$npx skillfedfor your agent

vercel-oidc

OIDC helpers for Vercel Python applications

With conditionsPyPI CryptographyReleased Aug 20261.2M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — vercel_oidc-0.8.0-py3-none-any.whl
v0.8.0 · released 2026-08-08 · Python >=3.10 · 3 runtime deps: anyio, httpx, vercel-headers

Yes, if you are building Python applications on Vercel and need to work with OIDC tokens. The library is actively maintained, has low install friction, and provides both basic token handling and optional cryptographic verification. No known vulnerabilities. The MIT license poses no restrictions.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Token verification requires the optional verify extra: pip install vercel-oidc[verify]
  • Low install friction with a pure Python wheel and only three runtime dependencies (anyio, httpx, vercel-headers).

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with only attribution required.

last release 2026-08-08 (6 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,192,374 downloads/mo, #4,238 on PyPI

Verify before relying

# Install
pip install vercel-oidc

# Async token retrieval and decode
from vercel.oidc import decode_oidc_payload
from vercel.oidc.aio import get_vercel_oidc_token

async def main():
    token = await get_vercel_oidc_token()
    payload = decode_oidc_payload(token)
    project_id = payload.get("project_id")
  • Whether vercel-headers is a first-party Vercel package or a separate community dependency with its own maintenance status.
  • Whether the optional verify extra (pyjwt[crypto]) adds significant install complexity or system dependencies beyond Python packages.
Same gist for agents: .md · .json

What it is and what it does

vercel-oidc is a library for working with OpenID Connect tokens issued by Vercel's OIDC service. It provides functions to retrieve tokens from request headers or environment variables, decode their payloads to extract claims like project_id, and optionally verify signatures using Vercel's public key set. The library supports both synchronous and asynchronous code paths and includes a token identity resolver that produces a stable digest safe for logging.

The package is designed for Vercel Python applications that need to authenticate workloads or validate incoming requests. Token retrieval prefers the x-vercel-oidc-token header (registered via vercel.headers.set_headers) and falls back to the VERCEL_OIDC_TOKEN environment variable. Verification is optional but when enabled enforces RS256 signatures, pins the issuer to Vercel's OIDC endpoints, and fails closed if the expected project or environment cannot be resolved.

Use it for

  • Retrieve and decode OIDC tokens in async Vercel Functions to extract project or environment metadata from claims.
  • Verify incoming bearer tokens in request handlers to authenticate requests from other Vercel workloads.
  • Generate a stable identity digest from a token for keying client-side state without exposing the token itself.
  • Validate token signatures and issuer in local development by loading short-lived tokens via the vc CLI.
  • Enforce project and environment isolation by failing closed when expected context cannot be resolved from configuration.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are building Python applications on Vercel and need to work with OIDC tokens.

The library is actively maintained, has low install friction, and provides both basic token handling and optional cryptographic verification. No known vulnerabilities. The MIT license poses no restrictions.

Install

vercel-oidc on PyPI

Before you install

Low install friction with a pure Python wheel and only three runtime dependencies (anyio, httpx, vercel-headers). Active maintenance with a release 6 days ago.

Requires Python 3.10 or later. Token verification requires the optional verify extra: pip install vercel-oidc[verify]

License in practice

MIT license permits unrestricted use, modification, and distribution with only attribution required.

Quickstart

# Install
pip install vercel-oidc

# Async token retrieval and decode
from vercel.oidc import decode_oidc_payload
from vercel.oidc.aio import get_vercel_oidc_token

async def main():
    token = await get_vercel_oidc_token()
    payload = decode_oidc_payload(token)
    project_id = payload.get("project_id")

Verify before relying

  • Whether vercel-headers is a first-party Vercel package or a separate community dependency with its own maintenance status.
  • Whether the optional verify extra (pyjwt[crypto]) adds significant install complexity or system dependencies beyond Python packages.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
anyiohttpxvercel-headers
MaintenanceActively maintained 6 days since the last release
First released
Downloads1,192,374 / month, #4,238 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: vercel_oidc-0.8.0-py3-none-any.whl

Tags

Capabilities
vercel oidc tokenopenid connect verceljwt verification verceloidc token decodevercel authentication pythonoidc async token lookupvercel identity verification
Topics
vercel-platformoidc-jwtasync-support

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “vercel oidc token”

  • vercel-oidcRetrieves, decodes, and verifies Vercel OIDC tokens for Python…
  • vercelPython SDK for Vercel that provides modules for interacting with…
  • vercel-headersRegisters and exposes request headers for Vercel Python functions,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also okta-jwt-verifier · vercel-headers · pyjwt-key-fetcher · vercel · cognitojwt · flask-oidc · auth0-api-python · id · spiffe · jwt