Flask-HTTPAuth
HTTP authentication for Flask routes
Decision gist · record as of 2026-08-14
Yes. Flask-HTTPAuth is a mature, actively maintained package with no known vulnerabilities, permissive licensing, and minimal install friction. It solves a common problem—protecting Flask routes with standard HTTP authentication—directly and without unnecessary dependencies. Install it when you need straightforward Basic, Digest, or Token auth and want to avoid building authentication from scratch.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction install with a single runtime dependency on flask.
- Active maintenance with a recent release and steady repository activity.
License · maintenance · safety
permissive license (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal obligations.
last release 2026-03-28 (139 days) · last repo commit 2026-05-14 · 1,288 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 2,582,543 downloads/mo, #2,985 on PyPI
Alternatives
Verify before relying
pip install Flask-HTTPAuth
from flask import Flask
from flask_httpauth import HTTPBasicAuth
app = Flask(__name__)
auth = HTTPBasicAuth()
users = {"john": "hello"}
@auth.verify_password
def verify_password(username, password):
if username in users and users[username] == password:
return username
@app.route('/')
@auth.login_required
def index():
return "Hello, %s!" % auth.current_user()- Whether password hashing utilities are included or require a separate dependency for production use.
- Specific HTTP status codes returned by authentication failures.
What it is and what it does
Flask-HTTPAuth is a lightweight extension that adds HTTP authentication to Flask applications. It provides decorators for three standard authentication schemes—Basic, Digest, and Token—allowing you to protect individual routes or groups of routes with credential verification. You define a callback function to validate credentials against a database or in-memory store, then decorate your route handlers with @auth.login_required to enforce authentication.
The package integrates directly with Flask's request handling and works with standard HTTP authentication protocols. It's designed for straightforward authentication needs in REST APIs and web applications where you want to avoid the overhead of session management or third-party OAuth providers. The extension handles the HTTP protocol details—parsing Authorization headers and managing authentication state—so you focus only on credential validation logic.
Use it for
- Protect REST API endpoints with Basic authentication for internal tools or third-party integrations.
- Add Digest authentication to web services where credentials must not be sent in plaintext.
- Implement Token-based authentication for mobile apps or single-page applications.
- Secure administrative routes in Flask applications with simple decorator-based access control.
- Build microservices that require lightweight HTTP authentication without external identity providers.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Flask-HTTPAuth is a mature, actively maintained package with no known vulnerabilities, permissive licensing, and minimal install friction. It solves a common problem—protecting Flask routes with standard HTTP authentication—directly and without unnecessary dependencies. Install it when you need straightforward Basic, Digest, or Token auth and want to avoid building authentication from scratch.
Install
flask-httpauth on PyPI
Before you install
Low friction install with a single runtime dependency on flask. Active maintenance with a recent release and steady repository activity.
License in practice
MIT license permits unrestricted use, modification, and distribution with minimal obligations.
Quickstart
pip install Flask-HTTPAuth
from flask import Flask
from flask_httpauth import HTTPBasicAuth
app = Flask(__name__)
auth = HTTPBasicAuth()
users = {"john": "hello"}
@auth.verify_password
def verify_password(username, password):
if username in users and users[username] == password:
return username
@app.route('/')
@auth.login_required
def index():
return "Hello, %s!" % auth.current_user()
Verify before relying
- Whether password hashing utilities are included or require a separate dependency for production use.
- Specific HTTP status codes returned by authentication failures.
Package facts
| License | permissive license permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageflask |
| Maintenance | Actively maintained 139 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 2,582,543 / month, #2,985 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: Web EnvironmentIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: Implementation :: MicroPython |
Evidence: flask_httpauth-4.8.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “flask http authentication”
- Flask-HTTPAuthAdds HTTP Basic, Digest, and Token authentication decorators to Flask…
- Flask-BasicAuthFlask-BasicAuth adds HTTP basic access authentication to Flask…
- Flask-AWSCognitoIntegrates AWS Cognito user authentication into Flask applications,…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also Flask-AWSCognito · Flask-JWT-Extended · Flask-BasicAuth · dash-auth · Flask-Paranoid · aiohttp-basicauth · quart-auth · flask-cloudflared · Flask-Login · Flask-Bcrypt