requests-oauthlib
OAuthlib authentication support for Requests.
Decision gist · record as of 2026-08-14
Yes, with conditions. The package is production-stable with no known vulnerabilities and permissive licensing. However, the 875-day gap since the last release (v2.0.0 in March 2024) signals aging maintenance. Install it if you need OAuth support for Requests and can tolerate infrequent updates; monitor the repository for security patches. For new projects, verify that v2.0.0's features meet your requirements.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with only two runtime dependencies (oauthlib and requests).
- Maintenance status is aging—last release was 875 days ago (March 2024)—but the repository remains active with a recent commit in June 2025 and no archived status, suggesting continued stewardship despite infrequent releases.
License · maintenance · safety
ISC (permissive) — Licensed under ISC (permissive), which allows free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and proprietary projects.
last release 2024-03-22 (875 days) · last repo commit 2025-06-18 · 1,775 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 369,796,716 downloads/mo, #113 on PyPI
Alternatives
Verify before relying
pip install requests-oauthlib
from requests_oauthlib import OAuth1Session
twitter = OAuth1Session('client_key',
client_secret='client_secret',
resource_owner_key='resource_owner_key',
resource_owner_secret='resource_owner_secret')
r = twitter.get('https://api.twitter.com/1/account/settings.json')- Whether OAuth 2 PKCE support (mentioned in v2.0.0 changelog) is production-ready or still experimental.
- Current compatibility status with oauthlib versions beyond the dependency specification.
- Performance characteristics when handling token refresh under high concurrency.
What it is and what it does
Requests-OAuthlib bridges the Requests HTTP library and the oauthlib library to provide first-class OAuth authentication. It abstracts away the complexity of OAuth 1 and OAuth 2 workflows, letting you create authenticated sessions that handle credential management and token lifecycle automatically. The package provides OAuth1Session and OAuth2Session classes that extend Requests' Session with OAuth-aware request methods, so you can call .get(), .post(), etc. on protected APIs without manually managing signatures or token headers.
The library handles both the authorization flow (obtaining credentials from providers) and the resource access phase (using those credentials to fetch protected data). It includes compliance fixes for various OAuth providers and supports modern Python versions. Since v2.0.0, it includes PKCE support for OAuth 2 and has dropped Python 2 support entirely.
Use it for
- Authenticate with Twitter API v1 or other OAuth 1 providers to fetch user timelines or post on behalf of authorized users.
- Integrate OAuth 2 login into a web application to fetch user profile data after authorization.
- Build a service that refreshes OAuth 2 access tokens automatically when they expire, without manual intervention.
- Implement OAuth 2 Authorization Code Grant flow for third-party integrations with various providers.
- Use PKCE-protected OAuth 2 flow in mobile or desktop applications where client secrets cannot be safely stored.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
The package is production-stable with no known vulnerabilities and permissive licensing. However, the 875-day gap since the last release (v2.0.0 in March 2024) signals aging maintenance. Install it if you need OAuth support for Requests and can tolerate infrequent updates; monitor the repository for security patches. For new projects, verify that v2.0.0's features meet your requirements.
Install
requests-oauthlib on PyPI
Before you install
Low install friction with only two runtime dependencies (oauthlib and requests). Maintenance status is aging—last release was 875 days ago (March 2024)—but the repository remains active with a recent commit in June 2025 and no archived status, suggesting continued stewardship despite infrequent releases.
License in practice
Licensed under ISC (permissive), which allows free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and proprietary projects.
Quickstart
pip install requests-oauthlib
from requests_oauthlib import OAuth1Session
twitter = OAuth1Session('client_key',
client_secret='client_secret',
resource_owner_key='resource_owner_key',
resource_owner_secret='resource_owner_secret')
r = twitter.get('https://api.twitter.com/1/account/settings.json')
Verify before relying
- Whether OAuth 2 PKCE support (mentioned in v2.0.0 changelog) is production-ready or still experimental.
- Current compatibility status with oauthlib versions beyond the dependency specification.
- Performance characteristics when handling token refresh under high concurrency.
Package facts
| License | ISC permissive |
| Python support | Supports the current Python release >=3.4 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesoauthlibrequests |
| Maintenance | Aging 875 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 369,796,716 / month, #113 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseNatural Language :: EnglishProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy |
Evidence: requests_oauthlib-2.0.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “oauth1 oauth2 http client”
- requests-oauthlibAdds OAuth 1 and OAuth 2 authentication support to the Requests HTTP…
- garthGarth provides Python access to Garmin Connect data via OAuth…
- httpx-authProvides authentication classes for httpx HTTP client requests,…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also django-oauth-toolkit · oauthlib · ovh · python-upwork-oauth2 · requests-auth · PyCronofy · Flask-OAuthlib · oauth2-client · requests-oauth2client · Authlib