$npx skillfedfor your agent

python-jwt

Module for generating and verifying JSON Web Tokens

SkipPyPI CryptographyReleased Nov 2023374.0K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — python_jwt-4.1.0-py2.py3-none-any.whl
v4.1.0 · released 2023-11-13 · Python >=3.6 · 1 runtime deps: jwcrypto

No. While the package is functionally complete and has low install friction, it is abandoned and no longer maintained. The maintainer explicitly states they lack time to maintain it, the repository is archived, and no updates have been released since November 2023. For new projects, use an actively maintained JWT library instead. For existing projects already using python-jwt, consider migrating to an alternative that receives security updates and bug fixes.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.6 or later.
  • Low install friction with a single runtime dependency.
  • However, the package is abandoned and has not been maintained since November 2023; the repository is archived and the maintainer explicitly states they lack time to maintain it.

License · maintenance · safety

MIT (permissive) — MIT license is permissive and places no restrictions on use, modification, or distribution in commercial or private projects.

last release 2023-11-13 (1005 days) · last repo commit 2023-11-13 · 222 stars · archived

0 known vulnerabilities (OSV.dev, 2026-08-14) · 373,971 downloads/mo, #7,152 on PyPI

Verify before relying

pip install python_jwt

import python_jwt as jwt
import jwcrypto.jwk as jwk
import datetime

key = jwk.JWK.generate(kty='RSA', size=2048)
payload = {'foo': 'bar'}
token = jwt.generate_jwt(payload, key, 'RS256', datetime.timedelta(minutes=5))
header, claims = jwt.verify_jwt(token, key, ['RS256'])
  • Whether the abandoned status and lack of maintenance since November 2023 poses a risk for new projects or production use.
  • Current status of the CVE-2022-39227 vulnerability fix in version 4.1.0 and whether any newer issues have emerged post-abandonment.
Same gist for agents: .md · .json

What it is and what it does

python-jwt is a module for creating and validating JSON Web Tokens, wrapping the cryptographic primitives provided by jwcrypto. It supports multiple signature algorithms including RS256, RS384, RS512, PS256, PS384, PS512, HS256, HS384, HS512, ES256, ES384, ES512, ES256K, and EdDSA. The package provides two main functions: generate_jwt to create signed tokens with a payload and expiration, and verify_jwt to validate a token's signature and extract its claims.

The package is now abandoned; the maintainer has stated they lack time to maintain it. The repository is archived and the last release was in November 2023. While the codebase has been tested for interoperability and includes unit tests, no active development or security updates are expected. Users considering this package should be aware that it will not receive bug fixes or security patches going forward.

Use it for

  • Generate and verify JWTs for stateless authentication in REST APIs or microservices.
  • Implement token-based authorization where claims are embedded in the token itself.
  • Interoperate with systems that use standard JWT algorithms like RS256 or HS256.
  • Export and import cryptographic keys in PEM format for integration with external systems.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No.

While the package is functionally complete and has low install friction, it is abandoned and no longer maintained. The maintainer explicitly states they lack time to maintain it, the repository is archived, and no updates have been released since November 2023. For new projects, use an actively maintained JWT library instead. For existing projects already using python-jwt, consider migrating to an alternative that receives security updates and bug fixes.

Install

python-jwt on PyPI

Before you install

Low install friction with a single runtime dependency. However, the package is abandoned and has not been maintained since November 2023; the repository is archived and the maintainer explicitly states they lack time to maintain it.

Requires Python 3.6 or later.

License in practice

MIT license is permissive and places no restrictions on use, modification, or distribution in commercial or private projects.

Quickstart

pip install python_jwt

import python_jwt as jwt
import jwcrypto.jwk as jwk
import datetime

key = jwk.JWK.generate(kty='RSA', size=2048)
payload = {'foo': 'bar'}
token = jwt.generate_jwt(payload, key, 'RS256', datetime.timedelta(minutes=5))
header, claims = jwt.verify_jwt(token, key, ['RS256'])

Verify before relying

  • Whether the abandoned status and lack of maintenance since November 2023 poses a risk for new projects or production use.
  • Current status of the CVE-2022-39227 vulnerability fix in version 4.1.0 and whether any newer issues have emerged post-abandonment.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.6
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
jwcrypto
MaintenanceAbandoned 1,005 days since the last release
Last repo commit repository archived
First released
Downloads373,971 / month, #7,152 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Programming Language :: Python :: 3Programming Language :: Python :: Implementation :: CPython

Evidence: python_jwt-4.1.0-py2.py3-none-any.whl

Tags

Capabilities
jwt generation verificationjson web token libraryjwt signing verificationtoken authenticationjwt with rsa ecdsa hmac
Topics
jwtauthenticationabandoned

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “jwt generation verification”

  • python-jwtGenerates and verifies JSON Web Tokens (JWTs) using a variety of…
  • vonage-jwtGenerates and verifies JWTs for Vonage API authentication in Python,…
  • atlassian-jwt-authGenerates and verifies JWT tokens for Atlassian Service to Service…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also jwt · myjwt · scitokens · PyJWT · jose · vonage-jwt · okta-jwt-verifier · jwskate · python-jose · paytmchecksum