PyJWT
JSON Web Token implementation in Python
Decision gist · record as of 2026-08-14
Yes. PyJWT is a mature, actively maintained library with no known vulnerabilities, low install friction, and permissive licensing. It is the standard choice for token handling in Python and is appropriate for any project requiring token-based authentication or secure token exchange.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later.
- Installation is straightforward with low friction—a pure-Python wheel with only typing_extensions as a runtime dependency.
- The project is actively maintained with a recent release and 5680 repository stars, indicating stable, well-established code.
License · maintenance · safety
MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and commercial projects.
last release 2026-05-21 (85 days) · last repo commit 2026-08-10 · 5,680 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 715,697,201 downloads/mo, #44 on PyPI
Alternatives
Verify before relying
pip install PyJWT
encoded = PyJWT.encode({"some": "payload"}, "secret", algorithm="HS256")
decoded = PyJWT.decode(encoded, "secret", algorithms=["HS256"])- Whether the package supports additional cryptographic algorithms beyond HS256 or if those require optional dependencies.
- Whether typing_extensions is required at runtime or only for type hints on older Python versions.
- What specific algorithms and signing methods are supported by the library.
What it is and what it does
PyJWT is a production-stable implementation of the JSON Web Token standard (RFC 7519) that lets you create signed tokens for authentication and data exchange. It handles encoding a payload with a secret key and algorithm, then decoding and verifying tokens on the receiving end. The library is widely used in web APIs, microservices, and any system that needs stateless, cryptographically verifiable tokens.
The package depends only on typing_extensions and supports Python 3.9 through 3.14, making it compatible with current Python versions. It has been in production use since 2011, is actively maintained, and carries no known security vulnerabilities.
Use it for
- Implement token-based authentication in REST APIs where clients receive a token after login and include it in subsequent requests.
- Build microservices that verify tokens issued by a central auth service without querying a database on every request.
- Create secure session tokens for single-page applications that need to avoid server-side session storage.
- Exchange claims between services in a distributed system where each service can independently verify token signatures.
- Support OAuth 2.0 or OpenID Connect flows that rely on tokens for access and identity verification.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
PyJWT is a mature, actively maintained library with no known vulnerabilities, low install friction, and permissive licensing. It is the standard choice for token handling in Python and is appropriate for any project requiring token-based authentication or secure token exchange.
Install
pyjwt on PyPI
Before you install
Installation is straightforward with low friction—a pure-Python wheel with only typing_extensions as a runtime dependency. The project is actively maintained with a recent release and 5680 repository stars, indicating stable, well-established code.
Requires Python 3.9 or later.
License in practice
MIT license permits free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and commercial projects.
Quickstart
pip install PyJWT
encoded = PyJWT.encode({"some": "payload"}, "secret", algorithm="HS256")
decoded = PyJWT.decode(encoded, "secret", algorithms=["HS256"])
Verify before relying
- Whether the package supports additional cryptographic algorithms beyond HS256 or if those require optional dependencies.
- Whether typing_extensions is required at runtime or only for type hints on older Python versions.
- What specific algorithms and signing methods are supported by the library.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagetyping_extensions |
| Maintenance | Actively maintained 85 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 715,697,201 / month, #44 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersNatural Language :: EnglishProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: Utilities |
Evidence: pyjwt-2.13.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “rfc 7519 implementation”
- PyJWTPyJWT encodes and decodes JSON Web Tokens (JWT) according to RFC…
- tonyg-rfc3339Parses and formats RFC 3339 date-time strings according to the…
- uuidProvides UUID object creation and RFC 4122-compliant unique…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also joserfc · pyjwt-key-fetcher · python-jwt · jwt · python-jose · scitokens · pyjwkest · jwskate · standardwebhooks · djangorestframework-jwt