requests-auth
Authentication for Requests
Decision gist · record as of 2026-08-14
Yes. The package is stable, permissively licensed, has low install friction, and solves a common problem—integrating multiple authentication schemes with requests. Dormant maintenance is not a blocker for a feature-complete auth library, but verify that your target OAuth2 provider and requests version are compatible before relying on it for new projects.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with a single dependency on requests.
- Maintenance is dormant—no releases since June 2024—but the package is marked Production/Stable and the repository remains active, suggesting it is feature-complete rather than abandoned.
License · maintenance · safety
permissive license (permissive) — MIT License permits free use, modification, and distribution with minimal restrictions, making it safe for commercial and open-source projects.
last release 2024-06-18 (787 days) · last repo commit 2024-06-18 · 39 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 241,208 downloads/mo, #8,883 on PyPI
Alternatives
Verify before relying
import requests
from requests_auth import OAuth2AuthorizationCode
auth = OAuth2AuthorizationCode('https://www.authorization.url', 'https://www.token.url')
requests.get('https://www.example.com', auth=auth)- Whether token cache persistence works reliably across different operating systems and Python versions.
- Current compatibility with the latest versions of requests and modern OAuth2 provider implementations.
- Performance characteristics when handling high-frequency token refresh scenarios.
What it is and what it does
requests-auth is a Python library that extends the requests HTTP library with pluggable authentication handlers for OAuth2, API keys, Basic auth, and NTLM. It wraps these authentication schemes into classes that integrate directly with requests' auth parameter, eliminating the need to manually construct headers or manage token lifecycles.
The package supports multiple OAuth2 flows (Authorization Code, PKCE, Client Credentials, Resource Owner Password, Implicit) with built-in support for identity providers like Okta and Microsoft Entra. It handles token caching, automatic refresh, and early expiry detection to prevent token timeouts mid-request. You pass an authentication instance to requests.get() or any other HTTP method, and the library manages credential exchange and header injection transparently.
Use it for
- Authenticate requests to Okta or Microsoft Entra protected APIs using OAuth2 Authorization Code flow with automatic token refresh.
- Add API key authentication to requests by specifying header or query parameter placement without manual header construction.
- Implement NTLM authentication for Windows-integrated services and corporate proxies.
- Combine multiple authentication schemes in a single request.
- Cache and reuse OAuth2 tokens across multiple requests to reduce authentication overhead.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is stable, permissively licensed, has low install friction, and solves a common problem—integrating multiple authentication schemes with requests. Dormant maintenance is not a blocker for a feature-complete auth library, but verify that your target OAuth2 provider and requests version are compatible before relying on it for new projects.
Install
requests-auth on PyPI
Before you install
Low install friction with a single dependency on requests. Maintenance is dormant—no releases since June 2024—but the package is marked Production/Stable and the repository remains active, suggesting it is feature-complete rather than abandoned.
License in practice
MIT License permits free use, modification, and distribution with minimal restrictions, making it safe for commercial and open-source projects.
Quickstart
import requests
from requests_auth import OAuth2AuthorizationCode
auth = OAuth2AuthorizationCode('https://www.authorization.url', 'https://www.token.url')
requests.get('https://www.example.com', auth=auth)
Verify before relying
- Whether token cache persistence works reliably across different operating systems and Python versions.
- Current compatibility with the latest versions of requests and modern OAuth2 provider implementations.
- Performance characteristics when handling high-frequency token refresh scenarios.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagerequests |
| Maintenance | Dormant 787 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 241,208 / month, #8,883 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software Development :: Build Tools |
Evidence: requests_auth-8.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “oauth2 authentication requests”
- requests-authAdds OAuth2, API key, Basic, and NTLM authentication support to the…
- httpx-authProvides authentication classes for httpx HTTP client requests,…
- requests-oauth2clientAn OAuth 2.x client for Python that obtains, refreshes, and revokes…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also httpx-auth · requests-oauthlib · okta · requests-oauth · oauth2-client · mohawk · stups-tokens · requests-oauth2client · django-oauth-toolkit · plexauth