$npx skillfedfor your agent

pyjwt-key-fetcher

Async library to fetch JWKs for JWT tokens

With conditionsPyPI CryptographyReleased Aug 2024447.6K downloads / moBSD-3-ClausePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pyjwt_key_fetcher-0.8.0-py3-none-any.whl
v0.8.0 · released 2024-08-07 · Python <4.0,>=3.8 · 4 runtime deps: PyJWT, aiohttp, cachetools, aiocache

Yes, if you need async JWT validation against OpenID Connect providers. The library solves a real problem (automatic key discovery and caching) and integrates cleanly with PyJWT. Install friction is low and dependencies are solid. The aging maintenance status (last release 2024-08-07, no recent commits) is a minor concern for a stable utility, but no known vulnerabilities and active repository status mitigate that risk. Suitable for production use in async applications.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.8 or later and an async runtime context (asyncio or similar).
  • Low friction install with a pure-wheel distribution.
  • Maintenance is aging—last release was 2024-08-07 and the repository shows no recent commits, though it remains active and not archived.

License · maintenance · safety

BSD-3-Clause (permissive) — BSD-3-Clause is permissive and places no restrictions on commercial or proprietary use, making it suitable for most projects without license compliance burden.

last release 2024-08-07 (737 days) · last repo commit 2025-11-20 · 17 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 447,590 downloads/mo, #6,605 on PyPI

Verify before relying

pip install pyjwt-key-fetcher

import asyncio
from pyjwt_key_fetcher import AsyncKeyFetcher

async def main():
    fetcher = AsyncKeyFetcher()
    key_entry = await fetcher.get_key(token)

asyncio.run(main())
  • Whether the 5-minute re-fetch interval for new keys is configurable in practice or only via source modification.
  • Performance characteristics when caching across many issuers or under high concurrency.
  • Whether custom HTTP clients can be used with non-standard authentication schemes (mTLS, proxies, etc.).
Same gist for agents: .md · .json

What it is and what it does

pyjwt-key-fetcher is an async wrapper around JWT key verification that automates the process of discovering and fetching signing keys from OpenID Connect providers. Instead of manually managing JWKS endpoints, you pass a token to AsyncKeyFetcher.get_key(), and it extracts the issuer and key ID, fetches the provider's configuration from .well-known/openid-configuration, retrieves the JWKS from the jwks_uri, and returns the matching key for use with PyJWT's decode function.

The library caches configuration and keys by default for up to 32 issuers with a 1-hour TTL, and re-fetches JWKs within 5 minutes if an unknown key ID appears for a known issuer. You can customize cache size, TTL, configuration paths, and provide static issuer configurations for providers that don't expose standard endpoints. It ships with aiohttp-based HTTP fetching but allows custom HTTP client implementations.

Use it for

  • Verify JWTs from multiple OpenID Connect providers in a microservice without hardcoding key endpoints.
  • Build an API gateway that validates tokens from external identity providers with automatic key rotation.
  • Implement token validation in async web frameworks (FastAPI, aiohttp) where blocking I/O is unacceptable.
  • Cache and reuse JWKS across many concurrent requests to reduce latency and provider load.
  • Support custom issuer configurations for non-standard or internal OpenID providers.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need async JWT validation against OpenID Connect providers.

The library solves a real problem (automatic key discovery and caching) and integrates cleanly with PyJWT. Install friction is low and dependencies are solid. The aging maintenance status (last release 2024-08-07, no recent commits) is a minor concern for a stable utility, but no known vulnerabilities and active repository status mitigate that risk. Suitable for production use in async applications.

Install

pyjwt-key-fetcher on PyPI

Before you install

Low friction install with a pure-wheel distribution. Maintenance is aging—last release was 2024-08-07 and the repository shows no recent commits, though it remains active and not archived. Four runtime dependencies (PyJWT, aiohttp, cachetools, aiocache) are all well-established libraries.

Requires Python 3.8 or later and an async runtime context (asyncio or similar).

License in practice

BSD-3-Clause is permissive and places no restrictions on commercial or proprietary use, making it suitable for most projects without license compliance burden.

Quickstart

pip install pyjwt-key-fetcher

import asyncio
from pyjwt_key_fetcher import AsyncKeyFetcher

async def main():
    fetcher = AsyncKeyFetcher()
    key_entry = await fetcher.get_key(token)

asyncio.run(main())

Verify before relying

  • Whether the 5-minute re-fetch interval for new keys is configurable in practice or only via source modification.
  • Performance characteristics when caching across many issuers or under high concurrency.
  • Whether custom HTTP clients can be used with non-standard authentication schemes (mTLS, proxies, etc.).

Package facts

LicenseBSD-3-Clause permissive
Python supportSupports the current Python release <4.0,>=3.8
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
PyJWTaiohttpcachetoolsaiocache
MaintenanceAging 737 days since the last release
Last repo commit
First released
Downloads447,590 / month, #6,605 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: pyjwt_key_fetcher-0.8.0-py3-none-any.whl

Tags

Capabilities
jwt key fetching asyncjwks openid connectjwt verification keyspyjwt key resolverasync jwt validationopenid configuration fetcherjwk caching library
Topics
jwt-validationopenid-connectasync-http

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “jwt key fetching async”

  • pyjwt-key-fetcherAsync library that automatically fetches and caches JSON Web Keys…
  • cognitojwtDecodes and verifies Amazon Cognito JWT tokens in both synchronous…
  • spiffeProvides Python bindings to the SPIFFE Workload API for fetching,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also PyJWT · Authlib · vercel-oidc · spiffe · jwskate · okta-jwt-verifier · cognitojwt · pyop · python-jose · fastapi-cognito