django-authlib
Authentication utils for Django
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has no known vulnerabilities, installs with minimal friction, and solves a real problem (passwordless authentication) in a deliberately lightweight way. It's suitable for Django projects of any size that want OAuth2 or email-based login without heavy dependencies. The MIT license poses no restrictions.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Django project setup; OAuth providers need client credentials (GOOGLE_CLIENT_ID, etc.) configured in settings; OAUTHLIB_INSECURE_TRANSPORT must be set for development without HTTPS.
- Low install friction with a single runtime dependency (requests-oauthlib).
- Active maintenance with a recent release 43 days ago and ongoing commits.
License · maintenance · safety
MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
last release 2026-07-02 (43 days) · last repo commit 2026-08-11 · 72 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 96,102 downloads/mo, #13,230 on PyPI
Alternatives
Verify before relying
pip install django-authlib
In settings.py:
AUTHENTICATION_BACKENDS = ['authlib.backends.EmailBackend']
INSTALLED_APPS = [..., 'authlib']
from authlib.google import GoogleOAuth2Client
from authlib import views
# Use views.oauth2 with GoogleOAuth2Client for OAuth login- Whether the package supports Django versions beyond those implied by the Python 3.9+ requirement.
- Performance characteristics when handling high-volume email-based authentication flows.
- Current state of documentation beyond the README excerpt provided.
What it is and what it does
django-authlib is a lightweight Django authentication library that replaces password-based login with passwordless alternatives. It supports two main flows: sending cryptographically signed email links for registration and login, or delegating authentication to OAuth2 providers (Google, Microsoft, Facebook, Twitter). The library is intentionally minimal—it provides authentication backends and optional bundled views rather than imposing a full framework, allowing developers to integrate it into existing Django projects with minimal configuration.
The package includes an optional admin OAuth module for restricting Django admin access to users from specific email domains, and a basic user model (little_auth) for projects that don't have a custom user implementation. It relies on requests-oauthlib for OAuth handling and integrates with Django's authentication system via the EmailBackend. Setup requires adding the backend to AUTHENTICATION_BACKENDS and optionally including the app in INSTALLED_APPS for translation support.
Use it for
- Add OAuth2 social login (Google, Microsoft, Facebook, Twitter) to a Django site without building OAuth flows from scratch.
- Implement email-based passwordless registration where users receive signed links instead of setting passwords.
- Restrict Django admin access to users from a specific email domain using OAuth2 credentials.
- Replace traditional password authentication in a Django app with email-link-based login for improved security.
- Integrate a lightweight user model with email-as-username for projects without a custom user implementation.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has no known vulnerabilities, installs with minimal friction, and solves a real problem (passwordless authentication) in a deliberately lightweight way. It's suitable for Django projects of any size that want OAuth2 or email-based login without heavy dependencies. The MIT license poses no restrictions.
Install
django-authlib on PyPI
Before you install
Low install friction with a single runtime dependency (requests-oauthlib). Active maintenance with a recent release 43 days ago and ongoing commits.
Requires Django project setup; OAuth providers need client credentials (GOOGLE_CLIENT_ID, etc.) configured in settings; OAUTHLIB_INSECURE_TRANSPORT must be set for development without HTTPS.
License in practice
MIT license permits free use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
Quickstart
pip install django-authlib
In settings.py:
AUTHENTICATION_BACKENDS = ['authlib.backends.EmailBackend']
INSTALLED_APPS = [..., 'authlib']
from authlib.google import GoogleOAuth2Client
from authlib import views
# Use views.oauth2 with GoogleOAuth2Client for OAuth login
Verify before relying
- Whether the package supports Django versions beyond those implied by the Python 3.9+ requirement.
- Performance characteristics when handling high-volume email-based authentication flows.
- Current state of documentation beyond the README excerpt provided.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagerequests-oauthlib |
| Maintenance | Actively maintained 43 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 96,102 / month, #13,230 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: DjangoLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9 |
Evidence: django_authlib-0.18.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “oauth2 social login django”
- django-authlibProvides passwordless authentication for Django using email-based…
- fastapi-auth0Integrates Auth0 authentication into FastAPI applications with…
- social-auth-app-djangoIntegrates social authentication and registration into Django…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also django-allauth · django-google-sso · django-magiclink · django-sesame · stytch · django-auth-ldap · django-auth-adfs · Authlib · django-otp-webauthn · webauthn