Flask-BasicAuth
HTTP basic access authentication for Flask.
Decision gist · record as of 2026-08-14
No. The package is abandoned (last release June 2013, last commit February 2021) and has not been tested against modern Python or Flask versions. For new projects, use a maintained authentication library. For existing projects already using it, plan a migration to an actively maintained alternative.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Flask to be installed; package targets Python 2.6, 2.7, and 3.3 but has not been tested against modern Python versions.
- High install friction and abandoned maintenance status (last commit February 2021, no releases since June 2013) make this a risky choice for new projects.
- The package has not been updated in over a decade and receives no active support.
License · maintenance · safety
BSD (permissive) — BSD license is permissive and poses no restrictions on use, modification, or distribution in commercial or private projects.
last release 2013-06-15 (4808 days) · last repo commit 2021-02-12 · 85 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 429,996 downloads/mo, #6,734 on PyPI
Alternatives
Verify before relying
pip install Flask-BasicAuth
from flask import Flask
from flask_basicauth import BasicAuth
app = Flask(__name__)
app.config['BASIC_AUTH_USERNAME'] = 'user'
app.config['BASIC_AUTH_PASSWORD'] = 'pass'
basic_auth = BasicAuth(app)
@app.route('/')
@basic_auth.login_required
def index():
return 'Protected content'- Whether the package works reliably with current Flask versions and modern Python versions.
- Security implications of using an unmaintained authentication library without ongoing audits.
- Whether there are known incompatibilities or breaking changes in newer Flask releases.
- HTTP status code behavior for unauthenticated requests.
What it is and what it does
Flask-BasicAuth is a Flask extension that wraps HTTP basic access authentication—the simple username-and-password mechanism built into the HTTP protocol—so you can protect Flask views with a decorator. It lets you configure credentials via Flask config and mark routes as requiring authentication.
The package has no runtime dependencies beyond Flask itself and is straightforward to set up. However, it has been abandoned since June 2013 and has not received updates or maintenance for over a decade. The codebase targets Python 2.6, 2.7, and 3.3, and there is no evidence it has been tested against modern Python versions or recent Flask releases. For new projects, this poses significant risk: you are adopting a library that will not receive bug fixes, security patches, or compatibility updates.
Use it for
- Protecting internal admin dashboards or development tools with simple HTTP basic auth when no complex user management is needed.
- Adding quick authentication to Flask prototypes or proof-of-concept applications during early development.
- Securing API endpoints in legacy Flask applications that already depend on this package and cannot easily migrate.
- Protecting static documentation or internal services where basic credentials are acceptable.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is abandoned (last release June 2013, last commit February 2021) and has not been tested against modern Python or Flask versions. For new projects, use a maintained authentication library. For existing projects already using it, plan a migration to an actively maintained alternative.
Install
flask-basicauth on PyPI
Before you install
High install friction and abandoned maintenance status (last commit February 2021, no releases since June 2013) make this a risky choice for new projects. The package has not been updated in over a decade and receives no active support.
Requires Flask to be installed; package targets Python 2.6, 2.7, and 3.3 but has not been tested against modern Python versions.
License in practice
BSD license is permissive and poses no restrictions on use, modification, or distribution in commercial or private projects.
Quickstart
pip install Flask-BasicAuth
from flask import Flask
from flask_basicauth import BasicAuth
app = Flask(__name__)
app.config['BASIC_AUTH_USERNAME'] = 'user'
app.config['BASIC_AUTH_PASSWORD'] = 'pass'
basic_auth = BasicAuth(app)
@app.route('/')
@basic_auth.login_required
def index():
return 'Protected content'
Verify before relying
- Whether the package works reliably with current Flask versions and modern Python versions.
- Security implications of using an unmaintained authentication library without ongoing audits.
- Whether there are known incompatibilities or breaking changes in newer Flask releases.
- HTTP status code behavior for unauthenticated requests.
Package facts
| License | BSD permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Abandoned 4,808 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 429,996 / month, #6,734 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: Web EnvironmentIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3.3Programming Language :: Python :: Implementation :: PyPyTopic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Software Development :: Libraries :: Python Modules |
Evidence: Flask-BasicAuth-0.2.0.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “flask basic auth”
- Flask-BasicAuthFlask-BasicAuth adds HTTP basic access authentication to Flask…
- Flask-HTTPAuthAdds HTTP Basic, Digest, and Token authentication decorators to Flask…
- dash-authAdds HTTP Basic Authentication and OpenID Connect (OIDC) login to…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also aiohttp-basicauth · Flask-HTTPAuth · Flask-Paranoid · Flask-Login · Flask-Principal · Flask-JWT-Extended · flask-talisman · Flask-WTF · python-cas · sanic-jwt