Skip to main content

Django Multifactor Authentication

pypi version

Flexible authentication for web, mobile, desktop and hybrid apps. It can be used for 1fa, 2fa and mfa cases. Easily configurable and extendable with new authentication methods or services. Authenticaton scenarios, called flows, are based on identifiers and secrets, which can be used or not used in multiple combinations:

  • username, email, phone, ...
  • password, passcode (one-time pass or token), hardcode (device or card id), ...

Full list of supported services and corresponding identifiers:

  • Email
  • Phone (as Sms)
  • WhatsApp
  • Google Authenticator
  • Microsoft Authenticator
  • Authy, andOTP, etc
  • Yubikey (soon)
  • ...add yours

and service providers:

  • Twilio
  • Vonage (Nexmo)
  • Amazon SNS (soon)
  • ...add yours

Usage

The package creates custom user model, that could be used as is or as inherited. General priniciples for custom user models in Django are respected (how it works).

Base settings (required):

AUTH_USER_MODEL = 'multauth.User'
AUTHENTICATION_BACKENDS = (
    'multauth.backends.ModelBackend',
    # ...etc
)

MULTAUTH_FLOWS = (
    # pattern: ('identifier', 'secret1', 'secret2', ...)
    ('phone', 'hardcode', 'passcode'),
    ('email', 'password', 'passcode'),
    ('username', 'password'),
    # ...etc
)

The flows mean that user could be authenticated with any of these sets of crendials, ie set of identfier and secrets. For example, this one: ('email', 'password', 'passcode',). Number of flows could be any, but in most cases only one or two are used.

Extra settings (optional):
(see built-in services, providers and templates)

MULTAUTH_SERVICES = [
  'multauth.services.UsernameService',
  'multauth.services.EmailService',
  'multauth.services.PhoneService',
] # by default

MULTAUTH_DEBUG = True # False by default
MULTAUTH_PASSCODE_LENGTH = 6 # size in digits
MULTAUTH_PASSCODE_EXPIRY = 3600 # time in seconds
MULTAUTH_PASSCODE_SERVICE = 'multauth.services.PhoneService' # by default

MULTAUTH_SERVICE_EMAIL_PROVIDER = 'multauth.providers.MailProvider' # by default
MULTAUTH_SERVICE_PHONE_PROVIDER = 'multauth.providers.TwilioProvider' # by default

MULTAUTH_SERVICE_EMAIL_TEMPLATE_NAME = 'custom'
MULTAUTH_SERVICE_EMAIL_VERIFICATION_VIEWNAME = 'custom'
MULTAUTH_SERVICE_PHONE_TEMPLATE_NAME = 'custom'

Provider specific settings (could be required):

MULTAUTH_PROVIDER_TWILIO_ACCOUNT_SID = 'SID'
MULTAUTH_PROVIDER_TWILIO_AUTH_TOKEN = 'TOKEN'
MULTAUTH_PROVIDER_TWILIO_CALLER_ID = 'CALLER_ID' # '+15005550006'

MULTAUTH_PROVIDER_VONAGE_API_KEY = 'KEY'
MULTAUTH_PROVIDER_VONAGE_API_SECRET = 'SECRET'
MULTAUTH_PROVIDER_VONAGE_BRAND_NAME = 'BRAND_NAME' # 'Vonage APIs'

Usage more

Custom use cases and how to config or code them.

APIs

Package contains full set of rest api endpoints, but it's optional. To activate it, djangorestframework>=3.10.3 should be installed and the urls be included:

urlpatterns = [
    path(r'^', include('multauth.api.urls')),
]

User activation

Users are set as "active" on creation. This behavior is not managed by settings for now (check for further updates).

Services verification

By default all services are set as "confirmed" on creation. To change this behavior extra settings should be added, for example:

MULTAUTH_SERVICE_EMAIL_CONFIRMED = False
MULTAUTH_SERVICE_PHONE_CONFIRMED = False
...

Non-comfirmed services will automatically be called for verification (token/key to be sent) on creation or idenfier updates. To invoke verification manually, call api endpoints:

  • multauth:signup-verification

or model methods:

  • user.verify for all non-confirmed services
  • user.verify_email for email
  • user.verify_phone for phone
  • ...

And to complete verification process call api endpoints:

  • multauth:signup-verification-phone to post the token
  • multauth:signup-verification-email to post the token
  • multauth:signup-verification-email-key as a classic in-email link to pass the key
  • ...

or model methods:

  • user.verify_phone_token
  • user.verify_email_token
  • user.verify_email_key
  • ...

Metadata

Release files for django-multifactor-authentication 2.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for django-multifactor-authentication 2.0.1
File Size Uploaded
django-multifactor-authentication-2.0.1.tar.gz 25.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for django-multifactor-authentication 2.0.1
File Interpreter ABI Platform
django_multifactor_authentication-2.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 99.2 kB

Release files / django-multifactor-authentication-2.0.1.tar.gz

Download URL django-multifactor-authentication-2.0.1.tar.gz
Size 25.7 kB
Tags Source
SHA-256 checksum
How to use checksums
83a32e1e8f2a794fe341f109825c3259d567297aea06452c78cf1a6c27df23b2
BLAKE2b-256 checksum
How to use checksums
25e816388bf3c2b7d7a8e5fb3d86cd32a390c9f4de604a3a74b7efe5bd9f743f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.2.0 pkginfo/1.6.1 requests/2.24.0 setuptools/49.2.0 requests-toolbelt/0.9.1 tqdm/4.54.0 CPython/3.8.5

Release files / django_multifactor_authentication-2.0.1-py3-none-any.whl

Download URL django_multifactor_authentication-2.0.1-py3-none-any.whl
Size 73.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
13aa7cf63b263e1853d57302a4f3aa04bed8155f8e1819ba30710f378ab88a3d
BLAKE2b-256 checksum
How to use checksums
67d44cfe360c677509c137e4255e98572be31d128a0fdab76b24e3b22c8bd8f2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.2.0 pkginfo/1.6.1 requests/2.24.0 setuptools/49.2.0 requests-toolbelt/0.9.1 tqdm/4.54.0 CPython/3.8.5

Release history Release notifications | RSS feed

This release

2.0.1 This release

2 release files

2.0.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.9.7

1 release file

0.9.5

2 release files

0.9.3

2 release files

0.0.3

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page