django-otp
A pluggable framework for adding two-factor authentication to Django using one-time passwords.
Decision gist · record as of 2026-08-14
Yes, if you need OTP-based two-factor authentication in Django and can accept a stable but aging codebase. The package is production-ready, has no known vulnerabilities, and low install friction. However, the lack of active development means you should verify that any OTP plugins you need remain compatible with your Django version, and consider django-two-factor-auth if you prefer a more actively maintained, opinionated solution.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Django to be installed and configured; integrates with django.contrib.auth but is not itself an authentication backend.
- Low install friction with a single runtime dependency on django.
- Maintenance status is aging—the project is stable and production-ready but no longer actively developed by its author, though well-formed issues and pull requests are welcomed.
License · maintenance · safety
Unlicense (permissive) — Licensed under the Unlicense (permissive), placing the code in the public domain with no restrictions on use, modification, or distribution.
last release 2026-01-07 (219 days) · last repo commit 2026-01-07 · 627 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,148,580 downloads/mo, #2,156 on PyPI
Alternatives
Verify before relying
pip install django-otp
from django_otp.decorators import otp_required
@otp_required
def my_view(request):
pass- Whether existing OTP plugins remain maintained and compatible with current Django versions.
- Performance characteristics when handling high volumes of OTP validation requests.
- Compatibility with modern authentication patterns beyond traditional two-factor flows.
What it is and what it does
django-otp is a pluggable framework for adding one-time password authentication to Django projects. It integrates with Django's built-in authentication system to enable two-factor authentication without replacing the core auth backend. The package includes implementations of the standard HOTP and TOTP algorithms (RFC 4226 and RFC 6238) and supports a plugin architecture for additional OTP methods.
The project is stable and production-ready but is aging—it is no longer actively developed by its original author, though the repository remains open to well-formed contributions. It targets developers who need to add OTP-based two-factor authentication to existing Django applications. For users seeking a more opinionated, higher-level solution, the description notes that django-two-factor-auth may be a better fit.
Use it for
- Add two-factor authentication to a Django admin interface or user login flow using TOTP codes from authenticator apps.
- Implement OTP-based account recovery or sensitive action verification in a Django web application.
- Build a custom authentication flow that requires both password and one-time code validation.
- Integrate hardware or software OTP generators into a Django-based identity management system.
- Extend Django authentication with pluggable OTP methods tailored to specific security requirements.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need OTP-based two-factor authentication in Django and can accept a stable but aging codebase.
The package is production-ready, has no known vulnerabilities, and low install friction. However, the lack of active development means you should verify that any OTP plugins you need remain compatible with your Django version, and consider django-two-factor-auth if you prefer a more actively maintained, opinionated solution.
Install
django-otp on PyPI
Before you install
Low install friction with a single runtime dependency on django. Maintenance status is aging—the project is stable and production-ready but no longer actively developed by its author, though well-formed issues and pull requests are welcomed.
Requires Django to be installed and configured; integrates with django.contrib.auth but is not itself an authentication backend.
License in practice
Licensed under the Unlicense (permissive), placing the code in the public domain with no restrictions on use, modification, or distribution.
Quickstart
pip install django-otp
from django_otp.decorators import otp_required
@otp_required
def my_view(request):
pass
Verify before relying
- Whether existing OTP plugins remain maintained and compatible with current Django versions.
- Performance characteristics when handling high volumes of OTP validation requests.
- Compatibility with modern authentication patterns beyond traditional two-factor flows.
Package facts
| License | Unlicense permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagedjango |
| Maintenance | Aging 219 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 5,148,580 / month, #2,156 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableFramework :: DjangoIntended Audience :: DevelopersLicense :: OSI Approved :: The Unlicense (Unlicense)Programming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyTopic :: SecurityTopic :: Software Development :: Libraries :: Python Modules |
Evidence: django_otp-1.7.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django two-factor authentication”
- django-otpAdds one-time password (OTP) support to Django applications, enabling…
- django-two-factor-authAdds complete two-factor authentication to Django projects,…
- django-allauth-2faAdds two-factor authentication to django-allauth versions older than…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also django-allauth-2fa · django-two-factor-auth · PyOTP · yubico-client · django-otp-webauthn · oathtool · authy · pwned-passwords-django · google-reauth · django-allauth