$npx skillfedfor your agent

django-otp-webauthn

FIDO2 WebAuthn support for django-otp: lets your users authenticate with Passkeys

With conditionsPyPI SecurityReleased Jul 2026142.0K downloads / moBSD-3-ClausePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — django_otp_webauthn-0.10.0-py3-none-any.whl
v0.10.0 · released 2026-07-01 · Python >=3.10 · 3 runtime deps: django-otp, django, webauthn

Yes, if you need WebAuthn Passkey support in Django and are willing to target Django 5.2+ and Python 3.10+. The package is actively maintained, has low install friction, carries no known vulnerabilities, and is marked stable for production use. The permissive BSD-3-Clause license poses no restrictions. Evaluate whether your target browsers and user base support WebAuthn before committing.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Django >= 5.2, Python >= 3.10, and django-otp >= 1.4.0; WebAuthn support in the target browser (Chrome 67+, Firefox 60+, Safari 13+, Edge 18+).
  • Low install friction with a pure-Python wheel.
  • Actively maintained as of August 2026, with recent commits and marked stable for production use as of May 2025, though the package is still relatively new.

License · maintenance · safety

BSD-3-Clause (permissive) — BSD-3-Clause permissive license allows commercial and private use with minimal restrictions.

last release 2026-07-01 (44 days) · last repo commit 2026-08-14 · 35 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 141,967 downloads/mo, #11,228 on PyPI

Verify before relying

pip install django-otp-webauthn

# In Django settings.py
INSTALLED_APPS = [
    "django_otp_webauthn",
    "django_otp",
]

MIDDLEWARE = [
    "django.contrib.auth.middleware.AuthenticationMiddleware",
    "django_otp.middleware.OTPMiddleware",
]

OTP_WEBAUTHN_RP_NAME = "My Site"
OTP_WEBAUTHN_RP_ID = "example.com"
OTP_WEBAUTHN_ALLOWED_ORIGINS = ["https://example.com"]
  • Whether the default frontend JavaScript implementation meets CSP requirements in all deployment contexts.
  • Production-readiness status and any known limitations beyond the May 2025 stability claim.
  • Performance characteristics under high registration or authentication volume.
Same gist for agents: .md · .json

What it is and what it does

Django OTP WebAuthn is a plugin for the Django OTP framework that integrates FIDO2 WebAuthn Passkey authentication into Django projects. It uses the py_webauthn library for cryptographic operations and provides both passwordless login and multi-factor authentication modes—users can either replace passwords entirely with biometric or security-key verification, or use Passkeys as a second factor after password entry.

The package includes a default frontend implementation with JavaScript templates for registration and verification flows, styled to work with strict Content Security Policy settings. It requires minimal configuration: adding the app and middleware to Django settings, setting a few environment variables (relying party name, domain, and allowed origins), and including template tags in your login and registration pages. The package supports Django 5.2+ and Python 3.10+, and as of May 2025 is considered stable enough for production use, though it remains relatively new.

Use it for

  • Replace password-based login entirely with biometric or security-key verification for users with compatible devices.
  • Add a second authentication factor after password entry, letting users approve login with a tap or biometric scan.
  • Migrate existing Django projects to FIDO2-compliant authentication without rewriting authentication logic.
  • Support passwordless authentication for organizations requiring strong credential security without managing certificate infrastructure.
  • Enable cross-platform authentication across web, mobile, and desktop by leveraging platform authenticators.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need WebAuthn Passkey support in Django and are willing to target Django 5.2+ and Python 3.10+.

The package is actively maintained, has low install friction, carries no known vulnerabilities, and is marked stable for production use. The permissive BSD-3-Clause license poses no restrictions. Evaluate whether your target browsers and user base support WebAuthn before committing.

Install

django-otp-webauthn on PyPI

Before you install

Low install friction with a pure-Python wheel. Actively maintained as of August 2026, with recent commits and marked stable for production use as of May 2025, though the package is still relatively new.

Requires Django >= 5.2, Python >= 3.10, and django-otp >= 1.4.0; WebAuthn support in the target browser (Chrome 67+, Firefox 60+, Safari 13+, Edge 18+).

License in practice

BSD-3-Clause permissive license allows commercial and private use with minimal restrictions.

Quickstart

pip install django-otp-webauthn

# In Django settings.py
INSTALLED_APPS = [
    "django_otp_webauthn",
    "django_otp",
]

MIDDLEWARE = [
    "django.contrib.auth.middleware.AuthenticationMiddleware",
    "django_otp.middleware.OTPMiddleware",
]

OTP_WEBAUTHN_RP_NAME = "My Site"
OTP_WEBAUTHN_RP_ID = "example.com"
OTP_WEBAUTHN_ALLOWED_ORIGINS = ["https://example.com"]

Verify before relying

  • Whether the default frontend JavaScript implementation meets CSP requirements in all deployment contexts.
  • Production-readiness status and any known limitations beyond the May 2025 stability claim.
  • Performance characteristics under high registration or authentication volume.

Package facts

LicenseBSD-3-Clause permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
django-otpdjangowebauthn
MaintenanceActively maintained 44 days since the last release
Last repo commit
First released
Downloads141,967 / month, #11,228 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaEnvironment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 5.2Framework :: Django :: 6.0Framework :: Django :: 6.1Intended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.15Topic :: Communications :: FIDOTopic :: Security

Evidence: django_otp_webauthn-0.10.0-py3-none-any.whl

Tags

Capabilities
webauthn passkey djangodjango passwordless authenticationfido2 django otpdjango multi-factor authenticationwebauthn mfa djangopasskey registration djangodjango security key login
Topics
webauthnpasswordless-authfido2
PyPI keywords
authenticationdjangodjango-otpfido2mfasecurityu2fwebauthn

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “webauthn passkey django”

  • django-otp-webauthnAdds WebAuthn Passkey support to Django OTP, enabling passwordless…
  • djoserProvides Django REST Framework views for user registration, login,…
  • Flask-SecurityFlask-Security adds authentication, authorization, and user…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also webauthn · soft-webauthn · django-otp · fido2 · django-magiclink · PyOTP · django-authlib · django-two-factor-auth · Flask-Security-Too · djoser