webargs
Declarative parsing and validation of HTTP request objects, with built-in support for popular web frameworks, including Flask, Django, Bottle, Tornado, Pyramid, Falcon, and aiohttp.
Decision gist · record as of 2026-08-14
Yes. webargs is a mature, actively maintained library in production/stable status with no known vulnerabilities, low install friction, and broad framework support. It solves a common problem—request validation—in a declarative, reusable way. Install it if you are building web APIs or handlers in any of the supported frameworks and want to avoid manual argument parsing and validation boilerplate.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; also requires the web framework you intend to use (e.g., Flask for the example above).
- Low install friction; pure Python wheel with only three runtime dependencies (marshmallow, packaging, typing_extensions).
- Actively maintained with recent releases and no known vulnerabilities.
License · maintenance · safety
permissive license (permissive) — MIT licensed under permissive terms, allowing use in commercial and proprietary projects with minimal restrictions.
last release 2025-10-29 (289 days) · last repo commit 2026-08-13 · 1,408 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 3,929,873 downloads/mo, #2,451 on PyPI
Alternatives
Verify before relying
pip install webargs
from webargs import fields
from webargs.flaskparser import use_args
@use_args({"name": fields.Str(required=True)}, location="query")
def index(args):
return "Hello " + args["name"]- Whether webargs automatically coerces types beyond what marshmallow provides by default.
- Performance characteristics when validating large request payloads or deeply nested schemas.
- Exact scope of framework support—whether all listed frameworks are equally maintained.
- Whether all supported frameworks (Flask, Django, Bottle, Tornado, Pyramid, Falcon, aiohttp) are actively maintained in webargs.
What it is and what it does
webargs is a declarative HTTP request parsing and validation library built on top of marshmallow schemas. It lets you define what arguments your web endpoint expects—their names, types, and validation rules—then automatically extracts and validates them from incoming requests. Instead of manually checking request objects and writing validation code, you decorate your handler with a schema and webargs handles the rest, returning either validated data or raising validation errors.
The library integrates with popular Python web frameworks including Flask, Django, Bottle, Tornado, Pyramid, Falcon, and aiohttp, so you use the same schema definitions across different frameworks. It supports extracting arguments from query strings, form data, JSON bodies, headers, and cookies. The underlying validation engine is marshmallow, so you get all of marshmallow's field types, custom validators, and error handling.
Use it for
- Validate query parameters in a REST endpoint without writing manual type checks or try-catch blocks.
- Parse and validate JSON request bodies in an API view using declarative field schemas.
- Extract and coerce form data in a handler, with automatic error responses for invalid input.
- Centralize request validation logic across multiple endpoints using reusable marshmallow schemas.
- Build a REST API where request validation errors are automatically formatted and returned to clients.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
webargs is a mature, actively maintained library in production/stable status with no known vulnerabilities, low install friction, and broad framework support. It solves a common problem—request validation—in a declarative, reusable way. Install it if you are building web APIs or handlers in any of the supported frameworks and want to avoid manual argument parsing and validation boilerplate.
Install
webargs on PyPI
Before you install
Low install friction; pure Python wheel with only three runtime dependencies (marshmallow, packaging, typing_extensions). Actively maintained with recent releases and no known vulnerabilities.
Requires Python 3.9 or later; also requires the web framework you intend to use (e.g., Flask for the example above).
License in practice
MIT licensed under permissive terms, allowing use in commercial and proprietary projects with minimal restrictions.
Quickstart
pip install webargs
from webargs import fields
from webargs.flaskparser import use_args
@use_args({"name": fields.Str(required=True)}, location="query")
def index(args):
return "Hello " + args["name"]
Verify before relying
- Whether webargs automatically coerces types beyond what marshmallow provides by default.
- Performance characteristics when validating large request payloads or deeply nested schemas.
- Exact scope of framework support—whether all listed frameworks are equally maintained.
- Whether all supported frameworks (Flask, Django, Bottle, Tornado, Pyramid, Falcon, aiohttp) are actively maintained in webargs.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesmarshmallowpackagingtyping_extensions |
| Maintenance | Actively maintained 289 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 3,929,873 / month, #2,451 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Internet :: WWW/HTTP :: WSGI :: Application |
Evidence: webargs-8.7.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “http request parsing validation”
- webargswebargs parses and validates HTTP request arguments (query strings,…
- aiohttp-swagger3Integrates OpenAPI 3 documentation and request validation into…
- Flask-PydanticAdds Pydantic model validation to Flask route handlers, automatically…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also flask-apispec · apispec-webframeworks · jsonschema · marshmallow · beautifulsoup4 · hug · flask-marshmallow · APIFlask · Flask-WTF