$npx skillfedfor your agent

repoze.who

repoze.who is an identification and authentication framework for WSGI.

With conditionsPyPI WWW/HTTPReleased Feb 2025167.4K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — repoze.who-3.1.0-py3-none-any.whl
v3.1.0 · released 2025-02-22 · Python >=3.9 · 4 runtime deps: WebOb, zope.interface, setuptools, legacy-cgi

Yes, if you are building or maintaining a WSGI application that needs pluggable authentication and you accept infrequent updates. The package is stable, has no known vulnerabilities, and supports modern Python versions. It is not suitable if you need active development, frequent security patches, or integration with modern async frameworks (it is WSGI-only, not ASGI).AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or higher; on Python 3.13 or higher, legacy-cgi must be installed for WebOb compatibility.
  • Low install friction with a pure-Python wheel.
  • Maintenance status is aging—last release was 538 days ago—but the package is marked Production/Stable and supports current Python versions (3.9–3.13).

License · maintenance · safety

permissive license (permissive) — BSD-derived permissive license allows use in most commercial and open-source projects with minimal restrictions; consult the license text at http://www.repoze.org/LICENSE.txt for exact terms.

last release 2025-02-22 (538 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 167,409 downloads/mo, #10,471 on PyPI

Verify before relying

pip install repoze.who

from repoze.who.middleware import IdentificationMiddleware
from repoze.who.plugins.auth_tkt import AuthTktCookiePlugin

plugin = AuthTktCookiePlugin(secret='my-secret')
app_with_auth = IdentificationMiddleware(app, [plugin])
  • Whether the aging maintenance status (538 days since last release) affects real-world compatibility with recent WSGI frameworks or if the package is stable-by-design.
  • Whether the four runtime dependencies introduce any transitive security or compatibility concerns beyond what the fact sheet shows.
Same gist for agents: .md · .json

What it is and what it does

repoze.who is a WSGI-based identification and authentication framework inspired by Zope's Pluggable Authentication Service. It sits between your web application and the WSGI server, extracting user identity from requests and managing login/logout flows through pluggable components. The framework handles the 'who are you' question but deliberately leaves authorization (what users can do) to your application.

You can deploy it as WSGI middleware wrapping your application or use its API directly within your code. It depends on WebOb for HTTP request/response handling and zope.interface for plugin contracts. On Python 3.13 or higher, legacy-cgi is required so WebOb works. The package supports Python 3.9 through 3.13 and has been stable since its early releases, though updates are infrequent.

Use it for

  • Add authentication to a legacy or custom WSGI application without rewriting the entire auth layer.
  • Integrate multiple authentication methods (cookies, form-based, htpasswd files) into a single WSGI middleware stack.
  • Delegate user identification to repoze.who middleware while your application focuses solely on authorization and business logic.
  • Migrate authentication from Zope 2's PAS to a standalone WSGI framework that works with any WSGI-compatible web stack.
  • Build a multi-tenant WSGI application where different auth plugins handle different user populations.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are building or maintaining a WSGI application that needs pluggable authentication and you accept infrequent updates.

The package is stable, has no known vulnerabilities, and supports modern Python versions. It is not suitable if you need active development, frequent security patches, or integration with modern async frameworks (it is WSGI-only, not ASGI).

Install

repoze-who on PyPI

Before you install

Low install friction with a pure-Python wheel. Maintenance status is aging—last release was 538 days ago—but the package is marked Production/Stable and supports current Python versions (3.9–3.13). No known vulnerabilities.

Requires Python 3.9 or higher; on Python 3.13 or higher, legacy-cgi must be installed for WebOb compatibility.

License in practice

BSD-derived permissive license allows use in most commercial and open-source projects with minimal restrictions; consult the license text at http://www.repoze.org/LICENSE.txt for exact terms.

Quickstart

pip install repoze.who

from repoze.who.middleware import IdentificationMiddleware
from repoze.who.plugins.auth_tkt import AuthTktCookiePlugin

plugin = AuthTktCookiePlugin(secret='my-secret')
app_with_auth = IdentificationMiddleware(app, [plugin])

Verify before relying

  • Whether the aging maintenance status (538 days since last release) affects real-world compatibility with recent WSGI frameworks or if the package is stable-by-design.
  • Whether the four runtime dependencies introduce any transitive security or compatibility concerns beyond what the fact sheet shows.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
WebObzope.interfacesetuptoolslegacy-cgi
MaintenanceAging 538 days since the last release
First released
Downloads167,409 / month, #10,471 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Internet :: WWW/HTTPTopic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Internet :: WWW/HTTP :: WSGITopic :: Internet :: WWW/HTTP :: WSGI :: Application

Evidence: repoze.who-3.1.0-py3-none-any.whl

Tags

Capabilities
wsgi authentication middlewareuser identification frameworkpluggable authentication servicewsgi identity managementweb application authenticationrepoze authenticationwsgi user login
Topics
wsgi-middlewareauthenticationlegacy-framework
PyPI keywords
webapplicationserverwsgizope

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “wsgi authentication middleware”

  • repoze.whorepoze.who is an identification and authentication framework for WSGI…
  • PastePaste provides WSGI middleware components for building web…
  • keystonemiddlewareProvides authentication and authorization middleware for OpenStack…

Give your agent the search over MCP, or paste the wish link into any chat.

More WWW/HTTP packages

urllib3 Worth it
PyPI · Libraries · released May 2026

urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.

MITpure Python · 3.10+
1.8Bdownloads / mo
requests Worth it
PyPI · Libraries · released May 2026

Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.

Apache-2.0pure Python · 3.10+
1.8Bdownloads / mo
h11 With conditions
PyPI · WWW/HTTP · released Apr 2025

h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.

MITpure Python · 3.8+aging
894.9Mdownloads / mo
httpx Worth it
PyPI · WWW/HTTP · released Dec 2024

HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.

Install it if you are building new projects or modernizing existing ones that rely on HTTP.

BSD-3-Clausepure Python · 3.8+
797.0Mdownloads / mo
httpcore With conditions
PyPI · WWW/HTTP · released Apr 2025

A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.

BSD-3-Clausepure Python · 3.8+aging
783.6Mdownloads / mo
aiohttp Worth it
PyPI · WWW/HTTP · released Jul 2026

aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.

Install it if you need async HTTP client or server capabilities in asyncio-based applications.

permissive licensecompiled wheel · 3.10+
643.6Mdownloads / mo

See also repoze-lru · repoze-sendmail · Beaker · keystonemiddleware · WebOb · tool · Paste · wsgiref · wsgidav · quart-auth