$npx skillfedfor your agent

flask-unsign

Flask Unsign is a penetration testing utility that attempts to uncover a Flask server's secret key by taking a signed session verifying it against a wordlist of commonly used and publicly known secret keys (sourced from books, GitHub, StackOverflow and various other sources).

With conditionsPyPI SecurityReleased Dec 2024101.2K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — flask_unsign-1.2.1-py3-none-any.whl
v1.2.1 · released 2024-12-03 · Python >=3.6.0 · 5 runtime deps: flask, requests, itsdangerous, markupsafe, werkzeug

Yes, if you are conducting authorized security testing or developing Flask applications and need to verify session security. The low install friction and permissive license make it accessible. However, maintenance is dormant (last release 619 days ago), so expect no active support; use it for one-off testing rather than as a dependency in production code. Not suitable for general-purpose use outside security testing contexts.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.6 or later.
  • Wordlist-based brute-forcing requires a newline-delimited wordlist file or the optional [wordlist] extra.
  • Low install friction with a pure-Python wheel.

License · maintenance · safety

MIT (permissive) — MIT license is permissive; you can use, modify, and distribute this tool freely in commercial and private projects with minimal restrictions, provided you retain the license notice.

last release 2024-12-03 (619 days) · last repo commit 2024-12-03 · 660 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 101,208 downloads/mo, #12,955 on PyPI

Verify before relying

pip install flask-unsign
flask-unsign --decode --cookie 'eyJsb2dnZWRfaW4iOmZhbHNlfQ.XDuWxQ.E2Pyb6x3w-NODuflHoGnZOEpbH8'
flask-unsign --unsign --cookie < cookie.txt
  • Whether the tool works reliably against modern Flask/itsdangerous versions without the --legacy flag.
  • Performance characteristics when brute-forcing against large wordlists on typical hardware.
  • Compatibility with Flask applications using custom session serialization or signing algorithms.
Same gist for agents: .md · .json

What it is and what it does

Flask-Unsign is a penetration testing utility designed to test Flask application security by attempting to recover or forge session cookies. It decodes Flask's signed (but not encrypted) session data, brute-forces the server's secret key against wordlists of common keys, and can craft new session cookies once a key is found. The tool operates as a command-line utility and depends on Flask, itsdangerous, and related web framework libraries.

The package is intended for authorized security testing and development environments. It reads session cookies from HTTP responses or accepts them directly, then attempts to match the signature against a wordlist of known or guessed secret keys. Once a match is found, you can generate new signed session data with arbitrary content. The tool includes options for handling older itsdangerous versions (--legacy flag) and custom wordlist formats.

Use it for

  • Test your own Flask application's session security by attempting to recover the secret key with common wordlists.
  • Decode and inspect Flask session data during development and debugging without knowing the secret key.
  • Authorized penetration testing to verify whether a Flask server uses weak or publicly known secret keys.
  • Forge custom session cookies to test authorization logic and access control in Flask applications.
  • Verify that session management is properly implemented before deploying a Flask application to production.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are conducting authorized security testing or developing Flask applications and need to verify session security.

The low install friction and permissive license make it accessible. However, maintenance is dormant (last release 619 days ago), so expect no active support; use it for one-off testing rather than as a dependency in production code. Not suitable for general-purpose use outside security testing contexts.

Install

flask-unsign on PyPI

Before you install

Low install friction with a pure-Python wheel. Maintenance is dormant—last release was 619 days ago, though the repository remains active with a recent commit on 2024-12-03. Suitable for one-off testing but not for ongoing development.

Requires Python 3.6 or later. Wordlist-based brute-forcing requires a newline-delimited wordlist file or the optional [wordlist] extra.

License in practice

MIT license is permissive; you can use, modify, and distribute this tool freely in commercial and private projects with minimal restrictions, provided you retain the license notice.

Quickstart

pip install flask-unsign
flask-unsign --decode --cookie 'eyJsb2dnZWRfaW4iOmZhbHNlfQ.XDuWxQ.E2Pyb6x3w-NODuflHoGnZOEpbH8'
flask-unsign --unsign --cookie < cookie.txt

Verify before relying

  • Whether the tool works reliably against modern Flask/itsdangerous versions without the --legacy flag.
  • Performance characteristics when brute-forcing against large wordlists on typical hardware.
  • Compatibility with Flask applications using custom session serialization or signing algorithms.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.6.0
Install frictionLow. Pure-Python wheel
Runtime dependencies
5 packages
flaskrequestsitsdangerousmarkupsafewerkzeug
MaintenanceDormant 619 days since the last release
Last repo commit
First released
Downloads101,208 / month, #12,955 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.6Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy

Evidence: flask_unsign-1.2.1-py3-none-any.whl

Tags

Capabilities
flask session cookie decoderbrute force flask secret keyflask cookie unsignerpenetration testing flask sessionsforge flask session cookiesflask security testing tooldecode signed flask cookies
Topics
penetration-testingflask-securitysession-management

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “flask session cookie decoder”

  • flask-unsignCommand-line tool to decode, brute-force, and forge Flask session…
  • Flask-SessionFlask-Session adds server-side session storage to Flask applications,…
  • Flask-LoginFlask-Login handles user session management for Flask applications,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also diceware · pycookiecheat · cookies · browser-cookie3 · flask-talisman · Flask-Paranoid · myjwt · fetch-use · streamlit-cookies-controller · uncurl