Flask-Dance
Doing the OAuth dance with style using Flask, requests, and oauthlib
Decision gist · record as of 2026-08-14
Yes, for stable OAuth authentication needs in Flask apps. The package is mature, well-documented, and carries no known vulnerabilities. Dormant maintenance is acceptable here because OAuth flows are standardized and unlikely to require frequent updates. Install it if you need straightforward OAuth integration; avoid it only if you require active upstream development or support for very recent OAuth extensions.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Flask app configuration with a secret key and OAuth provider credentials (client_id and client_secret).
- Low friction installation with a pure-Python wheel.
- Maintenance is dormant—last release was in March 2024—but the repository remains active with recent commits and no archived status.
License · maintenance · safety
permissive license (permissive) — Licensed under MIT (permissive), allowing unrestricted use, modification, and distribution in both open-source and commercial projects.
last release 2024-03-05 (892 days) · last repo commit 2024-06-07 · 1,012 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,235,885 downloads/mo, #4,175 on PyPI
Alternatives
Verify before relying
pip install Flask-Dance
from flask import Flask
from flask_dance.contrib.github import make_github_blueprint, github
app = Flask(__name__)
app.secret_key = "your-secret-key"
blueprint = make_github_blueprint(client_id="id", client_secret="secret")
app.register_blueprint(blueprint, url_prefix="/login")
if github.authorized:
resp = github.get("/user")
print(resp.json())- Whether the list of supported OAuth providers remains current given the dormant maintenance status.
- Performance characteristics when handling high-volume token storage and refresh scenarios.
- Compatibility with recent Flask and Werkzeug major versions beyond Python 3.7, 3.8, 3.9, 3.10.
What it is and what it does
Flask-Dance is a Flask extension that abstracts the OAuth consumer flow, letting you add OAuth-based login to your application with minimal boilerplate. It wraps requests, oauthlib, and requests-oauthlib to handle token exchange, refresh, and storage transparently. The package provides pre-configured blueprints for popular providers and a flexible API for custom providers.
By default, tokens are stored in Flask's session, but the package supports pluggable storage backends—most commonly SQLAlchemy for persistent database storage. This prevents users from losing authentication when clearing browser cookies. The library integrates with Flask-SQLAlchemy, Flask-Login, and Flask-Caching, making it a natural fit for larger Flask applications that already use those extensions.
Use it for
- Add OAuth login to a Flask app without writing OAuth flow code from scratch.
- Implement persistent OAuth token storage in a database using the SQLAlchemy backend.
- Support multiple OAuth providers in a single Flask application.
- Integrate OAuth authentication with Flask-Login for user session management.
- Build a custom OAuth integration for a non-standard provider using the flexible API.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, for stable OAuth authentication needs in Flask apps.
The package is mature, well-documented, and carries no known vulnerabilities. Dormant maintenance is acceptable here because OAuth flows are standardized and unlikely to require frequent updates. Install it if you need straightforward OAuth integration; avoid it only if you require active upstream development or support for very recent OAuth extensions.
Install
flask-dance on PyPI
Before you install
Low friction installation with a pure-Python wheel. Maintenance is dormant—last release was in March 2024—but the repository remains active with recent commits and no archived status. Suitable for stable use cases where OAuth integration doesn't need active development.
Requires Flask app configuration with a secret key and OAuth provider credentials (client_id and client_secret).
License in practice
Licensed under MIT (permissive), allowing unrestricted use, modification, and distribution in both open-source and commercial projects.
Quickstart
pip install Flask-Dance
from flask import Flask
from flask_dance.contrib.github import make_github_blueprint, github
app = Flask(__name__)
app.secret_key = "your-secret-key"
blueprint = make_github_blueprint(client_id="id", client_secret="secret")
app.register_blueprint(blueprint, url_prefix="/login")
if github.authorized:
resp = github.get("/user")
print(resp.json())
Verify before relying
- Whether the list of supported OAuth providers remains current given the dormant maintenance status.
- Performance characteristics when handling high-volume token storage and refresh scenarios.
- Compatibility with recent Flask and Werkzeug major versions beyond Python 3.7, 3.8, 3.9, 3.10.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 6 packagesrequestsoauthlibrequests-oauthlibFlaskWerkzeugurlobject |
| Maintenance | Dormant 892 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,235,885 / month, #4,175 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Framework :: FlaskFramework :: PytestLicense :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: flask_dance-7.1.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “flask oauth authentication”
- Flask-DanceFlask-Dance simplifies OAuth authentication in Flask applications by…
- Flask-OAuthlibFlask-OAuthlib adds OAuth 1.0a and OAuth 2.0 client and provider…
- Flask-SecurityFlask-Security adds authentication, authorization, and user…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also flask-oidc · Flask-OAuthlib · Flask-Security · Flask-Login · Flask-SQLAlchemy · oauthenticator · Flask-Security-Too · oauthlib · flask-appbuilder · PyLTI1p3