djangorestframework-guardian
django-guardian support for Django REST Framework
Decision gist · record as of 2026-08-14
Yes, if you are building a Django REST Framework API that requires object-level permissions beyond Django's standard model-level checks. The package is stable (Production/Stable status), has no known vulnerabilities, and low install friction. However, maintenance is infrequent (409 days since last release), so verify it works with your specific Django and djangorestframework versions before committing to it in a new project.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- django-guardian and djangorestframework must be installed and configured in INSTALLED_APPS and AUTHENTICATION_BACKENDS before this package's filters will function.
- Low friction: pure Python wheel with three straightforward dependencies (django, djangorestframework, django-guardian).
- Last release 2025-07-01; repository active and not archived, though 409 days since last release suggests maintenance is infrequent.
License · maintenance · safety
BSD-3-Clause (permissive) — BSD-3-Clause (permissive): you may use, modify, and distribute this package freely in commercial and open-source projects, provided you include the license notice.
last release 2025-07-01 (409 days) · last repo commit 2025-07-04 · 163 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 160,532 downloads/mo, #10,658 on PyPI
Alternatives
Verify before relying
pip install djangorestframework-guardian
from djangorestframework_guardian import filters
class MyViewSet:
filter_backends = [filters.ObjectPermissionsFilter]- Whether ObjectPermissionsFilter works correctly with all Django REST Framework view types and pagination strategies.
- Performance characteristics when filtering large querysets with many object-level permissions.
- Compatibility with custom user models or non-standard permission backends.
What it is and what it does
djangorestframework-guardian bridges django-guardian's object-level permission system into Django REST Framework's API layer. It provides two main tools: ObjectPermissionsFilter, which restricts querysets to only objects a user has permission to view, and ObjectPermissionsAssignmentMixin, which automatically assigns permissions to users or groups when objects are created or updated via serializers.
The package is designed for applications that need granular, per-object access control in REST APIs—where different users should see and modify different subsets of the same model. It requires django-guardian to be configured with its ObjectPermissionBackend and works alongside custom permission classes that map HTTP methods to specific permission names.
Use it for
- Multi-tenant SaaS APIs where each user should only see and modify their own data or shared resources.
- Collaborative platforms where permissions are assigned per-object to users and groups dynamically.
- Admin dashboards that expose REST endpoints with row-level security based on object permissions.
- Workflows where creating a resource automatically grants specific permissions to the creator and designated groups.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building a Django REST Framework API that requires object-level permissions beyond Django's standard model-level checks.
The package is stable (Production/Stable status), has no known vulnerabilities, and low install friction. However, maintenance is infrequent (409 days since last release), so verify it works with your specific Django and djangorestframework versions before committing to it in a new project.
Install
djangorestframework-guardian on PyPI
Before you install
Low friction: pure Python wheel with three straightforward dependencies (django, djangorestframework, django-guardian). Last release 2025-07-01; repository active and not archived, though 409 days since last release suggests maintenance is infrequent.
django-guardian and djangorestframework must be installed and configured in INSTALLED_APPS and AUTHENTICATION_BACKENDS before this package's filters will function.
License in practice
BSD-3-Clause (permissive): you may use, modify, and distribute this package freely in commercial and open-source projects, provided you include the license notice.
Quickstart
pip install djangorestframework-guardian
from djangorestframework_guardian import filters
class MyViewSet:
filter_backends = [filters.ObjectPermissionsFilter]
Verify before relying
- Whether ObjectPermissionsFilter works correctly with all Django REST Framework view types and pagination strategies.
- Performance characteristics when filtering large querysets with many object-level permissions.
- Compatibility with custom user models or non-standard permission backends.
Package facts
| License | BSD-3-Clause permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesdjangodjangorestframeworkdjango-guardian |
| Maintenance | Aging 409 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 160,532 / month, #10,658 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 4.2Framework :: Django :: 5.0Framework :: Django :: 5.1Framework :: Django :: 5.2Intended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13 |
Evidence: djangorestframework_guardian-0.4.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django rest framework object permissions”
- djangorestframework-guardianIntegrates django-guardian's object-level permissions into Django…
- dry-rest-permissionsDefines rules-based permissions for Django REST Framework APIs by…
- rulesrules provides object-level permission checking for Django…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also django-guardian · dry-rest-permissions · bridgekeeper · djangorestframework-role-filters · rest_condition · djangorestframework · django-permissionedforms · django-rest-multiple-models · djangorestframework-filters · oschmod