A reusable OAuth2 token provider and JWT verification dependency for FastAPI microservices with JWKS support.
Project description
# ikon-auth
**ikon-auth** is a reusable authentication and authorization library designed for FastAPI microservices.
It provides an OAuth2 client credentials token generator and JWT verification using JWKS public keys, enabling secure inter-service communication without duplicating authentication logic.
---
## 🚀 Features
- OAuth2 Client Credentials token generation
- JWT validation using JWKS public keys
- FastAPI-ready `verify_token` dependency
- Thread-safe token caching & auto refresh
- Seamless environment configuration using `pydantic-settings`
- Plug-and-play security for microservices architectures
---
## 📦 Installation
```bash
pip install ikon-auth
⚙️ Environment Configuration
Create a .env file in the root of your FastAPI application (not inside the package):
BASE_ISSUER_URL=https://example.com/issuer
OAUTH_CLIENT_ID=my-client-id
OAUTH_CLIENT_SECRET=my-client-secret
These environment values are automatically loaded when you import components from ikon-auth.
🛠 Usage with FastAPI
JWT Verification Dependency
from fastapi import FastAPI, Depends
from ikon_auth import verify_token
app = FastAPI()
@app.get("/secure", dependencies=[Depends(verify_token)])
def secure_route(claims=Depends(verify_token)):
return {"status": "access granted", "claims": claims}
Example Router Usage
from fastapi import APIRouter, Depends
from ikon_auth import verify_token
router = APIRouter(prefix="/items", tags=["Items"])
@router.get("/", dependencies=[Depends(verify_token)])
def list_items():
return {"items": []}
🔐 Generating Access Tokens Programmatically
from ikon_auth import OAuthProvider
provider = OAuthProvider()
token = provider.get_token()
print(token) # Bearer <access_token>
📡 How Verification Works
-
Loads JWKS configuration from:
<BASE_ISSUER_URL>/platform/.well-known/openid-configuration -
Downloads signing public keys (JWKS)
-
Validates signature, issuer, and token expiration
-
Makes verified claims available to your route
🧪 Example Project Structure
my-fastapi-service/
│
├── app/main.py
├── app/routers/
├── .env ← contains environment variables
└── requirements.txt
🎯 Ideal Use Cases
- Internal microservice authentication
- Internal gateway or API management
- Centralized authentication logic for multiple Python services
- Reusable token verification and security layer
🧱 Requirements
| Dependency | Version |
|---|---|
| Python | 3.10+ |
| FastAPI | 0.110+ |
| pydantic-settings | 2.0+ |
| python-jose | 3.3+ |
| cryptography | latest |
📄 License
This project is licensed under the MIT License.
🧠 Contributing
Contributions and improvements are always welcome. Please open an issue or submit a pull request on GitHub.
🌍 Links
| Resource | Link |
|---|---|
| PyPI Package | https://pypi.org/project/ikon-auth |
| Issues | https://github.com/your-org/ikon-auth/issues |
| GitHub Repository | https://github.com/your-org/ikon-auth |
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ikon_auth-0.1.1.tar.gz.
File metadata
- Download URL: ikon_auth-0.1.1.tar.gz
- Upload date:
- Size: 8.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a7be2c602a30055483061da74331baad408ca256e592cbae2263d7bb29154717
|
|
| MD5 |
ee3ce7c791461227de15c76665cdded0
|
|
| BLAKE2b-256 |
36bdbb5701316b41d1d3e4a33f3626acc0e72478bce705d94a49d47bcc05c421
|
File details
Details for the file ikon_auth-0.1.1-py3-none-any.whl.
File metadata
- Download URL: ikon_auth-0.1.1-py3-none-any.whl
- Upload date:
- Size: 7.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6eafe9c7976c9dbaa88b21003cc0b2cd1f99e0ab7e2d6cfd8f89221c25a43922
|
|
| MD5 |
657141f6a7c7f17d66510c2bbe280a4a
|
|
| BLAKE2b-256 |
690a46ee3a2e697f3d594d79553e40a12a51268c228d1d378570a82534db7ede
|