$npx skillfedfor your agent

auth0-api-python

SDK for verifying access tokens and securing APIs with Auth0, using Authlib.

Worth itPyPI CryptographyReleased Aug 2026248.9K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — auth0_api_python-1.0.0b10-py3-none-any.whl
v1.0.0b10 · released 2026-08-03 · Python >=3.9.2 · 4 runtime deps: ada-url, authlib, httpx, requests

Yes. The package is actively maintained, has low install friction, carries a permissive MIT license, and solves a concrete problem—Auth0 token verification—with no known vulnerabilities. Install it if you are building a Python API that needs to validate Auth0 tokens; skip it if you use a different identity provider or do not require server-side token validation.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9.2 or later.
  • All token verification methods are async and must be called within an asyncio context.
  • Low install friction with a pure-Python wheel distribution.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) allows commercial and private use with minimal restrictions—suitable for most production deployments.

last release 2026-08-03 (11 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 248,926 downloads/mo, #8,659 on PyPI

Verify before relying

pip install auth0-api-python

from auth0_api_python import ApiClient, ApiClientOptions
import asyncio

async def verify():
    client = ApiClient(ApiClientOptions(
        domain="<AUTH0_DOMAIN>",
        audience="<AUTH0_AUDIENCE>"
    ))
    token = await client.verify_access_token(access_token="...")
    print(token)

asyncio.run(verify())
  • Whether ada-url, authlib, httpx, and requests are all required at runtime or if some are optional dependencies.
  • Performance characteristics when validating tokens at scale or with multiple Auth0 domains.
  • Specific error types and HTTP status codes returned by verify_access_token() for different failure modes.
Same gist for agents: .md · .json

What it is and what it does

auth0-api-python is an SDK for validating Auth0-issued access tokens in Python server-side applications. It provides a unified entry point (`verify_access_token()`) that automatically detects and validates Bearer tokens (RS256) or DPoP-authenticated requests (ES256), with support for multiple Auth0 domains, automatic OIDC discovery, and per-issuer caching. The library is framework-agnostic and designed as a foundation for building integrations with FastAPI, Django, Flask, or any Python web framework.

The package handles the cryptographic and protocol details of JWT validation, DPoP proof verification (RFC 9449), and claim checking (iss, aud, exp, nbf). It also supports token exchange workflows via RFC 8693 for scenarios like migrating to Auth0 or integrating external identity providers. All operations are async-first, and the library provides detailed error handling with proper HTTP status codes and WWW-Authenticate headers.

Use it for

  • Validate incoming Bearer tokens in a FastAPI or Django REST endpoint before processing requests.
  • Implement DPoP-enhanced security for sensitive API operations requiring proof-of-possession authentication.
  • Accept and verify access tokens from multiple Auth0 domains in a multi-tenant SaaS application.
  • Exchange legacy or external identity provider tokens for Auth0 access tokens during a migration.
  • Automatically fetch and cache Auth0 JWKS metadata per issuer to validate token signatures.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The package is actively maintained, has low install friction, carries a permissive MIT license, and solves a concrete problem—Auth0 token verification—with no known vulnerabilities. Install it if you are building a Python API that needs to validate Auth0 tokens; skip it if you use a different identity provider or do not require server-side token validation.

Install

auth0-api-python on PyPI

Before you install

Low install friction with a pure-Python wheel distribution. Active maintenance status with a recent release (11 days old). Requires Python 3.9.2 or later and depends on four runtime packages: authlib, httpx, requests, and ada-url.

Requires Python 3.9.2 or later. All token verification methods are async and must be called within an asyncio context.

License in practice

MIT license (permissive) allows commercial and private use with minimal restrictions—suitable for most production deployments.

Quickstart

pip install auth0-api-python

from auth0_api_python import ApiClient, ApiClientOptions
import asyncio

async def verify():
    client = ApiClient(ApiClientOptions(
        domain="<AUTH0_DOMAIN>",
        audience="<AUTH0_AUDIENCE>"
    ))
    token = await client.verify_access_token(access_token="...")
    print(token)

asyncio.run(verify())

Verify before relying

  • Whether ada-url, authlib, httpx, and requests are all required at runtime or if some are optional dependencies.
  • Performance characteristics when validating tokens at scale or with multiple Auth0 domains.
  • Specific error types and HTTP status codes returned by verify_access_token() for different failure modes.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9.2
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
ada-urlauthlibhttpxrequests
MaintenanceActively maintained 11 days since the last release
First released
Downloads248,926 / month, #8,659 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14

Evidence: auth0_api_python-1.0.0b10-py3-none-any.whl

Tags

Capabilities
auth0 token verificationoauth2 bearer token validationapi authentication auth0dpop proof verificationjwt access token verificationauth0 api securitypython oauth2 middleware
Topics
auth0oauth2jwt-validation

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “auth0 token verification”

  • auth0-api-pythonVerifies Auth0-issued access tokens and secures Python APIs with…
  • fastapi-cloudauthIntegrates FastAPI applications with cloud authentication services…
  • auth0-pythonProvides Python bindings to Auth0's Authentication and Management…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also auth0-python · fastapi-auth0 · wandelbots_api_client · pulumi-auth0 · fastapi-cloudauth · axioms-fastapi · requests-oauth2client · plaid-python · py-vapid · h2o-authn