jwt_authenticator
jwt_authenticator is a simply python library for adding JWT token authentication/authorization in flask web sites/services. It controls access either by checking for just a validated token, or optionally, a single role claim from the token. Access is controlled by decorating the endpoint functions with an attribute.
Installation
Use the package manager pip to install jwt_authenticator.
pip install jwt-authenticator
If using RS256, you must also:
pip install cryptography
Usage
In the main application initialization area
from flask import Flask
from jwt_authenticator import AuthenticationHandler
APP = Flask(__name__)
AuthenticationHandler.load_configuration(APP)
In the endpoints
from jwt_authenticator import AuthenticationHandler, AuthError
@api.route('/<name>', methods=['GET'])
@AuthenticationHandler.requires_auth("admin")
def get_one(name):
return f"Hello {name}"
@api.route('/<name>', methods=['GET'])
@AuthenticationHandler.requires_auth()
def get_one(name):
return f"Hello {name}"
Configuration
jwt_authenticator requires two configuration values to work. These can be specified either in the normal Flask application configuration or as environment variables. Environment variable values will override application configuration values, when
AuthenticationHanlder.load_configuration(app)
is called.
APP.config (i.e. flask application configuration)
- SECRET - the key used to sign the JWT token. Option if JWKS_URL specified.
- AUDIENCE - the audience claim used in the JWT token
- JKWS_URL - [OPTIONAL] OIDC key discovery URL
- GROUPS_CLAIM - [OPTIONAL] which claim has the list of groups. Defaults to "groups"
Environment Variables
- JWT_SECRET - will override SECRET
- JWT_AUDIENCE - will override AUDIENCE
- JWKS_URL - will override JWKS_URL
- GROUPS_CLAIM - will override GROUPS_CLAIM
Contributing
Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.
Please make sure to update tests as appropriate.
Building
- Requires 'make'
make init
make test
make package
License
Release files for jwt-authenticator 1.11.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| jwt_authenticator-1.11.4.tar.gz | 39.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| jwt_authenticator-1.11.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 45.7 kB
Release files / jwt_authenticator-1.11.4.tar.gz
| Download URL | jwt_authenticator-1.11.4.tar.gz |
|---|---|
| Size | 39.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5ee6f744546e28511a1522f0368c9447f96f8d995c1c5600eab89e9a557b9049
|
|
BLAKE2b-256 checksum How to use checksums |
1362fb711fc9f78cc1558f4ddb431ac4098439eabeb0dbb358bd34754b945109
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.0.1 CPython/3.12.8
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 21, 2025.
Transparency logRelease files / jwt_authenticator-1.11.4-py3-none-any.whl
| Download URL | jwt_authenticator-1.11.4-py3-none-any.whl |
|---|---|
| Size | 6.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6c228eff99731ff69722043652203adfe7a06e4dfd77d841d92d59d4a9160c47
|
|
BLAKE2b-256 checksum How to use checksums |
6d811c29b909a666a9ed7a50736816e4786808e35e6085009a4f6d4b5284a081
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.0.1 CPython/3.12.8
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 21, 2025.
Transparency log