Beaker
A Session and Caching library with WSGI Middleware
Decision gist · record as of 2026-08-14
Yes, with a security caveat. Beaker is production-stable, actively maintained, has zero install friction, and offers a mature, flexible caching and session abstraction for WSGI applications. However, verify whether PYSEC-2020-216 affects version 1.14.1 before deploying to production; if unpatched, assess the risk in your threat model.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.8 or later; optional backends (Redis, memcached, MongoDB) require their respective client libraries.
- Low install friction with no runtime dependencies.
- Actively maintained as of 76 days ago with production-stable status across Python 3.8–3.13.
License · maintenance · safety
BSD (permissive) — BSD permissive license allows use in most projects without significant restrictions.
last release 2026-05-30 (76 days)
1 known vulnerabilities (OSV.dev, 2026-08-14) · 269,610 downloads/mo, #8,256 on PyPI
Alternatives
Verify before relying
pip install beaker
from beaker.cache import CacheManager
from beaker.session import SessionObject
cache_opts = {'cache.type': 'memory'}
cache = CacheManager(**cache_opts)- Whether PYSEC-2020-216 affects current version 1.14.1 or has been patched.
- Performance characteristics and scalability limits for high-concurrency scenarios.
- Current maintenance activity level beyond release date (last commit, recent PRs).
What it is and what it does
Beaker is a session and caching library designed for WSGI web applications. It abstracts storage across multiple backends—memory, file, database (via SQLAlchemy), memcached, Redis, and MongoDB—allowing you to choose the right persistence layer for your use case without changing application code. It includes WSGI middleware for transparent session and cache integration, signed cookies to prevent session hijacking, and cookie-only sessions for clustered deployments that don't require a backend store.
The library handles cache namespacing, key expiration, automatic cache regeneration via callbacks, and fine-grained backend toggling per cache object. It has been in production use since 2006 and is integrated into frameworks like Pylons and TurboGears. With zero runtime dependencies and support for Python 3.8–3.13, it is straightforward to install and integrate into existing WSGI applications.
Use it for
- Store user sessions in memcached or Redis for horizontally scaled web services.
- Cache expensive database queries or API responses with automatic expiration.
- Use signed cookies for stateless session management in clustered environments.
- Implement multi-tier caching (memory + persistent backend) with namespace isolation.
- Integrate session middleware into a Pylons or TurboGears application with minimal configuration.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with a security caveat.
Beaker is production-stable, actively maintained, has zero install friction, and offers a mature, flexible caching and session abstraction for WSGI applications. However, verify whether PYSEC-2020-216 affects version 1.14.1 before deploying to production; if unpatched, assess the risk in your threat model.
Install
beaker on PyPI
Before you install
Low install friction with no runtime dependencies. Actively maintained as of 76 days ago with production-stable status across Python 3.8–3.13.
Requires Python 3.8 or later; optional backends (Redis, memcached, MongoDB) require their respective client libraries.
License in practice
BSD permissive license allows use in most projects without significant restrictions.
Quickstart
pip install beaker
from beaker.cache import CacheManager
from beaker.session import SessionObject
cache_opts = {'cache.type': 'memory'}
cache = CacheManager(**cache_opts)
Verify before relying
- Whether PYSEC-2020-216 affects current version 1.14.1 or has been patched.
- Performance characteristics and scalability limits for high-concurrency scenarios.
- Current maintenance activity level beyond release date (last commit, recent PRs).
Package facts
| License | BSD permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 76 days since the last release |
| First released | |
| Downloads | 269,610 / month, #8,256 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | 1 PYSEC-2020-216 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Internet :: WWW/HTTP :: WSGITopic :: Internet :: WWW/HTTP :: WSGI :: Middleware |
Evidence: beaker-1.14.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “wsgi session middleware”
- BeakerBeaker provides session management and caching for WSGI web…
- PastePaste provides WSGI middleware components for building web…
- repoze-lruA lightweight LRU (least recently used) cache implementation that…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also Flask-Session · aiohttp-session · django-redis · repoze.who · django-cache-url · requests-cache · cachelib · aiohttp-client-cache · Paste