$npx skillfedfor your agent

scitokens

SciToken reference implementation library

Worth itPyPI Scientific/EngineeringReleased Mar 202695.8K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — scitokens-1.9.7-py3-none-any.whl
v1.9.7 · released 2026-03-13 · Python >=3.5 · 3 runtime deps: cryptography, PyJWT, requests

Yes. The package is actively maintained, has no known vulnerabilities, low install friction, and a permissive license. It is the reference implementation for SciTokens, making it the natural choice if you need to work with this token format in scientific computing environments. Install it if you are building or integrating with systems that use SciTokens for authorization.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low friction installation with three stable runtime dependencies (cryptography, PyJWT, requests).
  • Actively maintained with recent commits and no known vulnerabilities.

License · maintenance · safety

Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing use in commercial and private projects with minimal restrictions beyond attribution.

last release 2026-03-13 (154 days) · last repo commit 2026-04-21 · 7 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 95,770 downloads/mo, #13,250 on PyPI

Verify before relying

import scitokens

# Generate a new token
token = scitokens.SciToken()
token['read'] = '/ligo'
serialized = token.serialize()

# Deserialize and validate
token = scitokens.SciToken.deserialize(serialized)
val = scitokens.Validator()
val.add_validator('read', lambda v: v.startswith('/'))
val.validate(token)
  • Whether the demo token generator endpoint (demo.scitokens.org) is reliably available for production use
  • Performance characteristics when validating large numbers of tokens concurrently
  • Compatibility with Python versions beyond 3.10 (classifiers list 3.5–3.10 but current support is unclear)
Same gist for agents: .md · .json

What it is and what it does

SciTokens is a reference implementation library for the SciTokens JWT token format, designed to provide a high-level, safe interface for creating and validating authorization tokens in scientific computing workflows. It wraps PyJWT and cryptography to handle the low-level details of token signing, serialization, and verification, letting you focus on defining authorization claims and validation logic.

The library separates token verification (checking cryptographic integrity and authenticity) from validation (checking whether claims satisfy your authorization requirements). You can generate tokens with arbitrary claims, serialize them to a standard JWT format, deserialize and verify tokens from external sources, and use the Enforcer class to test whether a token grants specific permissions—such as read/write access to particular file paths. It also includes utilities for creating demo tokens and a Flask decorator for protecting endpoints.

Use it for

  • Generate and sign authorization tokens in an OAuth2 workflow for scientific computing infrastructure
  • Validate incoming tokens at a storage or compute service to enforce access control policies
  • Test token-based authorization logic in development using the demo token generator
  • Enforce path-based access control (e.g., read/write permissions on specific directories) using the Enforcer class
  • Protect Flask endpoints with token-based authentication and scope validation

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The package is actively maintained, has no known vulnerabilities, low install friction, and a permissive license. It is the reference implementation for SciTokens, making it the natural choice if you need to work with this token format in scientific computing environments. Install it if you are building or integrating with systems that use SciTokens for authorization.

Install

scitokens on PyPI

Before you install

Low friction installation with three stable runtime dependencies (cryptography, PyJWT, requests). Actively maintained with recent commits and no known vulnerabilities.

License in practice

Licensed under Apache-2.0 (permissive), allowing use in commercial and private projects with minimal restrictions beyond attribution.

Quickstart

import scitokens

# Generate a new token
token = scitokens.SciToken()
token['read'] = '/ligo'
serialized = token.serialize()

# Deserialize and validate
token = scitokens.SciToken.deserialize(serialized)
val = scitokens.Validator()
val.add_validator('read', lambda v: v.startswith('/'))
val.validate(token)

Verify before relying

  • Whether the demo token generator endpoint (demo.scitokens.org) is reliably available for production use
  • Performance characteristics when validating large numbers of tokens concurrently
  • Compatibility with Python versions beyond 3.10 (classifiers list 3.5–3.10 but current support is unclear)

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.5
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
cryptographyPyJWTrequests
MaintenanceActively maintained 154 days since the last release
Last repo commit
First released
Downloads95,770 / month, #13,250 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableLicense :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Scientific/Engineering

Evidence: scitokens-1.9.7-py3-none-any.whl

Tags

Capabilities
JWT token librarySciTokens implementationauthorization token validationscientific computing tokenstoken-based access controlcryptographic token signingOAuth2 token handling
Topics
jwt-tokensscientific-computingaccess-control

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “SciTokens implementation”

  • scitokensImplements the SciTokens JSON Web Token (JWT) format for generating,…
  • igwn-auth-utilsDiscovers and deserializes X.509 credentials and SciTokens for…
  • py3rijndaelpy3rijndael provides a pure-Python implementation of the Rijndael…

Give your agent the search over MCP, or paste the wish link into any chat.

More Scientific/Engineering packages

numpy Worth it
PyPI · Software Development · released Aug 2026

NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.

BSD-3-Clause AND 0BSD AND MIT AND Zlib AND CC0-1.0compiled wheel · 3.12+
1.1Bdownloads / mo
pandas Worth it
PyPI · Scientific/Engineering · released Jul 2026

pandas provides fast, flexible data structures (Series and DataFrame) for loading, cleaning, transforming, and analyzing labeled or relational data in Python.

BSD-3-Clausecompiled wheel · 3.11+
769.1Mdownloads / mo
scipy Worth it
PyPI · Libraries · released Jun 2026

scipy provides numerical algorithms for mathematics, science, and engineering—including optimization, integration, linear algebra, Fourier transforms, signal and image processing, and ODE solvers—built on numpy arrays.

BSD-3-Clausecompiled wheel · 3.12+
449.0Mdownloads / mo
scikit-learn Worth it
PyPI · Software Development · released Jun 2026

scikit-learn provides a comprehensive Python library for supervised and unsupervised machine learning, including classification, regression, clustering, dimensionality reduction, and model evaluation tools built on NumPy and SciPy.

Install it if you need to train, evaluate, or deploy supervised or unsupervised learning models.

BSD-3-Clausecompiled wheel · 3.11+
235.5Mdownloads / mo
dill Worth it
PyPI · Software Development · released Jan 2026

dill extends Python's pickle module to serialize and deserialize a much wider range of Python objects, including functions, lambdas, classes, and interpreter sessions, to byte streams for storage or network transmission.

BSD-3-Clausepure Python · 3.9+
208.1Mdownloads / mo
multiprocess Worth it
PyPI · Software Development · released Jan 2026

Multiprocess is an enhanced fork of Python's standard multiprocessing library that uses dill for better serialization, allowing you to spawn processes with a threading-like API and share complex objects between them.

Install it if you use multiprocessing and encounter pickle serialization limits with lambdas or complex objects.

BSD-3-Clausepure Python · 3.9+
202.7Mdownloads / mo

See also igwn-auth-utils · jose · python-jwt · jwskate · PyJWT · axioms-fastapi · python-jose · okta-jwt-verifier · atlassian-jwt-auth · Authlib