Skip to main content

[Build Status PyPI version

jwt_authenticator

jwt_authenticator is a simply python library for adding JWT token authentication/authorization in flask web sites/services. It controls access either by checking for just a validated token, or optionally, a single role claim from the token. Access is controlled by decorating the endpoint functions with an attribute.

Installation

Use the package manager pip to install jwt_authenticator.

pip install jwt-authenticator

If using RS256, you must also:

pip install cryptography

Usage

In the main application initialization area

from flask import Flask
from jwt_authenticator import AuthenticationHandler

APP = Flask(__name__)
AuthenticationHandler.load_configuration(APP)

In the endpoints

from jwt_authenticator import AuthenticationHandler, AuthError

@api.route('/<name>', methods=['GET'])
@AuthenticationHandler.requires_auth("admin")
def get_one(name):
    return f"Hello {name}"

@api.route('/<name>', methods=['GET'])
@AuthenticationHandler.requires_auth()
def get_one(name):
    return f"Hello {name}"

Configuration

jwt_authenticator requires two configuration values to work. These can be specified either in the normal Flask application configuration or as environment variables. Environment variable values will override application configuration values, when

AuthenticationHanlder.load_configuration(app)

is called.

APP.config (i.e. flask application configuration)

  • SECRET - the key used to sign the JWT token. Option if JWKS_URL specified.
  • AUDIENCE - the audience claim used in the JWT token
  • JKWS_URL - [OPTIONAL] OIDC key discovery URL
  • GROUPS_CLAIM - [OPTIONAL] which claim has the list of groups. Defaults to "groups"

Environment Variables

  • JWT_SECRET - will override SECRET
  • JWT_AUDIENCE - will override AUDIENCE
  • JWKS_URL - will override JWKS_URL
  • GROUPS_CLAIM - will override GROUPS_CLAIM

Contributing

Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.

Please make sure to update tests as appropriate.

Building

  • Requires 'make'
make init
make test
make package

License

MIT

Release files for jwt-authenticator 1.11.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for jwt-authenticator 1.11.4
File Size Uploaded
jwt_authenticator-1.11.4.tar.gz 39.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for jwt-authenticator 1.11.4
File Interpreter ABI Platform
jwt_authenticator-1.11.4-py3-none-any.whl Python 3 none any Details

Total release size: 45.7 kB

Release files / jwt_authenticator-1.11.4.tar.gz

Download URL jwt_authenticator-1.11.4.tar.gz
Size 39.7 kB
Tags Source
SHA-256 checksum
How to use checksums
5ee6f744546e28511a1522f0368c9447f96f8d995c1c5600eab89e9a557b9049
BLAKE2b-256 checksum
How to use checksums
1362fb711fc9f78cc1558f4ddb431ac4098439eabeb0dbb358bd34754b945109
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.0.1 CPython/3.12.8

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 21, 2025.

Transparency log

Release files / jwt_authenticator-1.11.4-py3-none-any.whl

Download URL jwt_authenticator-1.11.4-py3-none-any.whl
Size 6.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6c228eff99731ff69722043652203adfe7a06e4dfd77d841d92d59d4a9160c47
BLAKE2b-256 checksum
How to use checksums
6d811c29b909a666a9ed7a50736816e4786808e35e6085009a4f6d4b5284a081
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.0.1 CPython/3.12.8

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 21, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

1.11.4 This release

2 release files

1.11.3

2 release files

1.11.2

2 release files

1.11.1

2 release files

1.11.0

2 release files

1.0.8

2 release files

1.0.6

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page