Skip to main content
PyPI Code Coverage Test Checked with mypy Checked with pyright Docstring

Modern Django REST Framework authentication toolkit with JWT cookies, social login, MFA, and comprehensive user management.

Built as a next-generation alternative to existing DRF authentication packages, DRF Auth Kit provides a complete authentication solution with modern developer experience, inspired by dj-rest-auth but enhanced with full type safety, automatic OpenAPI schema generation, and comprehensive MFA support inspired by django-trench.

Features

  • Multiple Authentication Types: JWT (default), DRF Token, or Custom

  • Cookie-Based Security: HTTP-only cookies

  • Complete User Management: Registration, password reset, email verification

  • Multi-Factor Authentication: Support multiple MFAs with backup codes, including passkeys and hardware security keys

  • Passwordless Authentication: Email magic links and passkey (WebAuthn) login

  • Social Authentication: Django Allauth integration with 50+ providers, support for both OAuth2 and OpenID connect.

  • Internationalization: Built-in support for 57 languages including English, Spanish, French, German, Chinese, Japanese, Korean, Vietnamese, and more

  • Full Type Safety: Complete type hints with mypy and pyright

  • OpenAPI Integration: Auto-generated API documentation with DRF Spectacular

  • Flexible Configuration: Customizable serializers, views, and authentication backends

Installation

pip install drf-auth-kit

Optional Features:

# For MFA support
pip install drf-auth-kit[mfa]

# For social authentication
pip install drf-auth-kit[social]

# For passkeys / WebAuthn (passwordless and MFA)
pip install drf-auth-kit[webauthn]

# For everything
pip install drf-auth-kit[all]

Core Dependencies: Django 5.0+, DRF 3.0+, Django Allauth, DRF SimpleJWT

Quick Start

  1. Add to your Django settings:

INSTALLED_APPS = [
    # ... your apps
    'rest_framework',
    'allauth',  # Required for social auth
    'allauth.account',  # Required for social auth
    # 'allauth.socialaccount',  # For social login
    # 'allauth.socialaccount.providers.google',  # For Google login
    'auth_kit',
    # 'auth_kit.social',  # For social authentication
    # 'auth_kit.mfa',  # For MFA support
    # 'auth_kit.webauthn',  # For passkeys (passwordless login and MFA)
]

REST_FRAMEWORK = {
    'DEFAULT_AUTHENTICATION_CLASSES': [
        'auth_kit.authentication.JWTCookieAuthentication',
    ],
}

# Override only if needed:
# AUTH_KIT = {
#     'USE_MFA': True,  # Enable MFA
#     'USE_PASSWORDLESS': True,  # Enable passwordless login
# }

# Google OAuth2 settings (for social login)
# SOCIALACCOUNT_PROVIDERS = {
#     'google': {
#         'SCOPE': ['profile', 'email'],
#         'AUTH_PARAMS': {'access_type': 'online'},
#         'OAUTH_PKCE_ENABLED': True,
#         'APP': {
#             'client_id': 'your-google-client-id',
#             'secret': 'your-google-client-secret',
#         }
#     }
# }
  1. Include Auth Kit URLs:

from django.urls import path, include

urlpatterns = [
    path('api/auth/', include('auth_kit.urls')),
    # path('api/auth/social/', include('auth_kit.social.urls')),  # For social auth
    # path('api/auth/webauthn/', include('auth_kit.webauthn.urls')),  # For passkey management
    # ... your other URLs
]
  1. Run migrations (needed if using MFA or WebAuthn):

python manage.py migrate

Authentication Types

JWT Authentication (Recommended)
  • Access and refresh tokens

  • Token refresh support

  • Secure cookie storage

DRF Token Authentication
  • Simple token-based auth

  • Compatible with DRF TokenAuthentication

  • Cookie support available

Custom Authentication
  • Bring your own authentication backend

  • Full customization support

  • Integrate with third-party services

Documentation

Please visit DRF Auth Kit docs for complete documentation, including:

  • Detailed configuration options

  • Custom serializer examples

  • Advanced usage patterns

  • Integration guides

Upcoming Features

Enhanced Multi-Factor Authentication

  • SMS & Voice: Twilio integration for SMS and voice-based MFA

  • Authenticator Apps: Enhanced TOTP support (Google Authenticator, Authy, etc.)

  • Trusted Devices: Remember MFA verification for trusted browsers/sessions

Passwordless Authentication

  • SMS Login: One-time password via SMS

Advanced Security Features

  • Rate Limiting: Configurable rate limits for authentication endpoints

  • Account Lockout: Progressive delays and temporary account locks

  • Audit Logging: Comprehensive security event logging

  • Geographic Restrictions: IP-based access controls and geo-blocking

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

This project is licensed under the MIT License - see the LICENSE file for details.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

drf_auth_kit-1.8.1.tar.gz (591.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

drf_auth_kit-1.8.1-py3-none-any.whl (685.1 kB view details)

Uploaded Python 3

File details

Details for the file drf_auth_kit-1.8.1.tar.gz.

File metadata

  • Download URL: drf_auth_kit-1.8.1.tar.gz
  • Upload date:
  • Size: 591.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for drf_auth_kit-1.8.1.tar.gz
Algorithm Hash digest
SHA256 2ef098f7f385690e404a6295ecbd883db639c32b22e2e5771c67db31b2bd640d
MD5 06ee288cc20f31705c047f56d4995814
BLAKE2b-256 9cebe2eda941fb0d5048d496c7ff7b43271d418032223ba06cce8f164e70be98

See more details on using hashes here.

Provenance

The following attestation bundles were made for drf_auth_kit-1.8.1.tar.gz:

Publisher: publish.yml on forthecraft/drf-auth-kit

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file drf_auth_kit-1.8.1-py3-none-any.whl.

File metadata

  • Download URL: drf_auth_kit-1.8.1-py3-none-any.whl
  • Upload date:
  • Size: 685.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for drf_auth_kit-1.8.1-py3-none-any.whl
Algorithm Hash digest
SHA256 1d52a1dfdcad1b291f0546bbaed7b26f8c947dbabfa509a68254866a60b03a0d
MD5 d9b3c172eb9d9833fb1c5f6d2a4643a6
BLAKE2b-256 96aaa79075d90685f86066bd32c101745b9cbed5888b6e7b9ce4097b5fd0d657

See more details on using hashes here.

Provenance

The following attestation bundles were made for drf_auth_kit-1.8.1-py3-none-any.whl:

Publisher: publish.yml on forthecraft/drf-auth-kit

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

1.8.1 This release

2 files

1.8.0

2 files

1.7.0

2 files

1.6.0

2 files

1.5.0

2 files

1.4.0

2 files

1.3.0

2 files

1.2.0

2 files

1.1.5

2 files

1.1.4

2 files

1.1.3

2 files

1.1.2

2 files

1.1.1

2 files

1.1.0

2 files

1.0.1

2 files

1.0.0

2 files

0.3.11

2 files

0.3.10

2 files

0.3.9

2 files

0.3.8

2 files

0.3.7

2 files

0.3.6

2 files

0.3.5

2 files

0.3.4

2 files

0.3.3

2 files

0.3.2

2 files

0.3.1

2 files

0.3.0

2 files

0.2.9

2 files

0.2.8

2 files

0.2.7

2 files

0.2.6

2 files

0.2.5

2 files

0.2.4

2 files

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.1

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page