Skip to main content

litestar-auth keeps opaque human sessions and sender-constrained workload identity on separate fail-closed trust paths

Tests Codecov coverage Latest stable release on PyPI Supported Python versions MIT license

litestar-auth 8 is the human-authentication layer in the six-distribution AuthWeave workspace for Python 3.12–3.14. Browser sessions and machine credentials stay on separate trust paths while sharing typed, fail-closed AuthWeave decisions.

uv add litestar-auth

Six packages, one version

  • litestar-auth — Litestar registration, login, OAuth + PKCE, TOTP, roles, organizations, and opaque database or Redis sessions
  • authweave-core — Typed principals, evidence, decisions, route policies, and fail-closed provider coordination
  • authweave-workload — X.509 lifecycle plus mTLS, DPoP, SPIFFE, bound JWT, and introspection profiles
  • authweave-otel — API-only security spans and metrics without an SDK or exporter
  • authweave-webhooks — Ed25519 Standard Webhooks integrity, replay control, and bounded delivery
  • authweave-http-signatures — RFC 9530/RFC 9421 payment-message integrity after machine authentication

Install only the layer you need. All six distributions use one exact lockstep version; dependency direction stays one-way (authweave-core at the root). Details: architecture.

Start with a secure human session

uv add litestar-auth aiosqlite
from litestar import Litestar
from litestar_auth import DatabaseTokenAuthConfig, LitestarAuth, LitestarAuthConfig

config = LitestarAuthConfig(
    database_token_auth=DatabaseTokenAuthConfig(
        token_hash_secret=session_digest_secret,
    ),
    csrf_secret=csrf_secret,
    session_maker=session_maker,
    user_model=User,
    user_manager_class=UserManager,
    user_db_factory=user_db_factory,
    user_manager_security=user_manager_security,
)

app = Litestar(plugins=[LitestarAuth(config)])

Opaque sessions are not challenge JWTs and not workload credentials. Read credentials and tokens and the quickstart.

Keep machine identity on its own path

uv add 'authweave-workload[mtls,jwt,sqlalchemy]'
# Add [litestar] only for the Extension SDK v2 integration.

Bound tokens or proofs must match the verified certificate or DPoP key. Ambiguous credential ownership fails closed. See the security posture.

Security boundary

[!IMPORTANT] Authentication establishes a verified principal and constraints. Your application still owns tenant mapping, row-level security, resource ownership, and business authorization.

AuthWeave intentionally does not provide unconstrained bearer login, user-owned API keys, shared-secret machine credentials, an OAuth Authorization Server or STS, or generic IAM.

Release evidence

CI exercises Python 3.12–3.14 on Linux, macOS, and Windows with a 100% branch-coverage gate per distribution, CodeQL, dependency review, pinned actions, CycloneDX 1.7 SBOMs, and reference stacks. That evidence is library readiness, not certification of a deployment.

Documentation

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

litestar_auth-8.0.2.tar.gz (333.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

litestar_auth-8.0.2-py3-none-any.whl (469.1 kB view details)

Uploaded Python 3

File details

Details for the file litestar_auth-8.0.2.tar.gz.

File metadata

  • Download URL: litestar_auth-8.0.2.tar.gz
  • Upload date:
  • Size: 333.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for litestar_auth-8.0.2.tar.gz
Algorithm Hash digest
SHA256 ce1ff7ff096522f0cd1a82c957eafecb9c300efa1afea756631e6652a6400064
MD5 e823ad090cc88ab437139064a8a168f2
BLAKE2b-256 cae6dba850cce16bb8c246f713f9f95849f1ab6fc89fe1a9cd043fca478d9e39

See more details on using hashes here.

Provenance

The following attestation bundles were made for litestar_auth-8.0.2.tar.gz:

Publisher: 3_release.yml on ZYLVEXT/litestar-auth

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file litestar_auth-8.0.2-py3-none-any.whl.

File metadata

  • Download URL: litestar_auth-8.0.2-py3-none-any.whl
  • Upload date:
  • Size: 469.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for litestar_auth-8.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 dab6735e542468b523e18d3995abfa82d957490065b48a5944b539de42474072
MD5 9eaa0f3a4c3d9309c6e3153f95838811
BLAKE2b-256 0468552b00eb8b377fc7c65de693b35b6c492d0a0873f2218a761f97a332201f

See more details on using hashes here.

Provenance

The following attestation bundles were made for litestar_auth-8.0.2-py3-none-any.whl:

Publisher: 3_release.yml on ZYLVEXT/litestar-auth

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

8.0.2 This release

2 files

8.0.1

2 files

8.0.0

2 files

7.3.4

2 files

7.3.3

2 files

7.3.2

2 files

7.3.1

2 files

7.3.0

2 files

7.2.0

2 files

7.1.2

2 files

7.0.0

2 files

6.0.0

2 files

5.3.0

2 files

5.2.0

2 files

5.1.0

2 files

5.0.3

2 files

5.0.2

2 files

5.0.1

2 files

5.0.0

2 files

4.2.0

2 files

4.1.0

2 files

4.0.1

2 files

4.0.0

2 files

3.3.0

2 files

3.2.0

2 files

3.1.0

2 files

3.0.0

2 files

2.4.0

2 files

2.3.0

2 files

2.2.0

2 files

2.1.0

2 files

2.0.0

2 files

1.11.0

2 files

1.10.0

2 files

1.9.0

2 files

1.8.0

2 files

1.7.0

2 files

1.6.1

2 files

1.6.0

2 files

1.5.0

2 files

1.4.0

2 files

1.3.0

2 files

1.2.0

2 files

1.1.1

2 files

1.1.0

2 files

1.0.5

2 files

1.0.4

2 files

1.0.3

2 files

1.0.2

2 files

1.0.1

2 files

1.0.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page