Skip to main content

This is a low-level library for implementing Hawk Access Authentication, a simple HTTP request-signing scheme described in:

https://npmjs.org/package/hawk

To access resources using Hawk Access Authentication, the client must have obtained a set of Hawk credentials including an id and a secret key. They use these credentials to make signed requests to the server.

When accessing a protected resource, the server will generate a 401 challenge response with the scheme “Hawk” as follows:

> GET /protected_resource HTTP/1.1
> Host: example.com

< HTTP/1.1 401 Unauthorized
< WWW-Authenticate: Hawk

The client will use their Hawk credentials to build a request signature and include it in the Authorization header like so:

> GET /protected_resource HTTP/1.1
> Host: example.com
> Authorization: Hawk id="h480djs93hd8",
>                     ts="1336363200",
>                     nonce="dj83hs9s",
>                     mac="bhCQXTVyfj5cmA9uKkPFx1zeOXM="

< HTTP/1.1 200 OK
< Content-Type: text/plain
<
< For your eyes only:  secret data!

This library provices the low-level functions necessary to implement such an authentication scheme. For Hawk Auth clients, it provides the following function:

  • sign_request(req, id, key, algorithm=”sha256”): sign a request using Hawk Access Auth.

For Hawk Auth servers, it provides the following functions:

  • get_id(req): get the claimed Hawk Auth id from the request.

  • check_signature(req, key, algorithm=”sha256”): check that the request was signed with the given key.

The request objects passed to these functions can be any of a variety of common object types:

  • a WSGI environment dict

  • a webob.Request object

  • a requests.Request object

  • a string or file-like object of request data

A typical use for a client program might be to install the sign_request function as an authentication hook when using the requests library, like this:

import requests
import functools
import hawkauthlib

# Hook up sign_request() to be called on every request.
def auth_hook(req):
    hawkauthlib.sign_request(req, id="<AUTH-ID>", key="<AUTH-KEY>")
    return req
session = requests.session(hooks={"pre_request": auth_hook})

# Then use the session as normal, and the auth is applied transparently.
session.get("http://www.secret-data.com/get-my-data")

A typical use for a server program might be to verify requests using a WSGI middleware component, like this:

class HawkAuthMiddleware(object):

    # ...setup code goes here...

    def __call__(self, environ, start_response):

        # Find the identity claimed by the request.
        id = hawkauthlib.get_id(environ)

        # Look up their secret key.
        key = self.SECRET_KEYS[id]

        # If the signature is invalid, error out.
        if not hawkauthlib.check_signature(environ, key):
            start_response("401 Unauthorized",
                           [("WWW-Authenticate", "Hawk")])
            return [""]

        # Otherwise continue to the main application.
        return self.application(environ, start_response)

The following features of the Hawk protocol are not yet supported:

  • Bewits.

  • Timestamp adjustment.

  • Calculating or verifying the server’s response signature.

  • Calculating or verifying payload hashes.

2.0.0 - 2016-01-16

  • Py27, Py35 compatible

0.1.1 - 2013-11-12

  • Let key be any binary string; id must still be ascii.

0.1.0 - 2013-08-19

  • Initial release; this is essentially the macauthlib codebase, ported over to the new Hawk auth specification.

Metadata

Release files for hawkauthlib 2.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hawkauthlib 2.0.0
File Size Uploaded
hawkauthlib-2.0.0.tar.gz 14.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hawkauthlib 2.0.0
File Interpreter ABI Platform
hawkauthlib-2.0.0-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size: 47.3 kB

Release files / hawkauthlib-2.0.0.tar.gz

Download URL hawkauthlib-2.0.0.tar.gz
Size 14.9 kB
Tags Source
SHA-256 checksum
How to use checksums
effd64a2572e3c0d9090b55ad2180b36ad50e7760bea225cb6ce2248f421510d
BLAKE2b-256 checksum
How to use checksums
26b70ec2846e5e2b3591ca867d7b06b67b5242f73bfe6da164b7232b8bffc657
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / hawkauthlib-2.0.0-py2.py3-none-any.whl

Download URL hawkauthlib-2.0.0-py2.py3-none-any.whl
Size 32.4 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
935878d3a75832aa76f78ddee13491f1466cbd69a8e7e4248902763cf9953ba9
BLAKE2b-256 checksum
How to use checksums
53ec23dd5cbd5e950543fdd30d91ddac4f56e395d14316677aa4cb78a029f8e2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

2.0.0 This release

2 release files

0.1.1

1 release file

0.1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page