coze-workload-identity
Python SDK for Coze workload identity authentication
Decision gist · record as of 2026-08-14
Yes, if you are building Python applications that integrate with Coze services. The SDK handles OAuth2 token exchange transparently with automatic caching and thread safety, requires minimal setup beyond environment variables, and carries no security vulnerabilities. The low dependency footprint and permissive MIT license make it a straightforward addition to any Coze-dependent project.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires environment variables COZE_WORKLOAD_IDENTITY_CLIENT_ID, COZE_WORKLOAD_IDENTITY_CLIENT_SECRET, COZE_WORKLOAD_IDENTITY_TOKEN_ENDPOINT, and COZE_WORKLOAD_ACCESS_TOKEN_ENDPOINT to be set.
- Low install friction with only two runtime dependencies (requests, urllib3).
- Active maintenance status with a recent release.
License · maintenance · safety
MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal obligations.
last release 2026-06-30 (45 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 84,467 downloads/mo, #13,995 on PyPI
Alternatives
Verify before relying
pip install coze-workload-identity
from coze_workload_identity import Client
with Client() as client:
token = client.get_access_token()- Whether the package is actively maintained beyond the 45 days since last release.
- Real-world performance and reliability of token caching under high concurrency.
- Completeness of error handling for network failures and edge cases.
What it is and what it does
Coze Workload Identity SDK is a Python client for authenticating with Coze services using OAuth2.0 token exchange. It manages the two-step flow of obtaining an ID token via client credentials grant, then exchanging it for an access token, with automatic process-level caching that refreshes tokens one minute before expiration.
The SDK provides thread-safe token management, support for multiple deployment environments (BOE, PPE, custom), integration credential retrieval, project environment variable access, and configurable HTTPS proxy with custom CA certificate support. It requires Python 3.8 or later and depends only on requests and urllib3.
Use it for
- Authenticate microservices or background jobs to Coze APIs without managing token lifecycle manually.
- Retrieve integration credentials and project environment variables from Coze in a single authenticated session.
- Deploy multi-threaded applications that share a single cached token across worker threads.
- Route requests through corporate proxies with custom CA certificates while maintaining authentication.
- Switch between development (BOE), staging (PPE), and production environments via environment variables.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building Python applications that integrate with Coze services.
The SDK handles OAuth2 token exchange transparently with automatic caching and thread safety, requires minimal setup beyond environment variables, and carries no security vulnerabilities. The low dependency footprint and permissive MIT license make it a straightforward addition to any Coze-dependent project.
Install
coze-workload-identity on PyPI
Before you install
Low install friction with only two runtime dependencies (requests, urllib3). Active maintenance status with a recent release.
Requires environment variables COZE_WORKLOAD_IDENTITY_CLIENT_ID, COZE_WORKLOAD_IDENTITY_CLIENT_SECRET, COZE_WORKLOAD_IDENTITY_TOKEN_ENDPOINT, and COZE_WORKLOAD_ACCESS_TOKEN_ENDPOINT to be set.
License in practice
MIT license permits unrestricted use, modification, and distribution with minimal obligations.
Quickstart
pip install coze-workload-identity
from coze_workload_identity import Client
with Client() as client:
token = client.get_access_token()
Verify before relying
- Whether the package is actively maintained beyond the 45 days since last release.
- Real-world performance and reliability of token caching under high concurrency.
- Completeness of error handling for network failures and edge cases.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesrequestsurllib3 |
| Maintenance | Actively maintained 45 days since the last release |
| First released | |
| Downloads | 84,467 / month, #13,995 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: coze_workload_identity-0.1.14-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “oauth2 token exchange”
- coze-workload-identityImplements OAuth2.0 token exchange authentication for Coze workload…
- auth0-api-pythonVerifies Auth0-issued access tokens and secures Python APIs with…
- requests-authAdds OAuth2, API key, Basic, and NTLM authentication support to the…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also gcloud-rest-auth · gcloud-aio-auth · oauth2-client · onelogin · msal · gcs-oauth2-boto-plugin · python-squarelet · django-oidc-provider · google-auth-oauthlib · oauthenticator