Authlib
The ultimate Python library in building OAuth and OpenID Connect servers and clients.
Decision gist · record as of 2026-08-14
Yes. Authlib is a mature, actively maintained library (released within 100 days) with no known vulnerabilities, permissive licensing, and low install friction. It is the right choice if you need to build or integrate OAuth/OpenID Connect authentication in Python—whether as a client connecting to external providers or as a server implementing your own authorization endpoint. The broad framework support and spec compliance make it suitable for production use.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low friction installation with only two runtime dependencies (cryptography and joserfc).
- Actively maintained with a release within the last 100 days.
License · maintenance · safety
BSD-3-Clause (permissive) — BSD-3-Clause permissive license allows use in open and closed-source projects. Commercial license also available for organizations requiring dedicated support.
last release 2026-05-06 (100 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 155,113,336 downloads/mo, #261 on PyPI
Alternatives
Verify before relying
pip install authlib
from authlib.integrations.requests_client import OAuth2Session
oauth = OAuth2Session(client_id='...', client_secret='...')
token = oauth.fetch_token('https://provider.example.com/token')- Whether the authlib.jose module deprecation affects existing codebases and what the migration timeline is.
- Performance characteristics when handling high-volume token operations or large key sets.
- Whether all listed RFC implementations are feature-complete or have known limitations.
What it is and what it does
Authlib is a comprehensive OAuth and OpenID Connect library for Python that handles both client-side authentication flows and server-side provider implementation. It includes full support for OAuth 1.0 and 2.0 protocols, OpenID Connect 1.0, and JOSE standards (JWS, JWK, JWA, JWT). The library provides spec-compliant implementations of multiple RFCs including token revocation, dynamic client registration, proof key for code exchange (PKCE), and JWT-secured authorization requests.
The package integrates with popular Python frameworks and HTTP clients—Flask, Django, Starlette, FastAPI for web frameworks, and Requests and HTTPX for HTTP clients—allowing developers to add OAuth authentication to applications without building cryptographic primitives from scratch. It depends on cryptography for low-level cryptographic operations and joserfc for JOSE handling, keeping the dependency footprint minimal.
Use it for
- Build an OAuth 2.0 authorization server for your own platform to delegate authentication to third-party applications.
- Implement OpenID Connect provider functionality in a Django or Flask application for enterprise SSO integration.
- Add OAuth 2.0 client authentication to a service that needs to call third-party APIs on behalf of users.
- Handle JWT token generation, validation, and key management for microservice authentication.
- Implement PKCE-protected OAuth flows for mobile or single-page applications.
- Support multiple OAuth providers (Google, GitHub, etc.) in a web application using built-in client integrations.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Authlib is a mature, actively maintained library (released within 100 days) with no known vulnerabilities, permissive licensing, and low install friction. It is the right choice if you need to build or integrate OAuth/OpenID Connect authentication in Python—whether as a client connecting to external providers or as a server implementing your own authorization endpoint. The broad framework support and spec compliance make it suitable for production use.
Install
authlib on PyPI
Before you install
Low friction installation with only two runtime dependencies (cryptography and joserfc). Actively maintained with a release within the last 100 days. Supports current Python versions (3.10+) and compatible with both CPython and PyPy.
Requires Python 3.10 or later.
License in practice
BSD-3-Clause permissive license allows use in open and closed-source projects. Commercial license also available for organizations requiring dedicated support.
Quickstart
pip install authlib
from authlib.integrations.requests_client import OAuth2Session
oauth = OAuth2Session(client_id='...', client_secret='...')
token = oauth.fetch_token('https://provider.example.com/token')
Verify before relying
- Whether the authlib.jose module deprecation affects existing codebases and what the migration timeline is.
- Performance characteristics when handling high-volume token operations or large key sets.
- Whether all listed RFC implementations are feature-complete or have known limitations.
Package facts
| License | BSD-3-Clause permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagescryptographyjoserfc |
| Maintenance | Actively maintained 100 days since the last release |
| First released | |
| Downloads | 155,113,336 / month, #261 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleEnvironment :: Web EnvironmentIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Internet :: WWW/HTTP :: WSGI :: ApplicationTopic :: SecurityTopic :: Security :: Cryptography |
Evidence: authlib-1.7.2-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
An agent finds packages by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language. Give your agent the search over MCP.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
Disables the CVE-2023-47248 security vulnerability in older PyArrow versions by patching unsafe deserialization behavior when imported.
See also Flask-OAuthlib · pyjwt-key-fetcher · requests-oauthlib · oauth2 · oauthlib · aioauth · pyop · requests-oauth · django-authlib · oic