streamlit-authenticator
A secure authentication module to manage user access in a Streamlit application.
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has no known vulnerabilities, installs with low friction, and solves a common need for Streamlit developers. The permissive MIT license removes licensing concerns. Install it if you're building a multi-user Streamlit app that requires authentication; the alternative is implementing security infrastructure yourself.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a configuration file with user credentials, cookie settings, and optional OAuth2 parameters; plain-text passwords are hashed automatically on first run.
- Low install friction with a pure-Python wheel distribution.
- Actively maintained with recent commits and 2086 repository stars, indicating solid community adoption and ongoing support.
License · maintenance · safety
permissive license (permissive) — Licensed under MIT (permissive), allowing free use, modification, and distribution in both open-source and commercial projects with minimal restrictions.
last release 2025-03-01 (531 days) · last repo commit 2026-07-01 · 2,086 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 252,671 downloads/mo, #8,539 on PyPI
Alternatives
Verify before relying
pip install streamlit-authenticator
import streamlit as st
import streamlit_authenticator as stauth
authenticator = stauth.Authenticate(
config['credentials'],
config['cookie']['name'],
config['cookie']['key'],
config['cookie']['expiry_days']
)
authenticator.login()- Whether the package handles session state persistence correctly across Streamlit reruns in all deployment scenarios
- Performance characteristics when managing large numbers of concurrent users
- Specifics of the optional API key requirement for email-based password reset and two-factor authentication features
What it is and what it does
Streamlit-Authenticator is a Python module that adds secure user authentication to Streamlit web applications. It manages credentials through a configuration file, handles password hashing with bcrypt, and provides widgets for login, registration, password reset, and account management. The package integrates with Streamlit's session state to maintain authentication across page reloads and supports optional OAuth2 authentication via Google and Microsoft.
The module depends on bcrypt for password hashing, cryptography for secure token handling, PyJWT for token generation, PyYAML for configuration parsing, and extra-streamlit-components for UI elements. It also includes optional captcha support and can send authentication codes via email when configured with an API key. The package is designed for developers building multi-user Streamlit applications who need standard authentication flows without building security infrastructure from scratch.
Use it for
- Protect a Streamlit dashboard with username/password login to restrict access to authorized users only
- Allow new users to self-register through a registration widget while restricting signups to pre-authorized email addresses
- Implement password reset and account recovery flows for users who forget their credentials
- Add two-factor authentication via email for applications handling sensitive data or operations
- Enable single sign-on through Google or Microsoft OAuth2 for enterprise Streamlit deployments
- Manage user roles and permissions to control which features different users can access within the app
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has no known vulnerabilities, installs with low friction, and solves a common need for Streamlit developers. The permissive MIT license removes licensing concerns. Install it if you're building a multi-user Streamlit app that requires authentication; the alternative is implementing security infrastructure yourself.
Install
streamlit-authenticator on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Actively maintained with recent commits and 2086 repository stars, indicating solid community adoption and ongoing support.
Requires a configuration file with user credentials, cookie settings, and optional OAuth2 parameters; plain-text passwords are hashed automatically on first run.
License in practice
Licensed under MIT (permissive), allowing free use, modification, and distribution in both open-source and commercial projects with minimal restrictions.
Quickstart
pip install streamlit-authenticator
import streamlit as st
import streamlit_authenticator as stauth
authenticator = stauth.Authenticate(
config['credentials'],
config['cookie']['name'],
config['cookie']['key'],
config['cookie']['expiry_days']
)
authenticator.login()
Verify before relying
- Whether the package handles session state persistence correctly across Streamlit reruns in all deployment scenarios
- Performance characteristics when managing large numbers of concurrent users
- Specifics of the optional API key requirement for email-based password reset and two-factor authentication features
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 7 packagesbcryptcaptchacryptographyextra-streamlit-componentsPyJWTPyYAMLstreamlit |
| Maintenance | Actively maintained 531 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 252,671 / month, #8,539 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3 |
Evidence: streamlit_authenticator-0.4.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “streamlit user authentication”
- streamlit-authenticatorAdds user authentication and access control to Streamlit…
- streamlit-msalAdds Microsoft Authentication Library (MSAL) integration to Streamlit…
- streamlit-cookies-controllerProvides read, write, and delete operations on browser cookies from a…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also oauthenticator · streamlit-cookies-controller · fastapi-users · streamlit-msal · oauth2-client · django-google-sso · fastapi-auth0 · quart-auth · streamlit-vertical-slider · fastapi-login