Skip to main content


FastAPI-Azure-auth

Azure AD Authentication for FastAPI apps made easy.

Python version FastAPI Version Package version

Codecov Pre-commit Black mypy isort

🚀 Description

FastAPI is a modern, fast (high-performance), web framework for building APIs with Python, based on standard Python type hints.

At Intility, FastAPI is a popular framework among its developers, with customer-facing and internal services developed entirely on a FastAPI backend.

This package enables our developers (and you 😊) to create features without worrying about authentication and authorization.

Also, we're hiring!

⚡️ Quick start

Azure

Azure docs will be available when create-fastapi-app is developed. In the meantime please use the .NET documentation.

FastAPI

  1. Install this library:
pip install fastapi-azure-auth
# or
poetry add fastapi-azure-auth
  1. Include swagger_ui_oauth2_redirect_url and swagger_ui_init_oauth in your FastAPI app initialization:
app = FastAPI(
    ...
    swagger_ui_oauth2_redirect_url='/oauth2-redirect',
    swagger_ui_init_oauth={
        'usePkceWithAuthorizationCodeGrant': True, 
        'clientId': settings.OPENAPI_CLIENT_ID  # SPA app with grants to your app
    },
)
  1. Ensure you have CORS enabled for your local environment, such as http://localhost:8000. See main.py and the BACKEND_CORS_ORIGINS in config.py

  2. Import and configure your Azure authentication:

from fastapi_azure_auth.auth import AzureAuthorizationCodeBearer

azure_scheme = AzureAuthorizationCodeBearer(
    app=app,
    app_client_id=settings.APP_CLIENT_ID,  # Web app
    scopes={
        f'api://{settings.APP_CLIENT_ID}/user_impersonation': 'User Impersonation',
    },
)
  1. Set your intility_scheme as a dependency for your wanted views/routers:
app.include_router(api_router, prefix=settings.API_V1_STR, dependencies=[Depends(azure_scheme)])

⚙️ Configuration

For those using a non-Intility tenant, you also need to make changes to the provider_config:

from fastapi_azure_auth.provider_config import provider_config

intility_scheme = AzureAuthorizationCodeBearer(
    ...
)

provider_config.tenant_id = 'my-own-tenant-id'

If you want, you can deny guest users to access your API by passing the allow_guest_users=False to AzureAuthorizationCodeBearer:

intility_scheme = AzureAuthorizationCodeBearer(
    ...
    allow_guest_users=False
)

💡 Nice to knows

A User object is attached to the request state if the token is valid. Unparsed claims can be accessed at request.state.user.claims.

from fastapi_azure_auth.user import User
from fastapi import Request

@router.get(...)
async def world(request: Request) -> dict:
    user: User = request.state.user
    return {'user': user}

Metadata

Release files for fastapi-azure-auth 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for fastapi-azure-auth 1.1.0
File Size Uploaded
fastapi-azure-auth-1.1.0.tar.gz 8.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for fastapi-azure-auth 1.1.0
File Interpreter ABI Platform
fastapi_azure_auth-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 16.6 kB

Release files / fastapi-azure-auth-1.1.0.tar.gz

Download URL fastapi-azure-auth-1.1.0.tar.gz
Size 8.2 kB
Tags Source
SHA-256 checksum
How to use checksums
b609ca6dcfa1d2ede8b603bfd56c4528ee5761252b0dcee8235b582e082c7b89
BLAKE2b-256 checksum
How to use checksums
a228db4ea691a562e9f9e05471dddc0d174ffd59d293f5ce6c68e12a8efc073d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.1.7 CPython/3.9.6 Linux/5.8.0-1039-azure

Release files / fastapi_azure_auth-1.1.0-py3-none-any.whl

Download URL fastapi_azure_auth-1.1.0-py3-none-any.whl
Size 8.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c35a95b06bbfc7766aa89cbfba96594ea44bef90712416be990dfd60de1e937c
BLAKE2b-256 checksum
How to use checksums
3ab5cc57f9d80c51e18cf64396b88c87a9732991a7d7b495fc5f5f2f6a9f6685
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.1.7 CPython/3.9.6 Linux/5.8.0-1039-azure
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page