oauth2-client
A client library for OAuth2
Decision gist · record as of 2026-08-14
Yes, with conditions. The package is stable and has no known vulnerabilities, making it suitable for straightforward OAuth2 flows in applications that can tolerate aging maintenance. However, verify the license before use, test token expiration handling against your OAuth2 server, and be prepared to maintain or fork the code if the upstream project does not resume active development. Not recommended for new projects requiring ongoing security updates or support.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with no runtime dependencies.
- Maintenance status is aging—last release was in April 2023 and the repository has not been updated since January 2026, though it remains unarchived and has received a recent commit.
License · maintenance · safety
(unclear) — License treatment is unclear; no SPDX identifier or raw license text is available in the metadata. Verify the actual license before use in proprietary or restricted contexts.
last release 2023-04-28 (1204 days) · last repo commit 2026-01-08 · 16 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 203,781 downloads/mo, #9,624 on PyPI
Alternatives
Verify before relying
pip install oauth2-client
from oauth2_client.credentials_manager import CredentialManager, ServiceInformation
service_info = ServiceInformation(
'https://authorization-server/oauth/authorize',
'https://token-server/oauth/token',
'client_id', 'client_secret', ['scope_1'])
manager = CredentialManager(service_info)
manager.init_with_user_credentials('login', 'password')- Whether the package is actively maintained or will receive security updates going forward
- What license applies to the package (SPDX and raw license fields are both null)
- Whether token expiration handling is accurate for your specific OAuth2 server implementation
What it is and what it does
OAuth2Client is a Python library that abstracts the OAuth2 authentication process, handling three common token flows: authorization code (with optional PKCE support), user credentials, and client credentials. It manages token lifecycle including refresh and expiration detection, and provides a CredentialManager class that can be extended to handle server-specific token response fields like OpenID's id_token.
The library starts a local HTTP server to receive authorization callbacks in the authorization code flow, and supports proxy configuration for all flows. It is built on top of the requests library but has no other runtime dependencies, making it lightweight to install. However, the package has not been actively developed since April 2023, and token expiration detection may not be accurate for all OAuth2 server implementations without subclassing and customization.
Use it for
- Implement authorization code flow with PKCE for desktop or mobile applications redirecting to a local callback handler
- Obtain and refresh access tokens using user credentials for server-to-user OAuth2 integrations
- Manage client credentials grants for service-to-service authentication without user interaction
- Extend CredentialManager to parse and store additional token response fields like OpenID Connect id_token
- Integrate OAuth2 authentication into applications that need to work behind HTTP proxies
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
The package is stable and has no known vulnerabilities, making it suitable for straightforward OAuth2 flows in applications that can tolerate aging maintenance. However, verify the license before use, test token expiration handling against your OAuth2 server, and be prepared to maintain or fork the code if the upstream project does not resume active development. Not recommended for new projects requiring ongoing security updates or support.
Install
oauth2-client on PyPI
Before you install
Low install friction with no runtime dependencies. Maintenance status is aging—last release was in April 2023 and the repository has not been updated since January 2026, though it remains unarchived and has received a recent commit.
License in practice
License treatment is unclear; no SPDX identifier or raw license text is available in the metadata. Verify the actual license before use in proprietary or restricted contexts.
Quickstart
pip install oauth2-client
from oauth2_client.credentials_manager import CredentialManager, ServiceInformation
service_info = ServiceInformation(
'https://authorization-server/oauth/authorize',
'https://token-server/oauth/token',
'client_id', 'client_secret', ['scope_1'])
manager = CredentialManager(service_info)
manager.init_with_user_credentials('login', 'password')
Verify before relying
- Whether the package is actively maintained or will receive security updates going forward
- What license applies to the package (SPDX and raw license fields are both null)
- Whether token expiration handling is accurate for your specific OAuth2 server implementation
Package facts
| License | Not declared unclear |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 1,204 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 203,781 / month, #9,624 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Natural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Communications |
Evidence: oauth2_client-1.4.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “oauth2 authentication client”
- oauth2-clientHandles OAuth2 authentication flows (authorization code, user…
- httpx-authProvides authentication classes for httpx HTTP client requests,…
- google-oauth2-toolGenerates an OAuth2 key file from a Google OAuth2 client ID file,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Communications packages
Pyasn1 encodes and decodes ASN.1 data structures using BER, CER, DER, and native Python codecs, allowing you to serialize complex data for network protocols and file formats.
Install it if you need to work with ASN.1-based protocols or formats; it is the standard library for this in Python and has no known vulnerabilities.
Provides a collection of ASN.1 data structures expressed as Python classes, built on the pyasn1 library, for working with ASN.1-based protocols and standards.
Kombu is a messaging library that provides a high-level Python interface to AMQP and other message brokers, supporting pluggable transports for RabbitMQ, Redis, MongoDB, Amazon SQS, and others.
Install it if you are building any distributed system that requires reliable message passing.
Formats and parses numbers, file sizes, timespans, and other values into human-readable text; provides terminal interaction utilities including ANSI text styling and user prompts.
Adds colored output to Python's standard logging module using ANSI escape sequences, with automatic fallback support for Windows terminals.
However, it is abandoned and receives no maintenance, so it will not adapt to future Python changes or platform updates.
Parse, validate, format, and analyze international phone numbers across all countries, with support for extracting geographic, carrier, and timezone information from phone number data.
See also fds.sdk.utils · openfga-sdk · PureCloudPlatformClientV2 · requests-oauth2client · dynamics365crm-python · requests-oauthlib · h2o-authn · oauth2client · requests-auth · stups-tokens