drf-access-policy
Declarative access policies/permissions modeled after AWS' IAM policies.
Decision gist · record as of 2026-08-14
Yes, with conditions. The package solves a real problem—centralizing and clarifying access control in Django REST Framework—and the MIT license imposes no restrictions. However, dormancy is a concern: the last release was March 2023 and the project receives no active maintenance. Install it if your Django and DRF versions stay within the supported range (Django 2.0–3.2, Python 3.6–3.11) and you can maintain it yourself if needed. For newer Django/Python versions, verify compatibility before committing.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Django and Django REST Framework to be installed separately; no runtime dependencies are declared in the package metadata.
- High install friction: no runtime dependencies listed, but the package is dormant (last release March 2023, last commit August 2024).
- Supports Python 3.6–3.11 and Django 2.0–3.2, though those Django versions are now outdated.
License · maintenance · safety
MIT (permissive) — MIT license is permissive and imposes no restrictions on use or redistribution, making it safe to adopt in commercial or proprietary projects without compliance burden.
last release 2023-03-02 (1261 days) · last repo commit 2024-08-20 · 513 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 106,243 downloads/mo, #12,660 on PyPI
Alternatives
Verify before relying
pip install drf-access-policy
from drf_access_policy.access_policy import AccessPolicy
class ArticleAccessPolicy(AccessPolicy):
statements = [
{"action": ["list", "retrieve"], "principal": "*", "effect": "allow"},
{"action": ["publish"], "principal": ["group:editor"], "effect": "allow"}
]- Whether the package works with Django versions newer than 3.2 (classifiers only list up to 3.2).
- Current compatibility with modern Python 3.12+ given the last release was March 2023.
- Whether field-level permissions work correctly with all serializer types beyond the ModelSerializer example.
What it is and what it does
drf-access-policy brings declarative, centralized access control to Django REST Framework by letting you define authorization rules in a single policy class per view, modeled after AWS IAM syntax. Instead of scattering permission logic across views and serializers, you write explicit statements that match actions (list, retrieve, publish) to principals (users, groups, anonymous) and effects (allow/deny), making access rules readable to both developers and non-technical stakeholders.
The package also provides FieldAccessMixin to dynamically enforce field-level read-only restrictions based on the same policy, so you can control not just who can call an endpoint but which fields they can modify. The core AccessPolicy class is intentionally small (~150 lines) with no magic, and the library includes complete test coverage. It integrates directly into Django REST Framework's ViewSet permission system.
Use it for
- Define role-based access control for a REST API where editors can publish articles but regular users can only list and retrieve them.
- Enforce field-level permissions so junior developers can update certain fields but not others (e.g., status fields reserved for admins).
- Centralize authorization logic in one place instead of spreading it across multiple views, making audits and policy changes easier.
- Use reusable custom conditions to share complex permission checks across multiple policies without code duplication.
- Match HTTP methods (POST, PUT, PATCH) directly in action rules to handle different request types with a single statement.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
The package solves a real problem—centralizing and clarifying access control in Django REST Framework—and the MIT license imposes no restrictions. However, dormancy is a concern: the last release was March 2023 and the project receives no active maintenance. Install it if your Django and DRF versions stay within the supported range (Django 2.0–3.2, Python 3.6–3.11) and you can maintain it yourself if needed. For newer Django/Python versions, verify compatibility before committing.
Install
drf-access-policy on PyPI
Before you install
High install friction: no runtime dependencies listed, but the package is dormant (last release March 2023, last commit August 2024). Supports Python 3.6–3.11 and Django 2.0–3.2, though those Django versions are now outdated. Maintenance signal is weak for a security-adjacent library.
Requires Django and Django REST Framework to be installed separately; no runtime dependencies are declared in the package metadata.
License in practice
MIT license is permissive and imposes no restrictions on use or redistribution, making it safe to adopt in commercial or proprietary projects without compliance burden.
Quickstart
pip install drf-access-policy
from drf_access_policy.access_policy import AccessPolicy
class ArticleAccessPolicy(AccessPolicy):
statements = [
{"action": ["list", "retrieve"], "principal": "*", "effect": "allow"},
{"action": ["publish"], "principal": ["group:editor"], "effect": "allow"}
]
Verify before relying
- Whether the package works with Django versions newer than 3.2 (classifiers only list up to 3.2).
- Current compatibility with modern Python 3.12+ given the last release was March 2023.
- Whether field-level permissions work correctly with all serializer types beyond the ModelSerializer example.
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Dormant 1,261 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 106,243 / month, #12,660 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Framework :: DjangoFramework :: Django :: 2.0Framework :: Django :: 3.0Framework :: Django :: 3.1Framework :: Django :: 3.2License :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: drf-access-policy-1.5.0.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django rest framework access control”
- drf-access-policyDeclares access control rules for Django REST Framework views using…
- djangorestframework-guardianIntegrates django-guardian's object-level permissions into Django…
- djangorestframework-role-filtersAdds role-based access control to Django REST Framework viewsets,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Application Frameworks packages
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Textual is a Python framework for building cross-platform user interfaces that run in the terminal or web browser using a modern, component-based API.
Install it if you're developing CLI tools, dashboards, or interactive terminal applications.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Build and connect to Model Context Protocol servers that expose tools, resources, and prompts to LLM applications over stdio, HTTP, or SSE transports.
Install it if you need to build or connect to servers.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
See also djangorestframework-role-filters · zope.security · django-permissionedforms · dry-rest-permissions · django-zen-queries · cedarpy · awacs · invenio-records-permissions · django-rest-framework-docs · drf-dynamic-fields