scitokens
SciToken reference implementation library
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has no known vulnerabilities, low install friction, and a permissive license. It is the reference implementation for SciTokens, making it the natural choice if you need to work with this token format in scientific computing environments. Install it if you are building or integrating with systems that use SciTokens for authorization.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction installation with three stable runtime dependencies (cryptography, PyJWT, requests).
- Actively maintained with recent commits and no known vulnerabilities.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing use in commercial and private projects with minimal restrictions beyond attribution.
last release 2026-03-13 (154 days) · last repo commit 2026-04-21 · 7 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 95,770 downloads/mo, #13,250 on PyPI
Alternatives
Verify before relying
import scitokens
# Generate a new token
token = scitokens.SciToken()
token['read'] = '/ligo'
serialized = token.serialize()
# Deserialize and validate
token = scitokens.SciToken.deserialize(serialized)
val = scitokens.Validator()
val.add_validator('read', lambda v: v.startswith('/'))
val.validate(token)- Whether the demo token generator endpoint (demo.scitokens.org) is reliably available for production use
- Performance characteristics when validating large numbers of tokens concurrently
- Compatibility with Python versions beyond 3.10 (classifiers list 3.5–3.10 but current support is unclear)
What it is and what it does
SciTokens is a reference implementation library for the SciTokens JWT token format, designed to provide a high-level, safe interface for creating and validating authorization tokens in scientific computing workflows. It wraps PyJWT and cryptography to handle the low-level details of token signing, serialization, and verification, letting you focus on defining authorization claims and validation logic.
The library separates token verification (checking cryptographic integrity and authenticity) from validation (checking whether claims satisfy your authorization requirements). You can generate tokens with arbitrary claims, serialize them to a standard JWT format, deserialize and verify tokens from external sources, and use the Enforcer class to test whether a token grants specific permissions—such as read/write access to particular file paths. It also includes utilities for creating demo tokens and a Flask decorator for protecting endpoints.
Use it for
- Generate and sign authorization tokens in an OAuth2 workflow for scientific computing infrastructure
- Validate incoming tokens at a storage or compute service to enforce access control policies
- Test token-based authorization logic in development using the demo token generator
- Enforce path-based access control (e.g., read/write permissions on specific directories) using the Enforcer class
- Protect Flask endpoints with token-based authentication and scope validation
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has no known vulnerabilities, low install friction, and a permissive license. It is the reference implementation for SciTokens, making it the natural choice if you need to work with this token format in scientific computing environments. Install it if you are building or integrating with systems that use SciTokens for authorization.
Install
scitokens on PyPI
Before you install
Low friction installation with three stable runtime dependencies (cryptography, PyJWT, requests). Actively maintained with recent commits and no known vulnerabilities.
License in practice
Licensed under Apache-2.0 (permissive), allowing use in commercial and private projects with minimal restrictions beyond attribution.
Quickstart
import scitokens
# Generate a new token
token = scitokens.SciToken()
token['read'] = '/ligo'
serialized = token.serialize()
# Deserialize and validate
token = scitokens.SciToken.deserialize(serialized)
val = scitokens.Validator()
val.add_validator('read', lambda v: v.startswith('/'))
val.validate(token)
Verify before relying
- Whether the demo token generator endpoint (demo.scitokens.org) is reliably available for production use
- Performance characteristics when validating large numbers of tokens concurrently
- Compatibility with Python versions beyond 3.10 (classifiers list 3.5–3.10 but current support is unclear)
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.5 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagescryptographyPyJWTrequests |
| Maintenance | Actively maintained 154 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 95,770 / month, #13,250 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableLicense :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Scientific/Engineering |
Evidence: scitokens-1.9.7-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “SciTokens implementation”
- scitokensImplements the SciTokens JSON Web Token (JWT) format for generating,…
- igwn-auth-utilsDiscovers and deserializes X.509 credentials and SciTokens for…
- py3rijndaelpy3rijndael provides a pure-Python implementation of the Rijndael…
Give your agent the search over MCP, or paste the wish link into any chat.
More Scientific/Engineering packages
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
pandas provides fast, flexible data structures (Series and DataFrame) for loading, cleaning, transforming, and analyzing labeled or relational data in Python.
scipy provides numerical algorithms for mathematics, science, and engineering—including optimization, integration, linear algebra, Fourier transforms, signal and image processing, and ODE solvers—built on numpy arrays.
scikit-learn provides a comprehensive Python library for supervised and unsupervised machine learning, including classification, regression, clustering, dimensionality reduction, and model evaluation tools built on NumPy and SciPy.
Install it if you need to train, evaluate, or deploy supervised or unsupervised learning models.
dill extends Python's pickle module to serialize and deserialize a much wider range of Python objects, including functions, lambdas, classes, and interpreter sessions, to byte streams for storage or network transmission.
Multiprocess is an enhanced fork of Python's standard multiprocessing library that uses dill for better serialization, allowing you to spawn processes with a threading-like API and share complex objects between them.
Install it if you use multiprocessing and encounter pickle serialization limits with lambdas or complex objects.
See also igwn-auth-utils · jose · python-jwt · jwskate · PyJWT · axioms-fastapi · python-jose · okta-jwt-verifier · atlassian-jwt-auth · Authlib