aiohttp-session
sessions for aiohttp.web
Decision gist · record as of 2026-08-14
Yes. This is the standard session middleware for aiohttp.web with low install friction, active maintenance, no known vulnerabilities, and a permissive license. Install it if you are building an aiohttp web application that needs to track user state across requests. Choose your storage backend based on security and scalability needs.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- EncryptedCookieStorage requires an external encryption library; RedisStorage requires a Redis client library.
- Install optional dependencies via pip install aiohttp_session[secure] or aiohttp_session[aioredis].
- Low friction—pure Python wheel with a single runtime dependency (aiohttp).
License · maintenance · safety
Apache 2 (permissive) — Apache 2 (permissive): you may use, modify, and distribute this package freely in commercial and private projects, provided you retain the license notice.
last release 2024-09-25 (688 days) · last repo commit 2026-08-14 · 244 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 223,136 downloads/mo, #9,251 on PyPI
Alternatives
Verify before relying
from aiohttp import web
from aiohttp_session import setup, get_session
from aiohttp_session.cookie_storage import EncryptedCookieStorage
async def handler(request):
session = await get_session(request)
session['key'] = 'value'
return web.Response(text='OK')
app = web.Application()
setup(app, EncryptedCookieStorage(fernet_key))
app.router.add_get('/', handler)- Whether SimpleCookieStorage is suitable for any production use cases despite documentation warnings.
- Performance characteristics and scalability limits when using Redis or Memcached backends under high concurrency.
- Exact encryption algorithm and key length requirements for EncryptedCookieStorage.
What it is and what it does
aiohttp_session is a middleware library that adds session support to aiohttp.web applications. It provides a dict-like interface for storing and retrieving user-specific data across HTTP requests, with the session identifier stored in an HTTP cookie named AIOHTTP_SESSION (customizable via the storage class).
The library offers three main storage backends: SimpleCookieStorage (plain JSON in cookie, for testing only), EncryptedCookieStorage (encrypted cookie storage), and RedisStorage (server-side storage in Redis with only the session key in the cookie). You register the session middleware with your aiohttp Application via the setup() function, then retrieve the session object in handlers using get_session(request). The session automatically handles expiration, TTL management, and cookie attributes.
Use it for
- Store user login state and authentication tokens across requests in a web application.
- Track user preferences or UI state without a database.
- Maintain shopping cart or form data during multi-step workflows in async web apps.
- Use Redis as a centralized session store for load-balanced aiohttp deployments.
- Persist session data with automatic expiration and TTL management.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is the standard session middleware for aiohttp.web with low install friction, active maintenance, no known vulnerabilities, and a permissive license. Install it if you are building an aiohttp web application that needs to track user state across requests. Choose your storage backend based on security and scalability needs.
Install
aiohttp-session on PyPI
Before you install
Low friction—pure Python wheel with a single runtime dependency (aiohttp). Actively maintained as of 2024-09-25 with recent typing fixes and ongoing Python version support through 3.13.
EncryptedCookieStorage requires an external encryption library; RedisStorage requires a Redis client library. Install optional dependencies via pip install aiohttp_session[secure] or aiohttp_session[aioredis].
License in practice
Apache 2 (permissive): you may use, modify, and distribute this package freely in commercial and private projects, provided you retain the license notice.
Quickstart
from aiohttp import web
from aiohttp_session import setup, get_session
from aiohttp_session.cookie_storage import EncryptedCookieStorage
async def handler(request):
session = await get_session(request)
session['key'] = 'value'
return web.Response(text='OK')
app = web.Application()
setup(app, EncryptedCookieStorage(fernet_key))
app.router.add_get('/', handler)
Verify before relying
- Whether SimpleCookieStorage is suitable for any production use cases despite documentation warnings.
- Performance characteristics and scalability limits when using Redis or Memcached backends under high concurrency.
- Exact encryption algorithm and key length requirements for EncryptedCookieStorage.
Package facts
| License | Apache 2 permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageaiohttp |
| Maintenance | Actively maintained 688 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 223,136 / month, #9,251 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Framework :: AsyncIOFramework :: aiohttpIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Internet :: WWW/HTTP |
Evidence: aiohttp_session-2.12.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “aiohttp session management”
- aiohttp-sessionProvides session management for aiohttp.web applications with…
- electrickiwi-apiAsync Python client for the Electric Kiwi API that provides a simple…
- httpx-aiohttpProvides aiohttp-based transports for httpx, allowing httpx to use…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also pyramid-session-redis · starsessions · aiohttp-middlewares · Beaker · Flask-Session · fastapi-sessions · aiohttp-basicauth · aiohttp-client-cache · django-redis-sessions · aioredis