webauthn
Pythonic WebAuthn
Decision gist · record as of 2026-08-14
Yes. This is a production-stable, actively maintained library with no known vulnerabilities, low install friction, and a permissive license. Install it if you need to add WebAuthn support to a Python backend and are targeting Python 3.10+. The API is straightforward and the dependency footprint is small and well-established.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low install friction with a pure-Python wheel and five stable runtime dependencies.
- Active maintenance with a recent release and no known vulnerabilities.
License · maintenance · safety
BSD-3-Clause (permissive) — BSD-3-Clause permissive license allows commercial and private use with minimal restrictions.
last release 2026-06-29 (46 days) · last repo commit 2026-06-29 · 1,056 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 6,984,854 downloads/mo, #1,801 on PyPI
Alternatives
Verify before relying
pip install webauthn
from webauthn import generate_registration_options, verify_registration_response
options = generate_registration_options(rp_id="example.com", rp_name="Example")
# Send options to client, receive response, then:
verified = verify_registration_response(credential=response, expected_challenge=challenge)- Whether the library's type hints and dataclass helpers fully cover all WebAuthn spec edge cases in production deployments.
- Performance characteristics when handling high-volume concurrent registration and authentication flows.
What it is and what it does
py_webauthn is a server-side implementation of the WebAuthn specification that handles the cryptographic validation of passwordless authentication credentials. It works with any FIDO2-compliant authenticator—security keys, Touch ID, Face ID, Windows Hello, Android biometrics—and exposes four core methods: generate_registration_options, verify_registration_response, generate_authentication_options, and verify_authentication_response. The library assumes JSON transport between server and browser, with base64url encoding for binary data to avoid extra dependencies.
The package depends on pyasn1, pyasn1-modules, cbor2, cryptography, and pyOpenSSL to handle the underlying cryptographic operations and ASN.1 parsing required by the WebAuthn spec. It provides helper dataclasses for type-safe construction of inputs and outputs, and utility functions for JSON serialization and base64url conversion. Developers integrate it by generating challenge-based options on the server, sending them to the browser's WebAuthn API, then validating the returned credential against the server-stored challenge.
Use it for
- Add passwordless login to a web application using hardware security keys or platform biometrics.
- Implement multi-factor authentication where WebAuthn serves as a second factor alongside passwords.
- Build a registration flow that enrolls users' authenticators and stores their public keys server-side.
- Verify authentication responses from browser-based WebAuthn ceremonies without managing passwords.
- Support cross-platform authentication across desktop, mobile, and web clients with a single server implementation.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is a production-stable, actively maintained library with no known vulnerabilities, low install friction, and a permissive license. Install it if you need to add WebAuthn support to a Python backend and are targeting Python 3.10+. The API is straightforward and the dependency footprint is small and well-established.
Install
webauthn on PyPI
Before you install
Low install friction with a pure-Python wheel and five stable runtime dependencies. Active maintenance with a recent release and no known vulnerabilities.
Requires Python 3.10 or later.
License in practice
BSD-3-Clause permissive license allows commercial and private use with minimal restrictions.
Quickstart
pip install webauthn
from webauthn import generate_registration_options, verify_registration_response
options = generate_registration_options(rp_id="example.com", rp_name="Example")
# Send options to client, receive response, then:
verified = verify_registration_response(credential=response, expected_challenge=challenge)
Verify before relying
- Whether the library's type hints and dataclass helpers fully cover all WebAuthn spec edge cases in production deployments.
- Performance characteristics when handling high-volume concurrent registration and authentication flows.
Package facts
| License | BSD-3-Clause permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 5 packagespyasn1pyasn1-modulescbor2cryptographypyOpenSSL |
| Maintenance | Actively maintained 46 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 6,984,854 / month, #1,801 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: Python :: 3 |
Evidence: webauthn-3.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “webauthn server implementation”
- webauthnImplements server-side WebAuthn validation for passwordless…
- fido2Implements FIDO2 and WebAuthn protocols for communicating with USB…
- django-otp-webauthnAdds WebAuthn Passkey support to Django OTP, enabling passwordless…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also django-otp-webauthn · fido2 · soft-webauthn · django-authlib · pyobjc-framework-LocalAuthentication · djoser · PyOTP · django-magiclink · Flask-Security-Too · stytch