platform linking for Windows, Linux, and macOS
  • uv-managed deployment directories

You write normal Python. Py2Native globs your source files, compiles them through Cython, compiles the generated C, and links a native shared object or executable.

For many teams, this is already the main value proposition: source protection without adopting a new language or manually maintaining a build system.

Pro Edition: py2nativepro

The Pro Edition adds commercial license enforcement on top of the Community compiler. It gives you three CLI commands for managing signed licenses:

uv run py2native keygen private.pem public.pem
uv run py2native sign --private private.pem '{"sub":"customer-123","iss":"RSJ Software GmbH","aud":"TimestampGIT","exp":1767225600}' license.dat
uv run py2native show license.dat

The Pro plugin generates an EC P-256 keypair, signs a JWT payload, and writes the result to license.dat. When you build, you pass both the license file and the public key:

uv run py2native build main.py "src/**/*.py" \
  --license license.dat \
  --public public.pem \
  --embed dist/myapp

Only the public key is embedded in the executable. The private key never ships to customers. The elliptic key verification is handled by compiled code — no third-party JWT library is involved.

At runtime, the Pro plugin exposes a verifier through the build bootstrap. The generated .pxd declaration is:

# Py2Native Pro injects this .pxd declaration into the build:
cdef _runtime_verify_es256_jwt(token, expected_iss=*, expected_aud=*)

In your Python entry point, you call the verifier with your license string:

# main.py
from _p2n_bootstrap cimport _runtime_verify_es256_jwt

# Declared as:
# _runtime_verify_es256_jwt(token, expected_iss="RSJ Software GmbH", expected_aud="TimestampGIT")
licenseString = read_license_file()
license = _runtime_verify_es256_jwt(licenseString, expected_iss="RSJ Software GmbH", expected_aud="TimestampGIT")

if not license:
    raise SystemExit("License verification failed")

This is the only Cython-flavored line you add for Pro license verification. Py2Native bakes the verification logic and public key into the executable, and the uv run py2native build command does the rest.

One important limitation: Py2Native compiles your custom Python code. Third-party libraries remain as Python source, so they are not protected. They still work as-is, but your proprietary modules become native machine code.

Cost/Benefit and ROI

Costs

The Community Edition is free under the MIT license, including commercial use. The main costs are:

  • Setting up a local C toolchain: MSVC on Windows, GCC on Linux, or Clang on macOS
  • Installing uv if you do not already use it
  • Adding a build step to your CI pipeline
  • Time to verify that your compiled output works as expected

The Pro Edition requires a commercial license. Pricing details are outside the scope of this article, but the Py2Native Pro license pricing article covers what is included.

Benefits

The primary benefit is straightforward: your shipped artifact no longer contains readable Python source for your proprietary modules.

A native binary or wheel is not unhackable, but it raises the reverse-engineering cost considerably. For most commercial software, that is the goal: make casual copying and source theft expensive enough that honest licensing wins.

Other benefits include:

  • No Cython learning curve. You do not write .pyx files or run cythonize manually.
  • No hand-written C extensions. The compiler handles C generation and linking.
  • Minimal configuration. A single uv run py2native build invocation replaces a fragile custom build pipeline.
  • Flexible output. You can produce an executable, a compiled library, or a wheel.
  • Cross-platform builds. The same command shape works on Windows, Linux, and macOS with platform-specific linking handled for you.

ROI scenarios

For commercial desktop software, preventing source theft can directly protect revenue. If your product’s core value is an algorithm, data transformation, or proprietary workflow, shipping .py files is a risk. A single source leak can create an unsupported clone. Py2Native reduces that exposure.

For internal tools, the payoff is often tamper prevention. A native binary is harder for users to modify than a readable Python script, which matters in regulated or controlled environments.

For teams currently considering manual Cython or C-extension work, Py2Native’s zero-config approach saves developer time. Manual Cython builds require you to maintain .pyx stubs, understand Cython directives, and debug platform-specific linking. Py2Native automates those steps.

Upgrade Path: Community to Pro

A sensible adoption path looks like this:

  1. Start with the Community Edition.
  2. Compile your current Python project and test the executable or wheel on your target platforms.
  3. Evaluate whether source protection alone solves your problem.
  4. If you need per-seat licensing, trial periods, or hardware-locked activation, upgrade to Pro.

The Pro plugin integrates with the same build command. You do not replace your compiler or rewrite your application. You generate a keypair, sign a license payload, add --license and --public to your build command, and include the runtime verification call in your entry point.

The minimal verification code is:

from _p2n_bootstrap cimport _runtime_verify_es256_jwt

license = _runtime_verify_es256_jwt(licenseString, expected_iss="RSJ Software GmbH", expected_aud="TimestampGIT")

Because the public key and verification code are baked into the executable, there is no external license server to run. That keeps distribution simple and avoids ongoing infrastructure costs.

Self-Hosted vs Cloud Considerations

Py2Native is a local compiler tool. It runs on your machine with uv; it is not a cloud service that holds your source or build artifacts.

That has practical advantages:

  • No ongoing per-build cloud costs
  • No upload of proprietary source to a third party
  • Full control over build artifacts
  • Easy integration into CI/CD

A CI step can be as simple as:

uv run py2native build src/main.py "src/**/*.py" --embed dist/myapp

For Pro builds, store the license file and public key as build secrets or repository files, then run the same command with --license and --public. The private key should never leave your signing environment.

The main trade-off is that you are responsible for maintaining the local toolchain: Python, uv, Cython, and a platform C compiler. Py2Native’s core dependencies are cython, setuptools, uv, and on Linux, auditwheel. A supported CPython 3.11–3.15 environment with a standard compiler is enough.

FAQ

Is Py2Native free to use?

Yes, the Community Edition is open source under the MIT license and free for commercial use. The Pro Edition requires a commercial license for additional features like JWT license verification.

Does Py2Native protect third-party libraries?

No, Py2Native only compiles your custom Python code. Third-party libraries remain as Python source and are not protected. However, they work as-is without configuration.

How difficult is it to set up Py2Native?

Py2Native is designed to be zero-config. You write plain Python, run uv run py2native build with your source files, and get a native binary or wheel. No Cython syntax or manual build steps are required for normal builds.

Can I try Py2Native before buying Pro?

Yes, you can use the Community Edition to compile your code and evaluate the protection. When you need license verification, you can upgrade to Pro and add the verification code to your project.

Conclusion: Is Py2Native Worth It?

For Python developers shipping proprietary software, Py2Native solves a concrete problem: readable Python source is a liability. The Community Edition gives you a free, zero-config compilation path from plain Python to native machine code. The Pro Edition adds signed JWT license enforcement without forcing you to build a separate licensing service.

If you only need to make your source harder to read and copy, start with the Community Edition. If you sell software and need per-seat or per-customer activation, the Pro plugin is the natural upgrade. The workflow stays the same; you add a keypair, a signed license, and one verification call.

The best way to decide is to try it on a real project. Build a small module, inspect the output, and measure how much readable Python disappears. Py2Native is built for exactly that experiment.

Related posts

EU label: AI-generated content