propelauth-py
A python authentication library
Decision gist · record as of 2026-08-14
Yes, if you are building a B2B or multi-tenant application and already use or plan to adopt PropelAuth. The library eliminates token validation boilerplate and integrates cleanly with standard Python web frameworks. It is actively maintained, has no known vulnerabilities, and carries a permissive MIT license. Not suitable if you need a standalone auth solution without external service dependency.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later and a valid PropelAuth account with auth URL and API key.
- Low install friction with a pure-Python wheel distribution.
- Actively maintained with a recent release (115 days ago) and a stable commit history.
License · maintenance · safety
MIT (permissive) — MIT license permits unrestricted use, modification, and distribution in commercial and private projects with only attribution required.
last release 2026-04-21 (115 days) · last repo commit 2026-06-16 · 13 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 388,370 downloads/mo, #7,035 on PyPI
Alternatives
Verify before relying
from propelauth_py import init_base_auth
auth = init_base_auth("YOUR_AUTH_URL", "YOUR_API_KEY")
user = auth.validate_access_token_and_get_user("Bearer TOKEN")
print(user.user_id)- Whether the PropelAuth backend service itself is required and what its operational costs or availability guarantees are
- Performance characteristics when validating tokens at scale or under high request volume
- Whether token caching or refresh strategies are built in or must be implemented separately
What it is and what it does
PropelAuth Python SDK is a client library that connects your Python backend to PropelAuth's hosted authentication service. It handles token validation, user identity retrieval, and organization-level authorization checks (membership, roles, permissions) without requiring you to implement JWT verification or auth logic yourself. The library wraps HTTP calls to PropelAuth's backend APIs via httpx and requests, and uses pyjwt for token handling.
Typically, you initialize it once with your auth URL and API key, then call validate_access_token_and_get_user on incoming requests to extract and verify the bearer token from the Authorization header. The returned User object lets you inspect organization membership, role hierarchies, and custom permissions. It also exposes direct API methods to create magic links, fetch users, and manage organizations—useful for backend-to-backend operations beyond request validation.
Use it for
- Protect API routes by validating bearer tokens and extracting authenticated user identity before processing requests.
- Check whether a user belongs to a specific organization and return a 403 error if they do not.
- Verify that a user holds a required role (e.g., Owner, Admin) within an organization before granting access to sensitive operations.
- Enforce fine-grained permissions (e.g., 'can_view_billing') by querying the User object after token validation.
- Generate magic links or manage users and organizations programmatically via the PropelAuth backend API.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building a B2B or multi-tenant application and already use or plan to adopt PropelAuth.
The library eliminates token validation boilerplate and integrates cleanly with standard Python web frameworks. It is actively maintained, has no known vulnerabilities, and carries a permissive MIT license. Not suitable if you need a standalone auth solution without external service dependency.
Install
propelauth-py on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Actively maintained with a recent release (115 days ago) and a stable commit history.
Requires Python 3.9 or later and a valid PropelAuth account with auth URL and API key.
License in practice
MIT license permits unrestricted use, modification, and distribution in commercial and private projects with only attribution required.
Quickstart
from propelauth_py import init_base_auth
auth = init_base_auth("YOUR_AUTH_URL", "YOUR_API_KEY")
user = auth.validate_access_token_and_get_user("Bearer TOKEN")
print(user.user_id)
Verify before relying
- Whether the PropelAuth backend service itself is required and what its operational costs or availability guarantees are
- Performance characteristics when validating tokens at scale or under high request volume
- Whether token caching or refresh strategies are built in or must be implemented separately
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packageshttpxpyjwtrequests |
| Maintenance | Actively maintained 115 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 388,370 / month, #7,035 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: propelauth_py-4.4.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “b2b user authorization”
- propelauth-pyValidates access tokens and manages user authentication and…
- propelauth-fastapiIntegrates PropelAuth's authentication and authorization service into…
- stytchA Python client library for integrating Stytch's authentication and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also propelauth-fastapi · PyGithub · stytch · workos · onelogin · pymacaroons · auth · axioms-fastapi · cognitojwt · Flask-Principal