Skip to main content

Python client for Endevre ID authentication flows

Project description

Endevre ID Python Client

A Python helper library for interacting with Endevre ID authentication services. It mirrors the core workflows of the browser client with a server-friendly API.

Features

  • Build secure login URLs for Endevre ID SSO flows.
  • Exchange authorization codes for tokens (optionally requesting JWTs).
  • Refresh access tokens using stored refresh tokens.
  • Retrieve user information from tokens or the Endevre ID API.
  • Optional JWT validation backed by the public signing key.
  • Standards-based OIDC access-token validation from discovery and rotating JWKS.
  • Explicit legacy, dual, and oidc migration modes with no silent downgrade.

Installation

pip install endevre-id-client

Quick start

from endevre_id_client import EndevreClient

client = EndevreClient(
    client_id="<your client id>",
    client_secret="<your client secret>",
)

login_url = client.getLoginUrl(
    final_redirect_uri="https://app.example.com/auth/callback",
    redirect_uris=["https://app.example.com/start"],
)

# After your user completes the flow and you receive the `code`
exchange_result = client.exchange(code)
user_info = client.getUserInfo(exchange_result.token)
refreshed = client.refreshToken(exchange_result.refresh)

OIDC resource-server validation

OIDC support is additive. Existing construction remains in legacy mode by default. A resource server can opt into OIDC without changing the application user identifier:

from endevre_id_client import EndevreClient

client = EndevreClient(
    client_id="<your client id>",
    protocol="oidc",
    oidc_issuer="https://id.endevre.com",
)

claims = client.validateToken(bearer_token)
application_user_id = claims["sub"]
assert claims["userId"] == application_user_id

The OIDC sub is the same client-specific identifier issued by the legacy Endevre flow. userId is included as a compatibility alias. Validation requires an at+jwt RS256 access token and verifies its signature, issuer, audience, expiry, client_id, jti, and required claims. Discovery is cached for one hour and JWKS for five minutes by default; an unknown key ID or signature change triggers one bounded refresh so signing-key rotation does not require an application deployment.

During a staged migration, configure protocol="dual" and retain the client secret:

client = EndevreClient(
    client_id="<your client id>",
    client_secret="<your legacy client secret>",
    protocol="dual",
    oidc_issuer="https://id.endevre.com",
)

Dual mode routes tokens by their signed-token shape and exact issuer. An OIDC validation error never falls back to legacy validation. Legacy is still the default only for compatibility while consumers migrate.

For Worker 3 qualification, change only the explicit issuer:

client = EndevreClient(
    client_id="<your development client id>",
    protocol="oidc",
    oidc_issuer="https://worker3.id.endevre.com",
)

getUserInfo() validates OIDC locally first and then calls the discovered UserInfo endpoint. It rejects a UserInfo response whose sub differs from the validated access token.

Deliberate API boundary

This release adds resource-server validation; it does not add a second authorization-code client implementation. In oidc mode, the legacy getLoginUrl(), exchange(), and refreshToken() methods fail closed. Web applications should use the Endevre JavaScript SDK or another conformant OIDC relying-party library for the browser authorization-code flow. In legacy and dual modes those existing methods keep their current behavior during the migration window.

Publishing

Automated publishing mirrors the JavaScript package strategy:

  • Pushes to main publish the version defined in pyproject.toml as the stable release.
  • Pushes to beta publish a time-stamped beta pre-release (e.g. 0.1.0b20241006123000).
  • Pushes to dev publish a time-stamped development build (e.g. 0.1.0.dev20241006123000).
  • Pushes to justin* / ray* branches run tests only (no publish).

All workflows live under .github/workflows/python-ci-cd.yml and rely on the PYPI_API_TOKEN secret (or PyPI Trusted Publisher configuration) for auth.

Development

Install dev dependencies:

pip install -e .[dev]

Run the test suite:

pytest

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

endevre_id_client-0.1.1.dev20260727054833.tar.gz (17.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file endevre_id_client-0.1.1.dev20260727054833.tar.gz.

File metadata

File hashes

Hashes for endevre_id_client-0.1.1.dev20260727054833.tar.gz
Algorithm Hash digest
SHA256 7d4484ba22527d50fe495d49f8c9dfd5ee09d33b3ec0089c49d905d36a06775c
MD5 5248bfbd6a66e6d3912f6f1ee1e6b59c
BLAKE2b-256 ff70e1f86c68313dda8568dcae42616853fb7e0fa438739be74ad476239383c3

See more details on using hashes here.

Provenance

The following attestation bundles were made for endevre_id_client-0.1.1.dev20260727054833.tar.gz:

Publisher: python-ci-cd.yml on endevre/endevre-id-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file endevre_id_client-0.1.1.dev20260727054833-py3-none-any.whl.

File metadata

File hashes

Hashes for endevre_id_client-0.1.1.dev20260727054833-py3-none-any.whl
Algorithm Hash digest
SHA256 64eb6abb1f22099dd6e08b9aac09f1ef4882233d86f4f0fdf6af35e112b72c76
MD5 904620733a7546007c0115b43e41b5cd
BLAKE2b-256 6d6a6926049b8350485858674f53ca7054fd7aeb233c23ec8f8a5b6e258b3ebb

See more details on using hashes here.

Provenance

The following attestation bundles were made for endevre_id_client-0.1.1.dev20260727054833-py3-none-any.whl:

Publisher: python-ci-cd.yml on endevre/endevre-id-client-python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page