FastAPI Auth 🔐
Production-ready authentication system for FastAPI with async support, JWT, refresh tokens, and pluggable database backends.
🚀 Features
-
⚡ Fully async (no blocking I/O)
-
🔐 JWT authentication (access + refresh tokens)
-
🔁 Refresh token flow
-
🚪 Logout with token blacklist
-
🧱 Multi-database support:
- PostgreSQL (asyncpg)
- MySQL (aiomysql)
- SQLite (aiosqlite)
- MongoDB (motor)
-
🧠 Dependency-based auth (FastAPI native)
-
📦 Plug-and-play integration
-
🛡️ Password hashing with Argon2 (modern standard)
-
📄 Clean OpenAPI (Swagger) docs with Pydantic schemas
📦 Installation
pip install "fastapi-async-auth-kit[<db>]"
With database support
pip install "fastapi-async-auth-kit[postgres]"
pip install "fastapi-async-auth-kit[mysql]"
pip install "fastapi-async-auth-kit[mongodb]"
pip install "fastapi-async-auth-kit[sqlite]"
⚙️ Quick Start
Step 1: How to initiate auth on startup
from fastapi import FastAPI
from fastapi_async_auth_kit import init_auth, AuthConfig
app = FastAPI()
@app.on_event("startup")
# for postgres
async def startup():
await init_auth(
app,
AuthConfig(
secret_key="your-secret",
db_url="postgresql+asyncpg://user:pass@localhost/fastapi_auth",
db_type="postgres"
)
)
# for mysql
async def startup():
await init_auth(
app,
AuthConfig(
secret_key="secret",
db_url="mysql+aiomysql://admin:Admin123@localhost:3306/fastapi_auth",
db_type="mysql"
)
)
# for sqlite
async def startup():
await init_auth(
app,
AuthConfig(
secret_key="my-secret-key",
db_url="sqlite+aiosqlite:///./fastapi_auth.db",
db_type="sqlite"
)
)
# for mongo db
async def startup():
await init_auth(
app,
AuthConfig(
secret_key="super-secret-key",
db_url="mongodb://localhost:27017/fastapi_auth",
db_type="mongodb"
)
)
Step 2: How to validate token for all your FastAPIs
from fastapi import APIRouter, Depends
from fastapi_async_auth_kit.dependencies.auth import get_current_user
router = APIRouter()
@router.get("/user")
async def me(user=Depends(get_current_user)):
return user
🔐 Available Endpoints
| Endpoint | Description |
|---|---|
| POST /auth/register | Register new user |
| POST /auth/login | Login and get tokens |
| POST /auth/refresh | Refresh access token |
| POST /auth/logout | Logout and revoke token |
| GET /auth/me | Get current user |
🧪 Example
Login
POST /auth/login
{
"username": "john",
"password": "Strong@123"
}
Response
{
"access": "jwt_token",
"refresh": "refresh_token"
}
🧠 Architecture
FastAPI App
↓
Auth Service
↓
Repository Layer
↓
Database (Async)
🛡️ Security
- Argon2 password hashing
- JWT token expiration
- Refresh token blacklist
- No sensitive data exposure
- Clean error handling
🧩 Extensibility
- Add RBAC (roles & permissions)
- Plug custom user models
- Add OAuth providers (Google, GitHub)
- Integrate Redis for token storage
🛠 Tech Stack
- FastAPI
- SQLAlchemy (async)
- Pydantic
- python-jose (JWT)
- Argon2 (password hashing)
📌 Roadmap
- RBAC support
- Redis token blacklist
- OAuth integration
- Rate limiting
- Email verification
🤝 Contributing
Pull requests are welcome. For major changes, open an issue first.
Source Code: https://github.com/kmistry1110/fastapi_auth
📄 License
MIT License
Metadata
Release files for fastapi-async-auth-kit 0.11.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fastapi_async_auth_kit-0.11.0.tar.gz | 9.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| fastapi_async_auth_kit-0.11.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 20.4 kB
Release files / fastapi_async_auth_kit-0.11.0.tar.gz
| Download URL | fastapi_async_auth_kit-0.11.0.tar.gz |
|---|---|
| Size | 9.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
00e23cb7af443db71d4c96a83168af6b5413a08dbd306d85fc2881c4dfc83735
|
|
BLAKE2b-256 checksum How to use checksums |
4cddd69985613c2323895b169870382f52d52100164d6f1a9a727b2b0c7d6a62
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.11.15
|
Release files / fastapi_async_auth_kit-0.11.0-py3-none-any.whl
| Download URL | fastapi_async_auth_kit-0.11.0-py3-none-any.whl |
|---|---|
| Size | 10.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
653deb440a6413e483ea5b8e23c0299f745e6c27b322ea21a9742f3298b3f868
|
|
BLAKE2b-256 checksum How to use checksums |
97b10e0f7714e76a864e6307fe7ba4279efa4169eb492c2819851a0094fbcf56
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.11.15
|