Skip to main content

Comprehensive authentication and authorization library for Python

Project description

AuthFort

authfort

PyPI Coverage Python License: MIT Docs

Complete authentication and authorization library for Python.

Install

pip install authfort[fastapi]
# or with SQLite: pip install authfort[sqlite,fastapi]

Quick Start

from authfort import AuthFort, CookieConfig
from fastapi import FastAPI, Depends

auth = AuthFort(
    database_url="postgresql+asyncpg://user:pass@localhost/mydb",
    cookie=CookieConfig(),
)

app = FastAPI()
app.include_router(auth.fastapi_router(), prefix="/auth")
app.include_router(auth.jwks_router())

@app.get("/profile")
async def profile(user=Depends(auth.current_user)):
    return {"email": user.email, "roles": user.roles}

Endpoints

Method Path Description
POST /auth/signup Create account
POST /auth/login Sign in
POST /auth/refresh Refresh access token
POST /auth/logout Sign out
GET /auth/me Get current user
POST /auth/magic-link Request magic link
POST /auth/magic-link/verify Verify magic link
POST /auth/otp Request email OTP
POST /auth/otp/verify Verify email OTP
POST /auth/verify-email Verify email address
GET /auth/oauth/{provider}/authorize Start OAuth flow
GET /auth/oauth/{provider}/callback OAuth callback
POST /auth/introspect Token introspection
GET /.well-known/jwks.json Public signing keys

Features

  • Email/password auth with argon2 hashing
  • JWT RS256 with automatic key management
  • Refresh token rotation with theft detection
  • OAuth 2.1 with PKCE (Google, GitHub, or any provider via GenericOAuthProvider/GenericOIDCProvider)
  • Email verification, magic links, email OTP (passwordless)
  • Role-based access control
  • Password reset (programmatic — you control delivery)
  • Change password (with old password verification)
  • Session management (list, revoke, revoke all except current)
  • Ban/unban users
  • Rate limiting — per-endpoint IP + email based, in-memory sliding window, pluggable storage
  • Admin user management — list, search, get, delete users programmatically
  • Event hooks (24 event types)
  • JWKS + key rotation
  • Cookie and bearer token modes
  • Multi-database: PostgreSQL (default), SQLite, MySQL via SQLAlchemy

OAuth

from authfort import AuthFort, GoogleProvider, GitHubProvider, GenericOIDCProvider

auth = AuthFort(
    database_url="...",
    providers=[
        GoogleProvider(client_id="...", client_secret="..."),
        GitHubProvider(client_id="...", client_secret="..."),
        GenericOIDCProvider(
            "keycloak",
            client_id="...",
            client_secret="...",
            discovery_url="https://keycloak.example.com/realms/myrealm/.well-known/openid-configuration",
        ),
    ],
)

Programmatic API

# Create users without the HTTP endpoint
result = await auth.create_user("admin@example.com", "password", name="Admin")

# Roles
await auth.add_role(user_id, "admin")
await auth.remove_role(user_id, "editor")

# Password reset (you handle delivery — email, SMS, etc.)
token = await auth.create_password_reset_token("user@example.com")
if token:
    send_email(email, f"https://myapp.com/reset?token={token}")
await auth.reset_password(token, "new_password")

# Change password (authenticated)
await auth.change_password(user_id, "old_password", "new_password")

# Sessions
sessions = await auth.get_sessions(user_id, active_only=True)
await auth.revoke_session(session_id)
await auth.revoke_all_sessions(user_id, exclude=user.session_id)  # keep current

# Ban/unban
await auth.ban_user(user_id)
await auth.unban_user(user_id)

# Admin user management
users = await auth.list_users(query="john", role="admin", limit=20)
user = await auth.get_user(user_id)
await auth.delete_user(user_id)
count = await auth.get_user_count(banned=True)

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

authfort-0.0.13.tar.gz (79.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

authfort-0.0.13-py3-none-any.whl (62.2 kB view details)

Uploaded Python 3

File details

Details for the file authfort-0.0.13.tar.gz.

File metadata

  • Download URL: authfort-0.0.13.tar.gz
  • Upload date:
  • Size: 79.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.10.7 {"installer":{"name":"uv","version":"0.10.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for authfort-0.0.13.tar.gz
Algorithm Hash digest
SHA256 8cbb7ec1080abc25d867940a8251a0b237c997f5e71f5abae109452dc7e63d32
MD5 e0f33c1570a9c89b7b2d2cdb6f0ef3dd
BLAKE2b-256 943d5c0a674bc5bda044f01493afaa0a1c2d13b9cde93552f57f9188e019f343

See more details on using hashes here.

File details

Details for the file authfort-0.0.13-py3-none-any.whl.

File metadata

  • Download URL: authfort-0.0.13-py3-none-any.whl
  • Upload date:
  • Size: 62.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.10.7 {"installer":{"name":"uv","version":"0.10.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for authfort-0.0.13-py3-none-any.whl
Algorithm Hash digest
SHA256 4320c340a6761a87b19a5f60e43b6e62fe5440516d6d37f40d0203ab1010d76e
MD5 6da41b05fd734841b3e0976a71f443a2
BLAKE2b-256 50dd19a03295c560d5f5543371ea5361df336b65fd4e6aad60b062d81a86098f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page