stups-tokens
Python library to manage OAuth access tokens
Decision gist · record as of 2026-08-14
No, unless maintaining legacy Python 2.7 or 3.4–3.5 code. The package is abandoned (last release 2017-01-04, last commit 2019-03-19) and targets end-of-life Python versions. For new projects, use a modern OAuth library or your framework's built-in token handling. For existing deployments, evaluate whether migration is feasible.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires OAUTH2_ACCESS_TOKEN_URL environment variable or explicit url parameter; CREDENTIALS_DIR may be needed depending on configuration mode.
- Low install friction with no runtime dependencies.
- However, the package is abandoned—last release was 2017-01-04 and last commit 2019-03-19.
License · maintenance · safety
Apache License Version 2.0 (permissive) — Licensed under Apache License Version 2.0 (permissive), allowing commercial and private use with minimal restrictions.
last release 2017-01-04 (3509 days) · last repo commit 2019-03-19 · 14 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 144,229 downloads/mo, #11,158 on PyPI
Alternatives
Verify before relying
import tokens
tokens.configure(url='https://example.com/access_tokens')
tokens.manage('example', ['read', 'write'])
tokens.start()
token = tokens.get('example')- Compatibility with modern Python versions beyond the declared 2.7, 3.4, and 3.5 support.
- Whether the package works with current OAuth 2.0 provider implementations and token endpoint changes since 2017.
- Active maintenance or security updates for production use.
What it is and what it does
stups-tokens is a Python library for managing OAuth 2.0 access tokens, keeping them in memory and automatically refreshing them when they expire. It abstracts away token lifecycle management—you configure it with an OAuth endpoint and token scopes, then call tokens.get() to retrieve a valid token. The library handles expiration transparently, fetching a new token on the next call after expiry.
It supports three modes: fetching tokens from an OAuth 2.0 endpoint (the default), reading pre-generated tokens from files on disk, or injecting tokens via environment variables for local testing. This makes it useful for applications that need to authenticate with multiple OAuth-protected services without manually managing token refresh logic.
Use it for
- Manage multiple service tokens with different scopes in a single application.
- Local development and testing by injecting fixed tokens via environment variables.
- Read pre-generated credentials from disk for applications running in restricted environments.
- Automate token refresh for long-running processes that interact with OAuth 2.0-protected services.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No, unless maintaining legacy Python 2.7 or 3.4–3.5 code.
The package is abandoned (last release 2017-01-04, last commit 2019-03-19) and targets end-of-life Python versions. For new projects, use a modern OAuth library or your framework's built-in token handling. For existing deployments, evaluate whether migration is feasible.
Install
stups-tokens on PyPI
Before you install
Low install friction with no runtime dependencies. However, the package is abandoned—last release was 2017-01-04 and last commit 2019-03-19. It targets Python 2.7, 3.4, and 3.5, which are all end-of-life. Use only if maintaining legacy code.
Requires OAUTH2_ACCESS_TOKEN_URL environment variable or explicit url parameter; CREDENTIALS_DIR may be needed depending on configuration mode.
License in practice
Licensed under Apache License Version 2.0 (permissive), allowing commercial and private use with minimal restrictions.
Quickstart
import tokens
tokens.configure(url='https://example.com/access_tokens')
tokens.manage('example', ['read', 'write'])
tokens.start()
token = tokens.get('example')
Verify before relying
- Compatibility with modern Python versions beyond the declared 2.7, 3.4, and 3.5 support.
- Whether the package works with current OAuth 2.0 provider implementations and token endpoint changes since 2017.
- Active maintenance or security updates for production use.
Package facts
| License | Apache License Version 2.0 permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Abandoned 3,509 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 144,229 / month, #11,158 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 2.7Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5 |
Evidence: stups_tokens-1.1.19-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “oauth token management”
- stups-tokensManages OAuth 2.0 access tokens in memory, automatically refreshing…
- requests-oauthlibAdds OAuth 1 and OAuth 2 authentication support to the Requests HTTP…
- h2o-authnProvides OAuth 2.0 token management for H2O Python clients, handling…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also stups-cli-support · stups-zign · requests-oauth2client · oauth2-client · requests-oauthlib · requests-auth · django-oauth-toolkit · google-oauth · requests-kerberos · Flask-OAuthlib