Skip to main content

A reusable OAuth2 token provider and JWT verification dependency for FastAPI microservices with JWKS support.

Project description

# ikon-auth

**ikon-auth** is a reusable authentication and authorization library designed for FastAPI microservices.  
It provides an OAuth2 client credentials token generator and JWT verification using JWKS public keys, enabling secure inter-service communication without duplicating authentication logic.

---

## 🚀 Features

- OAuth2 Client Credentials token generation
- JWT validation using JWKS public keys
- FastAPI-ready `verify_token` dependency
- Thread-safe token caching & auto refresh
- Seamless environment configuration using `pydantic-settings`
- Plug-and-play security for microservices architectures

---

## 📦 Installation

```bash
pip install ikon-auth

⚙️ Environment Configuration

Create a .env file in the root of your FastAPI application (not inside the package):

BASE_ISSUER_URL=https://example.com/issuer
OAUTH_CLIENT_ID=my-client-id
OAUTH_CLIENT_SECRET=my-client-secret

These environment values are automatically loaded when you import components from ikon-auth.


🛠 Usage with FastAPI

JWT Verification Dependency

from fastapi import FastAPI, Depends
from ikon_auth import verify_token

app = FastAPI()

@app.get("/secure", dependencies=[Depends(verify_token)])
def secure_route(claims=Depends(verify_token)):
    return {"status": "access granted", "claims": claims}

Example Router Usage

from fastapi import APIRouter, Depends
from ikon_auth import verify_token

router = APIRouter(prefix="/items", tags=["Items"])

@router.get("/", dependencies=[Depends(verify_token)])
def list_items():
    return {"items": []}

🔐 Generating Access Tokens Programmatically

from ikon_auth import OAuthProvider

provider = OAuthProvider()
token = provider.get_token()
print(token)  # Bearer <access_token>

📡 How Verification Works

  1. Loads JWKS configuration from:

    <BASE_ISSUER_URL>/platform/.well-known/openid-configuration
    
  2. Downloads signing public keys (JWKS)

  3. Validates signature, issuer, and token expiration

  4. Makes verified claims available to your route


🧪 Example Project Structure

my-fastapi-service/
│
├── app/main.py
├── app/routers/
├── .env   ← contains environment variables
└── requirements.txt

🎯 Ideal Use Cases

  • Internal microservice authentication
  • Internal gateway or API management
  • Centralized authentication logic for multiple Python services
  • Reusable token verification and security layer

🧱 Requirements

Dependency Version
Python 3.10+
FastAPI 0.110+
pydantic-settings 2.0+
python-jose 3.3+
cryptography latest

📄 License

This project is licensed under the MIT License.


🧠 Contributing

Contributions and improvements are always welcome. Please open an issue or submit a pull request on GitHub.


🌍 Links

Resource Link
PyPI Package https://pypi.org/project/ikon-auth
Issues https://github.com/your-org/ikon-auth/issues
GitHub Repository https://github.com/your-org/ikon-auth

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ikon_auth-0.1.4.tar.gz (8.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ikon_auth-0.1.4-py3-none-any.whl (7.6 kB view details)

Uploaded Python 3

File details

Details for the file ikon_auth-0.1.4.tar.gz.

File metadata

  • Download URL: ikon_auth-0.1.4.tar.gz
  • Upload date:
  • Size: 8.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for ikon_auth-0.1.4.tar.gz
Algorithm Hash digest
SHA256 265bc903a457d5b802ee9f2cd1b046c84fb8b113d3dde83de8b1f652c00733f7
MD5 9c469709820c519fb183eb4aa74a3f8d
BLAKE2b-256 659c0cd09ff15765e03a92f4756e7b48a9f09cf1ab010b4a11ab2dc4f9993edb

See more details on using hashes here.

File details

Details for the file ikon_auth-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: ikon_auth-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 7.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for ikon_auth-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 38325e9e0c49b58dd2e5731fa22e5c59a871ce9126dc7442c9476639029ec374
MD5 9f6c2f7dc359e89b2a5d10ba425fba80
BLAKE2b-256 70e2b66972fa8b695d39ce362dd3ecc94c819a6f4e67972fd18aebd567f261a9

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page