Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

authorizer-python

Python SDK for authorizer.dev — self-hosted authentication & authorization. Current version: 0.2.0.

Getting Started

You need a running Authorizer instance before using this SDK. See the deployment guide to spin one up.

Install

pip install authorizer-py

For gRPC transport, install the optional extras:

pip install 'authorizer-py[grpc]'

Initialize the client

Parameter Required Description
client_id Yes Your Authorizer app's client ID
authorizer_url Yes Base URL of your Authorizer instance (no trailing slash)
redirect_url No Default redirect URL used by magic-link and forgot-password flows
extra_headers No Additional headers sent on every request (e.g. custom Origin)
protocol No Transport: "graphql" (default), "rest", or "grpc"
grpc_endpoint No gRPC target host:port. The server's gRPC listener runs on a separate port (default 9091), not the HTTP URL's port. Only used when protocol="grpc".

Protocol option

The protocol parameter selects which transport the SDK uses:

  • "graphql" (default) — sends requests to the /graphql endpoint
  • "rest" — uses the REST API (/api/*)
  • "grpc" — uses the gRPC endpoint (requires authorizer-py[grpc] and the server running >= v2.3.0)

Sync client:

from authorizer import AuthorizerClient

client = AuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
    # optional — 'graphql' (default), 'rest', or 'grpc'
    protocol="graphql",
)

# Use as a context manager to auto-close the HTTP session
with AuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
) as client:
    ...

Async client:

from authorizer import AsyncAuthorizerClient

async with AsyncAuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
) as client:
    ...

Usage

Login

from authorizer import AuthorizerClient, LoginRequest

with AuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
) as client:
    token = client.login(LoginRequest(email="user@example.com", password="Abc@123"))
    if token.user:
        print("Logged in as:", token.user.email)
    print("access_token:", token.access_token)

Note (Authorizer >= v2.3.0): the server's CSRF guard requires an Origin header on state-changing requests. The client sends the Authorizer server's own origin by default, which always passes. If your instance restricts ALLOWED_ORIGINS, pass your app's origin instead via extra_headers: {"Origin": "https://your-app.com"}.

gRPC transport

Set protocol="grpc" to call the server over gRPC. The server's gRPC listener runs on a separate port (default 9091). When grpc_endpoint is unset, the host is taken from authorizer_url and port 9091 is used; pass grpc_endpoint to dial a custom target:

from authorizer import AuthorizerClient

client = AuthorizerClient(
    client_id="YOUR_CLIENT_ID",
    authorizer_url="https://your-instance.authorizer.dev",
    protocol="grpc",
    grpc_endpoint="your-instance.authorizer.dev:9091",  # optional; defaults to host:9091
)

Admin API

The SDK exposes admin methods for server-side use cases (user management, session listing, etc.). Admin methods require the admin secret, which you should pass via extra_headers or by using the admin client directly. See the admin API docs for the full list of operations.

Fine-grained authorization (FGA)

Authorizer supports OpenFGA-style relationship-based access control. The subject of a permission check defaults to the authenticated caller — it is pinned server-side from the Authorization header you supply. The optional user field on CheckPermissionsRequest / ListPermissionsRequest is honored only for super-admins or when the value matches the caller's own identity.

from authorizer import (
    AuthorizerClient,
    CheckPermissionsRequest,
    ListPermissionsRequest,
    PermissionCheckInput,
)

client = AuthorizerClient("YOUR_CLIENT_ID", "https://your-instance.authorizer.dev")
auth = {"Authorization": "Bearer USER_ACCESS_TOKEN"}

# Check multiple relations in one call
checks = client.check_permissions(
    CheckPermissionsRequest(
        checks=[
            PermissionCheckInput(relation="can_view", object="document:1"),
            PermissionCheckInput(relation="can_edit", object="document:1"),
        ]
    ),
    headers=auth,
)
for r in checks.results:
    print(r.relation, r.object, r.allowed)

# List all objects the caller can view
accessible = client.list_permissions(
    ListPermissionsRequest(relation="can_view", object_type="document"),
    headers=auth,
)
print("can view:", accessible.objects)
client.close()

License

Apache-2.0 — see LICENSE for details.


Release

  1. Bump the version in setup.py / pyproject.toml.
  2. Tag the commit: git tag v<version>
  3. Push with tags: git push origin main --tags

The GitHub Actions release workflow handles PyPI publish and GitHub Release creation automatically.

Release files for authorizer-py 0.3.0rc4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for authorizer-py 0.3.0rc4
File Size Uploaded
authorizer_py-0.3.0rc4.tar.gz 62.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for authorizer-py 0.3.0rc4
File Interpreter ABI Platform
authorizer_py-0.3.0rc4-py3-none-any.whl Python 3 none any Details

Total release size: 115.2 kB

Release files / authorizer_py-0.3.0rc4.tar.gz

Download URL authorizer_py-0.3.0rc4.tar.gz
Size 62.6 kB
Tags Source
SHA-256 checksum
How to use checksums
0cd1f5a3608a7582536a3f6c184fac4afefe2538f63997cfc97f7fa1f382fe22
BLAKE2b-256 checksum
How to use checksums
803d8bead263d762b3f8f72ff32fda49135ba99acfcef86a5aee50da612e0909
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release files / authorizer_py-0.3.0rc4-py3-none-any.whl

Download URL authorizer_py-0.3.0rc4-py3-none-any.whl
Size 52.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
66a4a5d1f64451e5d38288a977e97629ba434889ef814672f2d0644b24af4ea2
BLAKE2b-256 checksum
How to use checksums
937029f43036c26dc5dcf5163c8daeb4db847b4497d6b0d718b8a03621cac82d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page