Skip to main content

litestar-auth keeps opaque human sessions and sender-constrained workload identity on separate fail-closed trust paths

Tests Codecov coverage Latest stable release on PyPI Supported Python versions MIT license

litestar-auth 7 is the human-authentication layer in the six-distribution AuthWeave workspace for Python 3.12–3.14. Browser sessions and machine credentials stay on separate trust paths while sharing typed, fail-closed AuthWeave decisions.

uv add litestar-auth

Six packages, one version

  • litestar-auth — Litestar registration, login, OAuth + PKCE, TOTP, roles, organizations, and opaque database or Redis sessions. uv add litestar-auth
  • authweave-core — Typed principals, evidence, decisions, route policies, and fail-closed provider coordination. uv add authweave-core
  • authweave-workload — X.509 lifecycle plus mTLS, DPoP, SPIFFE, bound JWT, and introspection profiles. uv add 'authweave-workload[all]'
  • authweave-otel — API-only security spans and metrics without an SDK or exporter. uv add authweave-otel
  • authweave-webhooks — Ed25519 Standard Webhooks integrity, replay control, and bounded delivery. uv add 'authweave-webhooks[redis,httpx]'
  • authweave-http-signatures — RFC 9530/RFC 9421 payment-message integrity after machine authentication. uv add authweave-http-signatures

Install only the layer you need; optional integrations stay lazy. All six distributions use one exact lockstep version, and the dependency direction stays one-way:

authweave-core
├── litestar-auth
├── authweave-workload
│   └── authweave-workload[litestar] → litestar-auth Extension SDK v2
├── authweave-otel
├── authweave-webhooks
└── authweave-http-signatures

Start with a secure human session

uv add litestar-auth aiosqlite
from litestar import Litestar
from litestar_auth import DatabaseTokenAuthConfig, LitestarAuth, LitestarAuthConfig

config = LitestarAuthConfig(
    database_token_auth=DatabaseTokenAuthConfig(
        token_hash_secret=session_digest_secret,
    ),
    csrf_secret=csrf_secret,
    session_maker=session_maker,
    user_model=User,
    user_manager_class=UserManager,
    user_db_factory=user_db_factory,
    user_manager_security=user_manager_security,
)

app = Litestar(plugins=[LitestarAuth(config)])

The quickstart covers schema requirements and links the runnable registration/login flow. Use RedisTokenStrategy with litestar-auth[redis] when sessions belong in Redis. Both implementations issue opaque server-side access tokens. With LitestarAuthConfig.enable_refresh=True, they also rotate refresh tokens, revoke replayed chains, and expose safe session metadata.

Keep machine identity on its own path

uv add 'authweave-workload[mtls,jwt,sqlalchemy]'
# Add [litestar] only for the Extension SDK v2 integration.

WorkloadLifecycleService manages service applications, principals, public certificate metadata, overlapping rotation, revocation, and same-transaction security events. Private keys are rejected at the package boundary and are never stored.

At request time:

  • DirectMTLSProvider consumes trusted TLS peer evidence.
  • MTLSBoundJWTProvider verifies an asymmetric access token from a configured external issuer.
  • DPoP, SPIFFE, and sender-constrained introspection profiles remain behind explicit extras and route policy.
  • Bound tokens or proofs must match the same verified certificate or DPoP key.
  • Ambiguous credential ownership and provider failures stop authentication; they never fall through to another provider.

authweave-workload also provides strict outbound RFC 8693 token exchange and typed payment authorization details. authweave-webhooks and authweave-http-signatures verify message integrity after authentication; authweave-otel observes outcomes without changing them.

The repository includes an Envoy-based reference stack with negative-path verification:

sh docker/reference/verify.sh

Security boundary

[!IMPORTANT] Authentication establishes a verified principal and constraints. Your application still owns tenant mapping, row-level security, resource ownership, and business authorization.

Version 7 intentionally does not provide unconstrained bearer login, user-owned API keys, shared-secret machine or request-signing credentials, an OAuth Authorization Server or STS, generic IAM, or production rollout automation. Token exchange is a strict client for an external STS; it does not operate one.

Release evidence

CI exercises Python 3.12–3.14 on Linux, macOS, and Windows. Every distribution has an independent 100% branch-coverage gate, and the repository runs CodeQL, dependency review, pinned-action checks, reproducible builds, per-distribution CycloneDX 1.7 SBOMs and build-provenance attestations, isolated wheel imports, and live PostgreSQL/Redis/proxy reference stacks.

That evidence establishes library readiness, not certification of a particular deployment. The readiness roadmap lists the independent conformance, security-review, KMS, capacity, and operational gates required for production profiles.

Documentation

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

litestar_auth-8.0.1.tar.gz (334.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

litestar_auth-8.0.1-py3-none-any.whl (469.9 kB view details)

Uploaded Python 3

File details

Details for the file litestar_auth-8.0.1.tar.gz.

File metadata

  • Download URL: litestar_auth-8.0.1.tar.gz
  • Upload date:
  • Size: 334.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for litestar_auth-8.0.1.tar.gz
Algorithm Hash digest
SHA256 5ed51a93e0865c53db211abe7e43a9a855432a8b860ec8eb9061df8e59d9f37e
MD5 70f49ad8435424d467bdfd57cb458350
BLAKE2b-256 e9fb21975ea49ae1fb8975ec0122c1bab2e8205d27d0c662cca117d3b7bf6474

See more details on using hashes here.

Provenance

The following attestation bundles were made for litestar_auth-8.0.1.tar.gz:

Publisher: 3_release.yml on ZYLVEXT/litestar-auth

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file litestar_auth-8.0.1-py3-none-any.whl.

File metadata

  • Download URL: litestar_auth-8.0.1-py3-none-any.whl
  • Upload date:
  • Size: 469.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for litestar_auth-8.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 e96284d6b08963a19c4d8921f4fcae74bce5f89ab77b42c67af955123b735dfc
MD5 b4193f14c79352b8f330f1dbfd591975
BLAKE2b-256 8357518cdbbfff0a352e94703afd889290ac958c0aad80ae9fe0ca0ddfd9487e

See more details on using hashes here.

Provenance

The following attestation bundles were made for litestar_auth-8.0.1-py3-none-any.whl:

Publisher: 3_release.yml on ZYLVEXT/litestar-auth

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

8.0.2

2 files

This release

8.0.1 This release

2 files

8.0.0

2 files

7.3.4

2 files

7.3.3

2 files

7.3.2

2 files

7.3.1

2 files

7.3.0

2 files

7.2.0

2 files

7.1.2

2 files

7.0.0

2 files

6.0.0

2 files

5.3.0

2 files

5.2.0

2 files

5.1.0

2 files

5.0.3

2 files

5.0.2

2 files

5.0.1

2 files

5.0.0

2 files

4.2.0

2 files

4.1.0

2 files

4.0.1

2 files

4.0.0

2 files

3.3.0

2 files

3.2.0

2 files

3.1.0

2 files

3.0.0

2 files

2.4.0

2 files

2.3.0

2 files

2.2.0

2 files

2.1.0

2 files

2.0.0

2 files

1.11.0

2 files

1.10.0

2 files

1.9.0

2 files

1.8.0

2 files

1.7.0

2 files

1.6.1

2 files

1.6.0

2 files

1.5.0

2 files

1.4.0

2 files

1.3.0

2 files

1.2.0

2 files

1.1.1

2 files

1.1.0

2 files

1.0.5

2 files

1.0.4

2 files

1.0.3

2 files

1.0.2

2 files

1.0.1

2 files

1.0.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page