Skip to main content

Identity library

This Identity library is an authentication/authorization library that:

  • Suitable for apps that are targeting end users on Microsoft identity platform, a.k.a. Microsoft Entra ID (which includes Work or school accounts provisioned through Azure AD, and Personal Microsoft accounts such as Skype, Xbox, Outlook.com).
  • Currently designed for web apps, regardless of which Python web framework you are using.
  • Provides a set of high level API that is built on top of, and easier to be used than Microsoft's MSAL Python library.
  • Written in Python, for Python apps.

DISCLAIMER: The code in this repo is not officially supported by Microsoft and is not intended for production use. The intention of this repo is to unblock customers who would like to use a higher level API, before such an API has been migrated to an Microsoft library with official support. Migration of this API to official support is not guaranteed and is not currently on the MSAL roadmap. Please ensure to fully test any code used from this repository to ensure it works in your environment.

Scenarios supported

Microsoft Entra ID Microsoft Entra External ID Microsoft Entra External ID with Custom Domain Azure AD B2C
App Registration

Following only the step 1, 2 and 3 of this Quickstart: Add sign-in with Microsoft to a Python web app

Follow only the page 1 of this Tutorial: Prepare your customer tenant ...

Coming soon.

Following only the step 1 and 2 (including 2.1 and 2.2) of this Configure authentication in a sample Python web app by using Azure AD B2C

After app registration, you shall obtain the following information:
  • Your app's client_id, also known as application ID. (For example, if you are using Entra ID, you may follow this app registration document).

  • Your app's credential, which can either be a secret string, or a certificate. (For example, if you are using Entra ID, you may follow this app credential document). The Identity library's client_credential parameter supports all formats supported by msal library's same name parameter.

  • Your app's Redirect URI. You may prepare two, one of them looks like http://localhost:5000/redirect for local development, the other looks like https://your_website.com/redirect for your production. (For example, if you are using Entra ID, you may follow this redirect URI document).

Web App Sign In & Sign Out

By using this library, it will automatically renew signed-in session when the ID token expires.

How to customize the login page

The default login page will typically redirect users to your Identity Provider, so you don't have to customize it. But if the default login page is shown in your browser, you can read its HTML source code, and find the how-to instructions there.

Web App Calls a web API

This library supports:

  • Incremental consent. If the user needs to consent to more permissions, the library will automatically redirect the user to the consent page.
  • Automatically cache the access token and renew it when needed

They are demonstrated by the same samples above.

Web API Calls another web API (On-behalf-of)

In roadmap.

How to build the samples above from scratch

Read our docs here

Other scenarios

Upvote existing feature request or create a new one

Installation

This package is available on PyPI. Choose the package declaration that matches your web framework:

Note: Make sure you put "identity[...]" in quotes to ensure it works in all terminals.

  • Django: pip install "identity[django]"
  • Flask: pip install "identity[flask]"
  • Quart: pip install "identity[quart]"

Versions

This library follows Semantic Versioning. Your project should declare identity dependency with proper lower and upper bound.

You can find the changes for each version under Releases.

Release files for identity 0.11.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for identity 0.11.0
File Size Uploaded
identity-0.11.0.tar.gz 24.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for identity 0.11.0
File Interpreter ABI Platform
identity-0.11.0-py3-none-any.whl Python 3 none any Details

Total release size: 50.5 kB

Release files / identity-0.11.0.tar.gz

Download URL identity-0.11.0.tar.gz
Size 24.6 kB
Tags Source
SHA-256 checksum
How to use checksums
d6900bd918dff0a6253941eb667cbb725a8123e8fa214d555862858fa094cd05
BLAKE2b-256 checksum
How to use checksums
535ceffb7524717d1ae0f56c7d79b69a67c57b507377ead7b531b4048f095ca6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 7, 2025.

Transparency log

Release files / identity-0.11.0-py3-none-any.whl

Download URL identity-0.11.0-py3-none-any.whl
Size 25.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6d6917effa94db96ce14fec7e8d8f3d5a4aad0c6db7a02d5310b27b1a5f02a0b
BLAKE2b-256 checksum
How to use checksums
491b4a8c6392ff44e4c7382b7b6a3fbe2ea1b79c548c118f644ca14f7b7011cd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 7, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.11.0 This release

2 release files

0.10.0

2 release files

0.9.2

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page