Flask-OAuthlib
OAuthlib for Flask
Decision gist · record as of 2026-08-14
No for new projects—the author recommends authlib instead. Yes-with-conditions for maintaining existing Flask-OAuthlib applications: the package is dormant (last release 2020-09-07), has no known vulnerabilities, and installs easily, but you should plan a migration path to authlib or another actively maintained OAuth library. Do not use for new OAuth integrations.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Flask and oauthlib as runtime dependencies; no minimum Python version is formally specified, though classifiers indicate support for Python 2.6 through 3.6.
- Low install friction with a pure-Python wheel.
- Maintenance is dormant—the last release was 2020-09-07, and the repository shows no recent commits despite being archived=false.
License · maintenance · safety
BSD (permissive) — BSD license (permissive) imposes no significant restrictions on use, modification, or distribution in proprietary or open-source projects.
last release 2020-09-07 (2167 days) · last repo commit 2024-07-19 · 1,446 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 369,752 downloads/mo, #7,184 on PyPI
Alternatives
Verify before relying
pip install Flask-OAuthlib
from flask import Flask
from flask_oauthlib.client import OAuth
app = Flask(__name__)
oauth = OAuth(app)- Whether the package remains compatible with modern Python versions (3.8+) despite classifiers only listing up to 3.6.
- Current state of OAuth 2.0 provider implementation and whether it meets contemporary security standards.
- Whether dormant status means critical bugs or security issues in the OAuth flow implementation will be addressed.
What it is and what it does
Flask-OAuthlib is a Flask extension that wraps oauthlib to provide OAuth authentication and authorization capabilities. It lets you build Flask applications that act as OAuth clients (authenticating users via external OAuth providers like Google or GitHub) and as OAuth providers (issuing tokens to third-party applications). The package supports OAuth 1.0a/1.0/1.1 on the client side and both OAuth 1.0 (with HMAC and RSA signatures) and OAuth 2.0 (with Bearer tokens) on the provider side.
The extension integrates directly with Flask's request/response model and provides a friendly API similar to the older Flask-OAuth. It depends on Flask, oauthlib, requests-oauthlib, and cachelib. However, the package is dormant—its last release was 2020-09-07, and the author explicitly recommends using authlib instead for new projects. This makes it suitable mainly for maintaining existing applications rather than starting new OAuth integrations.
Use it for
- Add OAuth 2.0 login (e.g., via Google or GitHub) to an existing Flask web application.
- Build a Flask-based OAuth provider to issue access tokens to third-party client applications.
- Migrate from Flask-OAuth to a more capable OAuth library while keeping Flask integration.
- Implement OAuth 1.0a authentication for legacy APIs that do not support OAuth 2.0.
- Cache OAuth tokens and credentials within a Flask application using the cachelib integration.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No for new projects—the author recommends authlib instead.
Yes-with-conditions for maintaining existing Flask-OAuthlib applications: the package is dormant (last release 2020-09-07), has no known vulnerabilities, and installs easily, but you should plan a migration path to authlib or another actively maintained OAuth library. Do not use for new OAuth integrations.
Install
flask-oauthlib on PyPI
Before you install
Low install friction with a pure-Python wheel. Maintenance is dormant—the last release was 2020-09-07, and the repository shows no recent commits despite being archived=false. The author's own description recommends authlib as an alternative.
Requires Flask and oauthlib as runtime dependencies; no minimum Python version is formally specified, though classifiers indicate support for Python 2.6 through 3.6.
License in practice
BSD license (permissive) imposes no significant restrictions on use, modification, or distribution in proprietary or open-source projects.
Quickstart
pip install Flask-OAuthlib
from flask import Flask
from flask_oauthlib.client import OAuth
app = Flask(__name__)
oauth = OAuth(app)
Verify before relying
- Whether the package remains compatible with modern Python versions (3.8+) despite classifiers only listing up to 3.6.
- Current state of OAuth 2.0 provider implementation and whether it meets contemporary security standards.
- Whether dormant status means critical bugs or security issues in the OAuth flow implementation will be addressed.
Package facts
| License | BSD permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagesFlaskoauthlibrequests-oauthlibcachelib |
| Maintenance | Dormant 2,167 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 369,752 / month, #7,184 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaEnvironment :: Web EnvironmentIntended Audience :: DevelopersLicense :: OSI ApprovedLicense :: OSI Approved :: BSD LicenseOperating System :: MacOSOperating System :: POSIXOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3.3Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: ImplementationProgramming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Software Development :: Libraries :: Python Modules |
Evidence: Flask_OAuthlib-0.9.6-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “flask oauth client provider”
- Flask-OAuthlibFlask-OAuthlib adds OAuth 1.0a and OAuth 2.0 client and provider…
- Flask-DanceFlask-Dance simplifies OAuth authentication in Flask applications by…
- AuthlibAuthlib provides a complete implementation of OAuth 1.0, OAuth 2.0,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also Authlib · oauth2 · oauthlib · Flask-Dance · requests-oauthlib · google-auth-oauthlib · oauthenticator · django-oauth-toolkit · google-auth-oauthlib-stubs · flask-oidc