django-user-sessions
Django sessions with a foreign key to the user
Decision gist · record as of 2026-08-14
Yes. This is a mature, actively maintained package (Production/Stable status, 719 GitHub stars) that solves a real Django limitation with zero security vulnerabilities and minimal install friction. Use it if you need per-user session visibility or multi-device logout; skip it if you have no need to query or manage sessions programmatically.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Django 3.2 or 4.0; GeoIP setup needed for location detection features.
- Low friction: single Django dependency, wheel distribution.
- Actively maintained with recent commits and no known vulnerabilities.
License · maintenance · safety
MIT (permissive) — MIT license is permissive; you can use, modify, and distribute this package freely in commercial and open-source projects with minimal restrictions.
last release 2022-12-13 (1340 days) · last repo commit 2026-08-10 · 719 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 95,197 downloads/mo, #13,281 on PyPI
Alternatives
Verify before relying
pip install django-user-sessions
# In Django settings, replace django.contrib.sessions with django_user_sessions
# Then query sessions:
from django.utils.timezone import now
user.session_set.filter(expire_date__gt=now())
# Or logout user everywhere:
user.session_set.all().delete()- Whether GeoIP setup is required for basic session tracking or only for location detection features.
- Current compatibility with Django versions beyond 4.0 and Python versions beyond 3.10.
What it is and what it does
Django User Sessions converts Django's built-in session system—which stores all data in opaque base64-encoded blobs—into first-class ORM objects linked to user accounts. This lets you query, filter, and manage sessions like any other Django model. The package stores IP address and user-agent information alongside session data, enabling you to display active sessions to users or administrators and perform bulk operations like logging a user out across all devices.
It's a drop-in replacement for Django's standard session backend, requiring only Django as a runtime dependency. The package supports Django 3.2 and 4.0 on Python 3.7, 3.8, 3.9 and 3.10. Common operations include filtering a user's active sessions by expiration date and deleting all sessions for a user in a single call.
Use it for
- Display a list of all active sessions for a user in account settings, showing device, IP, and last activity.
- Implement a 'log out everywhere' button that terminates all of a user's sessions at once.
- Query and audit session data for security monitoring or compliance reporting.
- Build admin dashboards that show active user sessions across your application.
- Detect and revoke suspicious sessions based on IP address or user-agent anomalies.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is a mature, actively maintained package (Production/Stable status, 719 GitHub stars) that solves a real Django limitation with zero security vulnerabilities and minimal install friction. Use it if you need per-user session visibility or multi-device logout; skip it if you have no need to query or manage sessions programmatically.
Install
django-user-sessions on PyPI
Before you install
Low friction: single Django dependency, wheel distribution. Actively maintained with recent commits and no known vulnerabilities.
Requires Django 3.2 or 4.0; GeoIP setup needed for location detection features.
License in practice
MIT license is permissive; you can use, modify, and distribute this package freely in commercial and open-source projects with minimal restrictions.
Quickstart
pip install django-user-sessions
# In Django settings, replace django.contrib.sessions with django_user_sessions
# Then query sessions:
from django.utils.timezone import now
user.session_set.filter(expire_date__gt=now())
# Or logout user everywhere:
user.session_set.all().delete()
Verify before relying
- Whether GeoIP setup is required for basic session tracking or only for location detection features.
- Current compatibility with Django versions beyond 4.0 and Python versions beyond 3.10.
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageDjango |
| Maintenance | Actively maintained 1,340 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 95,197 / month, #13,281 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 3.2Framework :: Django :: 4.0Intended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Security |
Evidence: django_user_sessions-2.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django user sessions queryable”
- django-user-sessionsReplaces Django's opaque session backend with queryable ORM objects…
- django-session-timeoutAdds automatic session expiration to Django applications, allowing…
- django-easy-auditLogs every CRUD operation, authentication event, and HTTP request in…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also Flask-Login · django-two-factor-auth · django-mock-queries · django-logentry-admin · django-netfields · quart-auth · djoser · django-loginas · djongo