$npx skillfedfor your agent

webauthn

Pythonic WebAuthn

Worth itPyPI CryptographyReleased Jun 20267.0M downloads / moBSD-3-ClausePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — webauthn-3.0.0-py3-none-any.whl
v3.0.0 · released 2026-06-29 · Python >=3.10 · 5 runtime deps: pyasn1, pyasn1-modules, cbor2, cryptography, pyOpenSSL

Yes. This is a production-stable, actively maintained library with no known vulnerabilities, low install friction, and a permissive license. Install it if you need to add WebAuthn support to a Python backend and are targeting Python 3.10+. The API is straightforward and the dependency footprint is small and well-established.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Low install friction with a pure-Python wheel and five stable runtime dependencies.
  • Active maintenance with a recent release and no known vulnerabilities.

License · maintenance · safety

BSD-3-Clause (permissive) — BSD-3-Clause permissive license allows commercial and private use with minimal restrictions.

last release 2026-06-29 (46 days) · last repo commit 2026-06-29 · 1,056 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 6,984,854 downloads/mo, #1,801 on PyPI

Verify before relying

pip install webauthn

from webauthn import generate_registration_options, verify_registration_response

options = generate_registration_options(rp_id="example.com", rp_name="Example")
# Send options to client, receive response, then:
verified = verify_registration_response(credential=response, expected_challenge=challenge)
  • Whether the library's type hints and dataclass helpers fully cover all WebAuthn spec edge cases in production deployments.
  • Performance characteristics when handling high-volume concurrent registration and authentication flows.
Same gist for agents: .md · .json

What it is and what it does

py_webauthn is a server-side implementation of the WebAuthn specification that handles the cryptographic validation of passwordless authentication credentials. It works with any FIDO2-compliant authenticator—security keys, Touch ID, Face ID, Windows Hello, Android biometrics—and exposes four core methods: generate_registration_options, verify_registration_response, generate_authentication_options, and verify_authentication_response. The library assumes JSON transport between server and browser, with base64url encoding for binary data to avoid extra dependencies.

The package depends on pyasn1, pyasn1-modules, cbor2, cryptography, and pyOpenSSL to handle the underlying cryptographic operations and ASN.1 parsing required by the WebAuthn spec. It provides helper dataclasses for type-safe construction of inputs and outputs, and utility functions for JSON serialization and base64url conversion. Developers integrate it by generating challenge-based options on the server, sending them to the browser's WebAuthn API, then validating the returned credential against the server-stored challenge.

Use it for

  • Add passwordless login to a web application using hardware security keys or platform biometrics.
  • Implement multi-factor authentication where WebAuthn serves as a second factor alongside passwords.
  • Build a registration flow that enrolls users' authenticators and stores their public keys server-side.
  • Verify authentication responses from browser-based WebAuthn ceremonies without managing passwords.
  • Support cross-platform authentication across desktop, mobile, and web clients with a single server implementation.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

This is a production-stable, actively maintained library with no known vulnerabilities, low install friction, and a permissive license. Install it if you need to add WebAuthn support to a Python backend and are targeting Python 3.10+. The API is straightforward and the dependency footprint is small and well-established.

Install

webauthn on PyPI

Before you install

Low install friction with a pure-Python wheel and five stable runtime dependencies. Active maintenance with a recent release and no known vulnerabilities.

Requires Python 3.10 or later.

License in practice

BSD-3-Clause permissive license allows commercial and private use with minimal restrictions.

Quickstart

pip install webauthn

from webauthn import generate_registration_options, verify_registration_response

options = generate_registration_options(rp_id="example.com", rp_name="Example")
# Send options to client, receive response, then:
verified = verify_registration_response(credential=response, expected_challenge=challenge)

Verify before relying

  • Whether the library's type hints and dataclass helpers fully cover all WebAuthn spec edge cases in production deployments.
  • Performance characteristics when handling high-volume concurrent registration and authentication flows.

Package facts

LicenseBSD-3-Clause permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
5 packages
pyasn1pyasn1-modulescbor2cryptographypyOpenSSL
MaintenanceActively maintained 46 days since the last release
Last repo commit
First released
Downloads6,984,854 / month, #1,801 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: Python :: 3

Evidence: webauthn-3.0.0-py3-none-any.whl

Tags

Capabilities
webauthn server implementationfido2 authenticationpasswordless loginsecurity key verificationbiometric authentication server
Topics
authenticationcryptographyfido2
PyPI keywords
webauthnfido2

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “webauthn server implementation”

  • webauthnImplements server-side WebAuthn validation for passwordless…
  • fido2Implements FIDO2 and WebAuthn protocols for communicating with USB…
  • django-otp-webauthnAdds WebAuthn Passkey support to Django OTP, enabling passwordless…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also django-otp-webauthn · fido2 · soft-webauthn · django-authlib · pyobjc-framework-LocalAuthentication · djoser · PyOTP · django-magiclink · Flask-Security-Too · stytch