Skip to main content

A reusable OAuth2 token provider and JWT verification dependency for FastAPI microservices with JWKS support.

Project description

# ikon-auth

**ikon-auth** is a reusable authentication and authorization library designed for FastAPI microservices.  
It provides an OAuth2 client credentials token generator and JWT verification using JWKS public keys, enabling secure inter-service communication without duplicating authentication logic.

---

## 🚀 Features

- OAuth2 Client Credentials token generation
- JWT validation using JWKS public keys
- FastAPI-ready `verify_token` dependency
- Thread-safe token caching & auto refresh
- Seamless environment configuration using `pydantic-settings`
- Plug-and-play security for microservices architectures

---

## 📦 Installation

```bash
pip install ikon-auth

⚙️ Environment Configuration

Create a .env file in the root of your FastAPI application (not inside the package):

BASE_ISSUER_URL=https://example.com/issuer
OAUTH_CLIENT_ID=my-client-id
OAUTH_CLIENT_SECRET=my-client-secret

These environment values are automatically loaded when you import components from ikon-auth.


🛠 Usage with FastAPI

JWT Verification Dependency

from fastapi import FastAPI, Depends
from ikon_auth import verify_token

app = FastAPI()

@app.get("/secure", dependencies=[Depends(verify_token)])
def secure_route(claims=Depends(verify_token)):
    return {"status": "access granted", "claims": claims}

Example Router Usage

from fastapi import APIRouter, Depends
from ikon_auth import verify_token

router = APIRouter(prefix="/items", tags=["Items"])

@router.get("/", dependencies=[Depends(verify_token)])
def list_items():
    return {"items": []}

🔐 Generating Access Tokens Programmatically

from ikon_auth import OAuthProvider

provider = OAuthProvider()
token = provider.get_token()
print(token)  # Bearer <access_token>

📡 How Verification Works

  1. Loads JWKS configuration from:

    <BASE_ISSUER_URL>/platform/.well-known/openid-configuration
    
  2. Downloads signing public keys (JWKS)

  3. Validates signature, issuer, and token expiration

  4. Makes verified claims available to your route


🧪 Example Project Structure

my-fastapi-service/
│
├── app/main.py
├── app/routers/
├── .env   ← contains environment variables
└── requirements.txt

🎯 Ideal Use Cases

  • Internal microservice authentication
  • Internal gateway or API management
  • Centralized authentication logic for multiple Python services
  • Reusable token verification and security layer

🧱 Requirements

Dependency Version
Python 3.10+
FastAPI 0.110+
pydantic-settings 2.0+
python-jose 3.3+
cryptography latest

📄 License

This project is licensed under the MIT License.


🧠 Contributing

Contributions and improvements are always welcome. Please open an issue or submit a pull request on GitHub.


🌍 Links

Resource Link
PyPI Package https://pypi.org/project/ikon-auth
Issues https://github.com/your-org/ikon-auth/issues
GitHub Repository https://github.com/your-org/ikon-auth

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ikon_auth-0.1.2.tar.gz (8.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ikon_auth-0.1.2-py3-none-any.whl (7.6 kB view details)

Uploaded Python 3

File details

Details for the file ikon_auth-0.1.2.tar.gz.

File metadata

  • Download URL: ikon_auth-0.1.2.tar.gz
  • Upload date:
  • Size: 8.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for ikon_auth-0.1.2.tar.gz
Algorithm Hash digest
SHA256 0243416683aadb444fecf24996d885cbd7b1007ad52b38c0c48c7310b7499263
MD5 fb480800bda095085876145078bbab1d
BLAKE2b-256 64deb18ad572c4dfacd6ec8bd1dc74295b110baf86ac9bbab6693790a34210f8

See more details on using hashes here.

File details

Details for the file ikon_auth-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: ikon_auth-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 7.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for ikon_auth-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 8c2362aaf69a2ca0393220116dc665cb078e9c866c318e27f66ca38f6e85c6c7
MD5 b777a7b71625b040044c268f809051d9
BLAKE2b-256 ca4d339bfee33a9510ba0b820478b418d7bae0c55c12177d689a28677dad39f3

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page