Python Keyring Library
pypi.org
pypi.org
This uses Keychain on macOS, Freedesktop Secret Service/KWallet on linux and Windows Credential Locker on Windows. So decrypting is managed by the OS usually it's done when the user log in or at first access, and is transparent to your program.
This avoids a pitfall I see too often where people hard code their password in their script because it's the simple thing to do.
Keyring is nice because it's only an inch more effort than that. It's the best ratio "ease of use" / "security" there is. You manipulate it like a key-value store, don't bother about encryption, prompting the user for decryption or anything. And you don't risk committing your secret or letting linger at the wrong place. Plus you benefit from your OS security team effort.
You can also use "os.environ" to read the key from env vars in production and only use keyring if it's not there.