Skip to main content

Python SDK for authorizer.dev — self-hosted authentication & authorization

Project description

authorizer-python

Python SDK for authorizer.dev — self-hosted authentication & authorization. Current version: 0.2.0.

Getting Started

You need a running Authorizer instance before using this SDK. See the deployment guide to spin one up.

Install

pip install authorizer-py

For gRPC transport, install the optional extras:

pip install 'authorizer-py[grpc]'

Initialize the client

Parameter Required Description
client_id Yes Your Authorizer app's client ID
authorizer_url Yes Base URL of your Authorizer instance (no trailing slash)
redirect_url No Default redirect URL used by magic-link and forgot-password flows
extra_headers No Additional headers sent on every request (e.g. custom Origin)
protocol No Transport: "graphql" (default), "rest", or "grpc"
grpc_endpoint No gRPC target host:port. The server's gRPC listener runs on a separate port (default 9091), not the HTTP URL's port. Only used when protocol="grpc".

Protocol option

The protocol parameter selects which transport the SDK uses:

  • "graphql" (default) — sends requests to the /graphql endpoint
  • "rest" — uses the REST API (/api/*)
  • "grpc" — uses the gRPC endpoint (requires authorizer-py[grpc] and the server running >= v2.3.0)

Sync client:

from authorizer import AuthorizerClient

client = AuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
    # optional — 'graphql' (default), 'rest', or 'grpc'
    protocol="graphql",
)

# Use as a context manager to auto-close the HTTP session
with AuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
) as client:
    ...

Async client:

from authorizer import AsyncAuthorizerClient

async with AsyncAuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
) as client:
    ...

Usage

Login

from authorizer import AuthorizerClient, LoginRequest

with AuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
) as client:
    token = client.login(LoginRequest(email="user@example.com", password="Abc@123"))
    if token.user:
        print("Logged in as:", token.user.email)
    print("access_token:", token.access_token)

Note (Authorizer >= v2.3.0): the server's CSRF guard requires an Origin header on state-changing requests. The client sends the Authorizer server's own origin by default, which always passes. If your instance restricts ALLOWED_ORIGINS, pass your app's origin instead via extra_headers: {"Origin": "https://your-app.com"}.

gRPC transport

Set protocol="grpc" to call the server over gRPC. The server's gRPC listener runs on a separate port (default 9091). When grpc_endpoint is unset, the host is taken from authorizer_url and port 9091 is used; pass grpc_endpoint to dial a custom target:

from authorizer import AuthorizerClient

client = AuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
    protocol="grpc",
    grpc_endpoint="your-instance.authorizer.dev:9091",  # optional; defaults to host:9091
)

Admin API

The SDK exposes admin methods for server-side use cases (user management, session listing, etc.). Admin methods require the admin secret, which you should pass via extra_headers or by using the admin client directly. See the admin API docs for the full list of operations.

Fine-grained authorization (FGA)

Authorizer supports OpenFGA-style relationship-based access control. The subject of a permission check defaults to the authenticated caller — it is pinned server-side from the Authorization header you supply. The optional user field on CheckPermissionsRequest / ListPermissionsRequest is honored only for super-admins or when the value matches the caller's own identity.

from authorizer import (
    AuthorizerClient,
    CheckPermissionsRequest,
    ListPermissionsRequest,
    PermissionCheckInput,
)

client = AuthorizerClient("YOUR_CLIENT_ID", "https://your-instance.authorizer.dev")
auth = {"Authorization": "Bearer USER_ACCESS_TOKEN"}

# Check multiple relations in one call
checks = client.check_permissions(
    CheckPermissionsRequest(
        checks=[
            PermissionCheckInput(relation="can_view", object="document:1"),
            PermissionCheckInput(relation="can_edit", object="document:1"),
        ]
    ),
    headers=auth,
)
for r in checks.results:
    print(r.relation, r.object, r.allowed)

# List all objects the caller can view
accessible = client.list_permissions(
    ListPermissionsRequest(relation="can_view", object_type="document"),
    headers=auth,
)
print("can view:", accessible.objects)
client.close()

License

Apache-2.0 — see LICENSE for details.


Release

  1. Bump the version in setup.py / pyproject.toml.
  2. Tag the commit: git tag v<version>
  3. Push with tags: git push origin main --tags

The GitHub Actions release workflow handles PyPI publish and GitHub Release creation automatically.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

authorizer_py-0.3.0rc1.tar.gz (105.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

authorizer_py-0.3.0rc1-py3-none-any.whl (108.8 kB view details)

Uploaded Python 3

File details

Details for the file authorizer_py-0.3.0rc1.tar.gz.

File metadata

  • Download URL: authorizer_py-0.3.0rc1.tar.gz
  • Upload date:
  • Size: 105.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.13

File hashes

Hashes for authorizer_py-0.3.0rc1.tar.gz
Algorithm Hash digest
SHA256 005143a76ca5b8f4e00e77ab7d39986c97e102a9532d31dbe304a6291ed333ec
MD5 2b359a649473dd30e19554ddf745fd00
BLAKE2b-256 9cbc43eba8e15fcf0a8a64cb4262965cd1d8ebedc155586ef8339b6c5e8b32fb

See more details on using hashes here.

File details

Details for the file authorizer_py-0.3.0rc1-py3-none-any.whl.

File metadata

File hashes

Hashes for authorizer_py-0.3.0rc1-py3-none-any.whl
Algorithm Hash digest
SHA256 13f5a1b501a3d976c2e96d587bc8d7c3f920781a7b9d86e3bda09f1fd0d90538
MD5 933242a529afa5805d5c90ef85aeb48a
BLAKE2b-256 d61da622120fb344d01f7ddf9083b571370f0cb30923e48aba6be9e8d12d4faf

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page