Skip to main content

fastapi-cognito-security

A micro-library that implements a FastAPI security class for AWS Cognito security.

This library supports receiving the Cogntio access (recommended) or id token in the HTTP Authorization header using the standard Bearer mechansism (e.g. - Authorization: Bearer <token>).

Installation

pip install fastapi-cognito-security

Usage

Securing an individual route

from fastapi import Depends, FastAPI
from fastapi_cognito_security import CognitoBearer

app = FastAPI()
auth = CognitoBearer(
    app_client_id="my_app_client_id",
    userpool_id="my_userpool_id"
)

@app.get("/", dependencies=[Depends(auth)])
async def root():
    return {"message": "Hello World"}

Securing a whole api

from fastapi import Depends, FastAPI
from fastapi_cognito_security import CognitoBearer

auth = CognitoBearer(
    app_client_id="my_app_client_id",
    userpool_id="my_userpool_id"
)
app = FastAPI(dependencies=[Depends(auth)])

@app.get("/")
async def root():
    return {"message": "Hello World"}

When called, the CognitoBearer object will:

  1. Get the public keys from your AWS Cognito UserPool.

    NOTE - this will only happen once, and will be cached thereafter.

  2. Validate the JWT by verifying:
    1. The JWT is correctly constructed and conforms to the public key.
    2. The JWT has not expired.
    3. The client_id (access token) or aud (id token) matches the app_client_id.
  3. Return either a fastapi_cognito_security.AccessToken or fastapi_cognito_security.IdToken that contains the claims.

    NOTE - you can use these claims for further verification either within your API or by subclassing CognitoBearer.

Any failure in the above steps will result in a fastapi.HTTPException being raised.

Claims

The returned AccessToken or IdToken will have the standard Cognito claims converted to Python types.

AccessToken and IdToken

Claim Python Type
auth_time datetime.datetime
exp datetime.datetime
iat datetime.datetime
iss pydantic.HttpUrl
jti uuid.UUID
origin_jti uuid.UUID
sub uuid.UUID
  • Username (username in access tokens and cognito:username in id tokens) is canonicalized to the claim username.
  • All additional claims will be converted directly to basic Python types.
  • All claim names will have : replaced with _ (e.g. - custom:thing will become custom_thing)

AccessToken only

Claim Python Type
device_key uuid.UUID
scope list[str]

Swagger/OpenAPI 3.0 Support

Because CognitoBearer is a fastapi.HTTPBearer, it will operate in the docs that are auotmatically generated by FastAPI in the same way as it's parent class.

Metadata

Release files for fastapi-cognito-security 0.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for fastapi-cognito-security 0.0.2
File Size Uploaded
fastapi-cognito-security-0.0.2.tar.gz 7.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for fastapi-cognito-security 0.0.2
File Interpreter ABI Platform
fastapi_cognito_security-0.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 15.4 kB

Release files / fastapi-cognito-security-0.0.2.tar.gz

Download URL fastapi-cognito-security-0.0.2.tar.gz
Size 7.5 kB
Tags Source
SHA-256 checksum
How to use checksums
f288bd0da53778256763a8200660646f58173201bcf0f440bf84417bee052e9b
BLAKE2b-256 checksum
How to use checksums
5adfabfcbaae6014eb0deba523e06ef04537561d6b1f1b89de104175cf8e366c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.0 CPython/3.9.12

Release files / fastapi_cognito_security-0.0.2-py3-none-any.whl

Download URL fastapi_cognito_security-0.0.2-py3-none-any.whl
Size 7.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a2cd7bd27e18ad632c2cb339f6690d8d3055b5d7754fb99f2c31042574750a7e
BLAKE2b-256 checksum
How to use checksums
fe2a0ddb4ac4e3e96f4896bfffb0ee919e8d5f3d671a4e5ce9e5f75fdcc8e298
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.0 CPython/3.9.12

Release history Release notifications | RSS feed

This release

0.0.2 This release

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page