Skip to main content

litestar-auth keeps opaque human sessions and sender-constrained workload identity on separate fail-closed trust paths

Tests Codecov coverage Latest stable release on PyPI Supported Python versions MIT license

litestar-auth 7 is the human-authentication layer in the six-distribution AuthWeave workspace for Python 3.12–3.14. Browser sessions and machine credentials stay on separate trust paths while sharing typed, fail-closed AuthWeave decisions.

uv add litestar-auth

Six packages, one version

  • litestar-auth — Litestar registration, login, OAuth + PKCE, TOTP, roles, organizations, and opaque database or Redis sessions. uv add litestar-auth
  • authweave-core — Typed principals, evidence, decisions, route policies, and fail-closed provider coordination. uv add authweave-core
  • authweave-workload — X.509 lifecycle plus mTLS, DPoP, SPIFFE, bound JWT, and introspection profiles. uv add 'authweave-workload[all]'
  • authweave-otel — API-only security spans and metrics without an SDK or exporter. uv add authweave-otel
  • authweave-webhooks — Ed25519 Standard Webhooks integrity, replay control, and bounded delivery. uv add 'authweave-webhooks[redis,httpx]'
  • authweave-http-signatures — RFC 9530/RFC 9421 payment-message integrity after machine authentication. uv add authweave-http-signatures

Install only the layer you need; optional integrations stay lazy. All six distributions use one exact lockstep version, and the dependency direction stays one-way:

authweave-core
├── litestar-auth
├── authweave-workload
│   └── authweave-workload[litestar] → litestar-auth Extension SDK v2
├── authweave-otel
├── authweave-webhooks
└── authweave-http-signatures

Start with a secure human session

uv add litestar-auth aiosqlite
from litestar import Litestar
from litestar_auth import DatabaseTokenAuthConfig, LitestarAuth, LitestarAuthConfig

config = LitestarAuthConfig(
    database_token_auth=DatabaseTokenAuthConfig(
        token_hash_secret=session_digest_secret,
    ),
    csrf_secret=csrf_secret,
    session_maker=session_maker,
    user_model=User,
    user_manager_class=UserManager,
    user_db_factory=user_db_factory,
    user_manager_security=user_manager_security,
)

app = Litestar(plugins=[LitestarAuth(config)])

The quickstart covers schema requirements and links the runnable registration/login flow. Use RedisTokenStrategy with litestar-auth[redis] when sessions belong in Redis. Both implementations issue opaque server-side access tokens. With LitestarAuthConfig.enable_refresh=True, they also rotate refresh tokens, revoke replayed chains, and expose safe session metadata.

Keep machine identity on its own path

uv add 'authweave-workload[mtls,jwt,sqlalchemy]'
# Add [litestar] only for the Extension SDK v2 integration.

WorkloadLifecycleService manages service applications, principals, public certificate metadata, overlapping rotation, revocation, and same-transaction security events. Private keys are rejected at the package boundary and are never stored.

At request time:

  • DirectMTLSProvider consumes trusted TLS peer evidence.
  • MTLSBoundJWTProvider verifies an asymmetric access token from a configured external issuer.
  • DPoP, SPIFFE, and sender-constrained introspection profiles remain behind explicit extras and route policy.
  • Bound tokens or proofs must match the same verified certificate or DPoP key.
  • Ambiguous credential ownership and provider failures stop authentication; they never fall through to another provider.

authweave-workload also provides strict outbound RFC 8693 token exchange and typed payment authorization details. authweave-webhooks and authweave-http-signatures verify message integrity after authentication; authweave-otel observes outcomes without changing them.

The repository includes an Envoy-based reference stack with negative-path verification:

sh docker/reference/verify.sh

Security boundary

[!IMPORTANT] Authentication establishes a verified principal and constraints. Your application still owns tenant mapping, row-level security, resource ownership, and business authorization.

Version 7 intentionally does not provide unconstrained bearer login, user-owned API keys, shared-secret machine or request-signing credentials, an OAuth Authorization Server or STS, generic IAM, or production rollout automation. Token exchange is a strict client for an external STS; it does not operate one.

Release evidence

CI exercises Python 3.12–3.14 on Linux, macOS, and Windows. Every distribution has an independent 100% branch-coverage gate, and the repository runs CodeQL, dependency review, pinned-action checks, reproducible builds, per-distribution CycloneDX 1.7 SBOMs and build-provenance attestations, isolated wheel imports, and live PostgreSQL/Redis/proxy reference stacks.

That evidence establishes library readiness, not certification of a particular deployment. The readiness roadmap lists the independent conformance, security-review, KMS, capacity, and operational gates required for production profiles.

Documentation

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

litestar_auth-7.1.2.tar.gz (325.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

litestar_auth-7.1.2-py3-none-any.whl (459.9 kB view details)

Uploaded Python 3

File details

Details for the file litestar_auth-7.1.2.tar.gz.

File metadata

  • Download URL: litestar_auth-7.1.2.tar.gz
  • Upload date:
  • Size: 325.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for litestar_auth-7.1.2.tar.gz
Algorithm Hash digest
SHA256 d402f487179325e39814762aee9ba811ecb8e87934cbd881bef22221e6f4766a
MD5 416883db6557654cbbd2e2d1a58d41dd
BLAKE2b-256 b337667041ece04ac984a29c30e53c4801c221072243702bfeb61e5fe6b2ee3a

See more details on using hashes here.

Provenance

The following attestation bundles were made for litestar_auth-7.1.2.tar.gz:

Publisher: 3_release.yml on ZYLVEXT/litestar-auth

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file litestar_auth-7.1.2-py3-none-any.whl.

File metadata

  • Download URL: litestar_auth-7.1.2-py3-none-any.whl
  • Upload date:
  • Size: 459.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for litestar_auth-7.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 e1c22cb8a3c95dcf93c375b39871926cd79681c397cf6f8831ed006e9a160175
MD5 b21b88ab561b6f2216f17805d0a607ab
BLAKE2b-256 7757ef479cd9f85134413a533ada0f8417a817a51dcb8d81e0f2f818cd29f3ff

See more details on using hashes here.

Provenance

The following attestation bundles were made for litestar_auth-7.1.2-py3-none-any.whl:

Publisher: 3_release.yml on ZYLVEXT/litestar-auth

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

8.0.2

2 files

8.0.1

2 files

8.0.0

2 files

7.3.4

2 files

7.3.3

2 files

7.3.2

2 files

7.3.1

2 files

7.3.0

2 files

7.2.0

2 files

This release

7.1.2 This release

2 files

7.0.0

2 files

6.0.0

2 files

5.3.0

2 files

5.2.0

2 files

5.1.0

2 files

5.0.3

2 files

5.0.2

2 files

5.0.1

2 files

5.0.0

2 files

4.2.0

2 files

4.1.0

2 files

4.0.1

2 files

4.0.0

2 files

3.3.0

2 files

3.2.0

2 files

3.1.0

2 files

3.0.0

2 files

2.4.0

2 files

2.3.0

2 files

2.2.0

2 files

2.1.0

2 files

2.0.0

2 files

1.11.0

2 files

1.10.0

2 files

1.9.0

2 files

1.8.0

2 files

1.7.0

2 files

1.6.1

2 files

1.6.0

2 files

1.5.0

2 files

1.4.0

2 files

1.3.0

2 files

1.2.0

2 files

1.1.1

2 files

1.1.0

2 files

1.0.5

2 files

1.0.4

2 files

1.0.3

2 files

1.0.2

2 files

1.0.1

2 files

1.0.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page