dj-rest-auth
Authentication and Registration in Django Rest Framework
Decision gist · record as of 2026-08-14
Yes, if you are building a Django REST Framework API and need standard authentication endpoints. The package is actively maintained, has no known vulnerabilities, and eliminates significant boilerplate. High install friction is offset by the time saved on auth implementation. Not suitable if you are not already using Django and djangorestframework.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires an existing Django project with djangorestframework installed and configured; Django database migrations must be run after adding dj_rest_auth to INSTALLED_APPS.
- High install friction due to two required runtime dependencies (Django and djangorestframework).
- Package is actively maintained with recent commits and no known vulnerabilities, but setup requires integrating into an existing Django project and configuring multiple settings.
License · maintenance · safety
MIT (permissive) — MIT license is permissive and imposes no restrictions on use, modification, or distribution in commercial or private projects.
last release 2026-03-15 (152 days) · last repo commit 2026-06-05 · 1,866 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 815,464 downloads/mo, #4,990 on PyPI
Alternatives
Verify before relying
pip install dj-rest-auth djangorestframework
# settings.py
INSTALLED_APPS = [
'rest_framework',
'rest_framework.authtoken',
'dj_rest_auth',
]
# urls.py
from django.urls import path, include
urlpatterns = [
path('auth/', include('dj_rest_auth.urls')),
]
# Now POST to /auth/login/ with {"username": "...", "password": "..."}- Whether social authentication (Google, GitHub, Facebook) requires additional setup beyond the 'with-social' extra
- Performance characteristics under high concurrent authentication load
- Compatibility with specific versions of Django and djangorestframework beyond the minimum Python 3.10 requirement
What it is and what it does
dj-rest-auth is a Django REST Framework library that exposes standard authentication workflows as HTTP endpoints, eliminating the need to build login, logout, registration, and password reset flows from scratch. It integrates with Django's built-in authentication system and provides endpoints like /auth/login/, /auth/logout/, /auth/password/reset/, and user detail endpoints that return JSON responses suitable for single-page applications and mobile clients.
The package supports multiple authentication strategies: token-based auth, JWT with HTTP-only cookies, and optional social authentication via django-allauth. It also includes an opt-in MFA sub-package with TOTP and recovery codes. Because it depends on both Django and djangorestframework, it is intended for projects already using Django REST Framework; it is not a standalone authentication service.
Use it for
- Build a REST API for a React or Vue SPA that needs login, logout, and user profile endpoints without writing custom auth views
- Add user registration with email verification to a Django REST API without implementing the workflow manually
- Implement JWT-based authentication with secure HTTP-only cookies in a mobile app backend
- Add multi-factor authentication (TOTP) to an existing Django REST API with minimal configuration
- Enable social login (Google, GitHub, Facebook) in a REST API using django-allauth integration
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building a Django REST Framework API and need standard authentication endpoints.
The package is actively maintained, has no known vulnerabilities, and eliminates significant boilerplate. High install friction is offset by the time saved on auth implementation. Not suitable if you are not already using Django and djangorestframework.
Install
dj-rest-auth on PyPI
Before you install
High install friction due to two required runtime dependencies (Django and djangorestframework). Package is actively maintained with recent commits and no known vulnerabilities, but setup requires integrating into an existing Django project and configuring multiple settings.
Requires an existing Django project with djangorestframework installed and configured; Django database migrations must be run after adding dj_rest_auth to INSTALLED_APPS.
License in practice
MIT license is permissive and imposes no restrictions on use, modification, or distribution in commercial or private projects.
Quickstart
pip install dj-rest-auth djangorestframework
# settings.py
INSTALLED_APPS = [
'rest_framework',
'rest_framework.authtoken',
'dj_rest_auth',
]
# urls.py
from django.urls import path, include
urlpatterns = [
path('auth/', include('dj_rest_auth.urls')),
]
# Now POST to /auth/login/ with {"username": "...", "password": "..."}
Verify before relying
- Whether social authentication (Google, GitHub, Facebook) requires additional setup beyond the 'with-social' extra
- Performance characteristics under high concurrent authentication load
- Compatibility with specific versions of Django and djangorestframework beyond the minimum Python 3.10 requirement
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | High. Source build required |
| Runtime dependencies | 2 packagesDjangodjangorestframework |
| Maintenance | Actively maintained 152 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 815,464 / month, #4,990 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Framework :: DjangoIntended Audience :: DevelopersIntended Audience :: System AdministratorsOperating System :: OS IndependentTopic :: Software Development |
Evidence: dj_rest_auth-7.2.0.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django login logout api endpoints”
- dj-rest-authProvides drop-in REST API endpoints for user authentication,…
- djoserProvides Django REST Framework views for user registration, login,…
- django-rest-authProvides REST API endpoints for user authentication and registration…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also django-maintenance-mode · django-rest-auth · django-rest-passwordreset · djoser · django-allauth-2fa · django-rest-knox · django-registration-redux · drf-jwt · djangorestframework-jwt · django-allauth