itsdangerous
Safely pass data to untrusted environments and back.
Decision gist · record as of 2026-08-14
Yes. ItsDangerous is a mature, widely-used library (188th on PyPI by downloads) with no known vulnerabilities, zero runtime dependencies, and a permissive license. Install friction is minimal. The aging maintenance status (850 days since last release) is not a concern for a stable, feature-complete utility—it indicates stability rather than abandonment, especially given active repository commits. Install if you need to sign and verify data tokens.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.8 or later.
- Low install friction with no runtime dependencies.
- Maintenance status is aging—last release was 850 days ago—but the repository remains active with recent commits and the package is classified as Production/Stable.
License · maintenance · safety
permissive license (permissive) — Permissive BSD license allows commercial and private use with minimal restrictions, typical for widely-adopted utility libraries.
last release 2024-04-16 (850 days) · last repo commit 2025-06-14 · 3,128 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 222,165,177 downloads/mo, #188 on PyPI
Alternatives
Verify before relying
from itsdangerous import URLSafeSerializer
auth_s = URLSafeSerializer("secret key", "auth")
token = auth_s.dumps({"id": 5, "name": "itsdangerous"})
data = auth_s.loads(token)- Whether compression is applied automatically or requires explicit configuration.
- Performance characteristics when handling large or deeply nested data structures.
- Compatibility with specific serialization formats beyond the default JSON.
What it is and what it does
ItsDangerous is a cryptographic signing library that creates tamper-proof tokens by signing serialized data with a secret key. It's designed for scenarios where you need to pass data through untrusted channels—such as cookies, URLs, or external APIs—and later verify that the data hasn't been modified. The library handles serialization, optional compression, and timestamp validation automatically, letting you focus on the security concern rather than the cryptographic mechanics.
Typically used in web frameworks to create secure session tokens, password reset links, or API authentication tokens. It supports customizable serialization formats and can automatically add and verify timestamps. With no external runtime dependencies and a permissive license, it integrates easily into existing projects.
Use it for
- Generate secure session tokens for web applications that encode user identity without server-side storage.
- Create tamper-proof password reset or email verification links that expire after a set time.
- Sign API authentication tokens to prevent client-side forgery in distributed systems.
- Serialize and sign configuration or state data passed between microservices or untrusted processes.
- Implement secure cookie payloads that encode user preferences or temporary permissions.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
ItsDangerous is a mature, widely-used library (188th on PyPI by downloads) with no known vulnerabilities, zero runtime dependencies, and a permissive license. Install friction is minimal. The aging maintenance status (850 days since last release) is not a concern for a stable, feature-complete utility—it indicates stability rather than abandonment, especially given active repository commits. Install if you need to sign and verify data tokens.
Install
itsdangerous on PyPI
Before you install
Low install friction with no runtime dependencies. Maintenance status is aging—last release was 850 days ago—but the repository remains active with recent commits and the package is classified as Production/Stable.
Requires Python 3.8 or later.
License in practice
Permissive BSD license allows commercial and private use with minimal restrictions, typical for widely-adopted utility libraries.
Quickstart
from itsdangerous import URLSafeSerializer
auth_s = URLSafeSerializer("secret key", "auth")
token = auth_s.dumps({"id": 5, "name": "itsdangerous"})
data = auth_s.loads(token)
Verify before relying
- Whether compression is applied automatically or requires explicit configuration.
- Performance characteristics when handling large or deeply nested data structures.
- Compatibility with specific serialization formats beyond the default JSON.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 850 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 222,165,177 / month, #188 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: PythonTyping :: Typed |
Evidence: itsdangerous-2.2.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “cryptographic signing tokens”
- itsdangerousItsDangerous cryptographically signs data to create tamper-proof…
- jwskateImplements the JOSE family of IETF standards (JWS, JWK, JWA, JWT,…
- pyjwkestImplements JWT, JWS, JWE, and JWK standards for signing, encrypting,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also MarkupSafe · eth-account · endesive · veracode-api-signing · signedjson · sigstore · securesystemslib · standardwebhooks · timeflake · tuf