atlassian-jwt-auth
Python implementation of the Atlassian Service to Service Authentication specification.
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has no known vulnerabilities, low install friction, and a permissive license. Install it if you need to authenticate with Atlassian services or implement the S2S spec. The requests integration is seamless; if you use aiohttp, you'll need to install it separately but the library provides drop-in replacements.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a private key in PEM format; for aiohttp support, aiohttp must be installed separately.
- Low install friction; pure Python wheel with three lightweight runtime dependencies (PyJWT, requests, CacheControl).
- Active maintenance with a recent release 85 days ago.
License · maintenance · safety
MIT (permissive) — MIT license permits commercial and private use with minimal restrictions; suitable for most projects.
last release 2026-05-21 (85 days) · last repo commit 2026-05-21 · 26 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 499,236 downloads/mo, #6,325 on PyPI
Alternatives
Verify before relying
pip install atlassian-jwt-auth
import atlassian_jwt_auth
from atlassian_jwt_auth.contrib.requests import JWTAuth
import requests
signer = atlassian_jwt_auth.create_signer('issuer', 'issuer/key', private_key_pem)
response = requests.get('https://your-url', auth=JWTAuth(signer, 'audience'))- Whether the package supports key rotation or automatic key discovery beyond file-based repositories.
- Performance characteristics when reusing tokens with reuse_jwts=True under high concurrency.
- Compatibility with non-Atlassian services that implement the S2S spec.
What it is and what it does
atlassian-jwt-auth implements the Atlassian Service to Service Authentication specification, allowing Python applications to generate and verify JWT tokens for authenticated communication with Atlassian services. It handles the full lifecycle: creating signers from private keys (in-memory, file-based, or data URIs), generating short-lived tokens with configurable lifetimes, and verifying tokens using public key retrieval from HTTPS endpoints.
The package integrates directly with requests and aiohttp, so you can drop a JWTAuth handler into standard HTTP client calls and let the library manage token generation and refresh automatically. It supports token reuse within validity periods to reduce overhead, and provides both synchronous and async verification paths.
Use it for
- Authenticate requests to Atlassian Cloud APIs (Jira, Confluence, Bitbucket) using JWT bearer tokens.
- Build microservices that communicate with each other using the S2S specification without shared secrets.
- Verify incoming JWT tokens from other services to confirm their identity and claims.
- Implement token caching and reuse to reduce cryptographic overhead in high-throughput scenarios.
- Manage multiple private keys from a file repository and automatically select the latest active key.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has no known vulnerabilities, low install friction, and a permissive license. Install it if you need to authenticate with Atlassian services or implement the S2S spec. The requests integration is seamless; if you use aiohttp, you'll need to install it separately but the library provides drop-in replacements.
Install
atlassian-jwt-auth on PyPI
Before you install
Low install friction; pure Python wheel with three lightweight runtime dependencies (PyJWT, requests, CacheControl). Active maintenance with a recent release 85 days ago.
Requires a private key in PEM format; for aiohttp support, aiohttp must be installed separately.
License in practice
MIT license permits commercial and private use with minimal restrictions; suitable for most projects.
Quickstart
pip install atlassian-jwt-auth
import atlassian_jwt_auth
from atlassian_jwt_auth.contrib.requests import JWTAuth
import requests
signer = atlassian_jwt_auth.create_signer('issuer', 'issuer/key', private_key_pem)
response = requests.get('https://your-url', auth=JWTAuth(signer, 'audience'))
Verify before relying
- Whether the package supports key rotation or automatic key discovery beyond file-based repositories.
- Performance characteristics when reusing tokens with reuse_jwts=True under high concurrency.
- Compatibility with non-Atlassian services that implement the S2S spec.
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesPyJWTrequestsCacheControl |
| Maintenance | Actively maintained 85 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 499,236 / month, #6,325 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9 |
Evidence: atlassian_jwt_auth-22.0.1-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “atlassian jwt authentication”
- atlassian-jwt-authGenerates and verifies JWT tokens for Atlassian Service to Service…
- atlassian-python-apiProvides Python bindings to REST APIs for Atlassian products (Jira,…
- mcp-atlassianAn MCP server that exposes Jira and Confluence APIs to AI language…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also cognitojwt · vonage-network-auth · djangorestframework-jwt · scitokens · okta-jwt-verifier · vonage-http-client · axioms-fastapi · pyjwt-key-fetcher · drf-jwt · atlassian-python-api