Skip to main content

Python Fernet Web Token

Library to produce and validate signed, encrypted tokens (via Fernet), to make them suitable for carrying confidential state over an unprotected channel.

Intended as a replacement for the JWT series of protocols.

Advantages compared to JWT

  • Encryption support, allowing tokens to contain confidential data without exposing it to the user
  • Tokens are encoded using a binary format, which is more concise than JSON
  • Tokens do not carry (unverified) information about the encryption algorithm used, eliminating an entire class of vulnerabilities

Supported features

  • Validity start date: tokens will not be accepted before this date
  • Expiration date: tokens will no longer be accepted after this date
  • Token type, to distinguish between different classes of token issued using the same shared key
  • Token payload can be binary data, a utf8 string, or JSON data, with support for user-extensible formats

Usage example

import fwt

tf = fwt.Authority(key=b'...', token_type='Authentication')

# Create a token containing some JSON data
token = tf.encode({"user_id": 12345})

# Or binary data
token = tf.encode(b"\x00\x00\x00\x00\x00\x0009")

# Create a token with an expiration date
token = tf.encode({...}, expire_after=3600)
token = tf.encode({...}, expire_at=datetime(2030, 1, 1))

# Decode payload data from a token
data = tf.decode_payload(token)

# Or if extra information is needed
token_info = tf.decode(token)
token_info.payload  # the original data
token_info.token_id  # for example...

Token binary format

Token data is encoded using a binary format. All numbers are stored in big-endian order.

The first byte contains a bitmask (four lower bits) to indicate the presence of the optional fields (in order, lsb first), while the upper four bits encode the payload type.

Following are a series of optional fields, as described below.

Optional fields

  • Validity start date: unix timestamp as an unsigned 64-bit integer
  • Expiration date: unix timestamp as an unsigned 64-bit integer
  • Token type: utf8 string, prefixed with a 8-bit integer indicating the encoded length
  • Token ID: utf8 string, prefixed with a 8-bit integer indicating the encoded length
  • Payload data: if the payload type is not 0, the payload is encoded as a 2-byte number indicating the encoded size, followed by that amount of bytes

Payload types

  • 0: empty
  • 1: binary data
  • 2: utf8 encoded string
  • 3: JSON encoded data
  • 4-7: reserved
  • 8-15: application specific usage

Metadata

Release files for fwt 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for fwt 1.0.0
File Size Uploaded
fwt-1.0.0.tar.gz 6.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for fwt 1.0.0
File Interpreter ABI Platform
fwt-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 12.3 kB

Release files / fwt-1.0.0.tar.gz

Download URL fwt-1.0.0.tar.gz
Size 6.6 kB
Tags Source
SHA-256 checksum
How to use checksums
7e76286a761d0611cf0ecb6bf88839be537bedc4513bf84f9ab17376910833c6
BLAKE2b-256 checksum
How to use checksums
598e114ca9fd261c0989a23ecec79045c5ca13fba4f4669df4092f9e9c9961d4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.8.15

Release files / fwt-1.0.0-py3-none-any.whl

Download URL fwt-1.0.0-py3-none-any.whl
Size 5.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6484f9a26e276e6b34e3f2cd3197b7b11c7486ff4b56206aa3798914cd10d044
BLAKE2b-256 checksum
How to use checksums
3fa5adc24cd22f442d506413abb928fb0f89f8f042ef67148dabc37f2125b50f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.8.15

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page