$npx skillfedfor your agent

asgi-csrf

ASGI middleware for protecting against CSRF attacks

With conditionsPyPI SecurityReleased Nov 2024166.7K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — asgi_csrf-0.11-py3-none-any.whl
v0.11 · released 2024-11-15 · Python >=3.9 · 2 runtime deps: itsdangerous, python-multipart

Yes, with conditions. asgi-csrf is a straightforward, low-friction implementation of a standard CSRF defense pattern with no known vulnerabilities. Install it if you are building traditional server-rendered ASGI applications that handle form submissions. However, note that maintenance is dormant (no releases in 637 days)—verify compatibility with your specific ASGI framework and Python version before committing to production, and be prepared to fork or switch if critical issues arise.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later; signing_secret should be configured explicitly or via ASGI_CSRF_SECRET environment variable to persist across server restarts.
  • Low install friction with just two runtime dependencies.
  • Maintenance is dormant—last commit was 2024-11-15 and no releases in the past 637 days—but the repository is not archived and the package remains functional for current Python versions.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 is permissive; you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.

last release 2024-11-15 (637 days) · last repo commit 2024-11-15 · 67 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 166,658 downloads/mo, #10,484 on PyPI

Verify before relying

pip install asgi-csrf

from asgi_csrf import asgi_csrf

app = asgi_csrf(app, signing_secret="your-secret-key")

# In templates, include the token:
# <input type="hidden" name="csrftoken" value="{{ request.scope['csrftoken']() }}" />
  • Whether the dormant maintenance status (no releases in 637 days) affects compatibility with recent ASGI framework versions or Python 3.12+.
  • Real-world performance impact when handling multipart form data with the python-multipart dependency.
Same gist for agents: .md · .json

What it is and what it does

asgi-csrf is ASGI middleware that defends web applications against Cross-Site Request Forgery attacks by implementing the Double Submit Cookie pattern. It automatically sets a CSRF token cookie on incoming requests and validates that token in subsequent POST requests—either as a hidden form field or as an x-csrftoken HTTP header. The middleware depends on itsdangerous for token signing and python-multipart for parsing multipart form data.

The middleware is configured by wrapping your ASGI application and providing a signing secret. It offers fine-grained control over cookie behavior (name, path, domain, secure flag, SameSite policy), can skip protection for API routes or Bearer-token requests, and supports custom error handlers. Requests without cookies or with Bearer authentication are allowed through by default, though specific paths can be marked for always-protection to defend against login CSRF.

Use it for

  • Protect traditional server-rendered web forms from CSRF attacks by validating tokens on POST requests.
  • Defend login endpoints against login CSRF by marking them with always_protect to require tokens even from unauthenticated users.
  • Skip CSRF checks for REST API endpoints while protecting form-based routes using skip_if_scope callbacks.
  • Customize CSRF error responses for different content types or to match your application's error handling style.
  • Configure cookie security settings (HTTPS-only, SameSite) to align with your deployment environment and security policy.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

asgi-csrf is a straightforward, low-friction implementation of a standard CSRF defense pattern with no known vulnerabilities. Install it if you are building traditional server-rendered ASGI applications that handle form submissions. However, note that maintenance is dormant (no releases in 637 days)—verify compatibility with your specific ASGI framework and Python version before committing to production, and be prepared to fork or switch if critical issues arise.

Install

asgi-csrf on PyPI

Before you install

Low install friction with just two runtime dependencies. Maintenance is dormant—last commit was 2024-11-15 and no releases in the past 637 days—but the repository is not archived and the package remains functional for current Python versions.

Requires Python 3.9 or later; signing_secret should be configured explicitly or via ASGI_CSRF_SECRET environment variable to persist across server restarts.

License in practice

Apache-2.0 is permissive; you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.

Quickstart

pip install asgi-csrf

from asgi_csrf import asgi_csrf

app = asgi_csrf(app, signing_secret="your-secret-key")

# In templates, include the token:
# <input type="hidden" name="csrftoken" value="{{ request.scope['csrftoken']() }}" />

Verify before relying

  • Whether the dormant maintenance status (no releases in 637 days) affects compatibility with recent ASGI framework versions or Python 3.12+.
  • Real-world performance impact when handling multipart form data with the python-multipart dependency.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
itsdangerouspython-multipart
MaintenanceDormant 637 days since the last release
Last repo commit
First released
Downloads166,658 / month, #10,484 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: Apache Software License

Evidence: asgi_csrf-0.11-py3-none-any.whl

Tags

Capabilities
csrf protection middlewareasgi security middlewarecross-site request forgery preventiondouble submit cookie patterntoken validation asgiweb application csrf defenseform token middleware
Topics
csrf-protectionasgi-middlewareweb-security

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “asgi security middleware”

  • asgi-csrfASGI middleware that protects web applications against CSRF attacks…
  • secureApplies HTTP security headers to Python web responses through a…
  • opentelemetry-instrumentation-asgiProvides ASGI middleware for OpenTelemetry that instruments request…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also fastapi-csrf-protect · starlette-csrf · piccolo-api · django-cookie-consent · flask-talisman · Flask-Paranoid · safehttpx · asgi-correlation-id · secure · tuf