Skip to main content

nexgensis-auth-client

Official Python SDK for CentralAuth — Nexgensis' shared identity provider.

Products use it to:

  • Validate Django-issued JWTs against the published JWKS (RS256, audience-bound).
  • Call /oauth/* and /api/auth/* (AuthClient) on behalf of a human user.
  • Mint M2M tokens (M2MClient) for service-to-service calls, with audience+scope-keyed in-process caching.
  • Drive admin operations (AdminClient) — users, groups, products, entitlements, audit — for backend sync jobs.
  • Receive webhooks safely — HMAC-SHA256 signature, timestamp replay-guard, idempotent dedupe (WebhookVerifier + Django @webhook_view).
  • Plug into Django/DRF with one settings dict — JWTAuthentication, AuthMiddleware, HasGroup / HasEntitlement / HasScope.

Install

pip install nexgensis-auth-client            # core: validation + clients + webhooks
pip install 'nexgensis-auth-client[django]'  # adds Django + DRF integration

60-second Django integration

# settings.py
CENTRALAUTH = {
    "BASE_URL": "https://auth.nexgensis.com",
    "AUDIENCE": "qms",   # this product's client_id
}

REST_FRAMEWORK = {
    "DEFAULT_AUTHENTICATION_CLASSES": [
        "nexgensis_auth_client.django.authentication.JWTAuthentication",
    ],
}
# views.py
from rest_framework.decorators import api_view, permission_classes
from rest_framework.permissions import IsAuthenticated
from nexgensis_auth_client.django.permissions import HasGroup

@api_view(["POST"])
@permission_classes([IsAuthenticated, HasGroup("QA_LEAD")])
def close_issue(request, issue_id):
    ...

After auth: request.user.id / request.auth.has_group(...) / request.auth.email.

Webhook receiver

# settings.py
QMS_USER_SYNC_SECRET = os.environ["QMS_USER_SYNC_SECRET"]

# urls.py
path("webhooks/centralauth/", on_user_event),

# views.py
from nexgensis_auth_client.django.webhooks import webhook_view

@webhook_view(secret_setting="QMS_USER_SYNC_SECRET")
def on_user_event(request, event):
    if event.event_type == "user.disabled":
        ...
    return HttpResponse(status=200)

Test helpers

from nexgensis_auth_client.testing import build_auth_context, override_auth

def test_qa_lead_can_close(api_client):
    ctx = build_auth_context(user_id="u-1", groups=["QA_LEAD"])
    with override_auth(api_client, ctx):
        response = api_client.post("/issues/I-1/close/")
    assert response.status_code == 200

Stable surface

These are the public, semver-protected names:

Module Purpose
AuthClient OAuth user flows (login/refresh/etc.)
AdminClient /api/v1/* admin REST
M2MClient client_credentials with token caching
JWTValidator / JWKSCache Token validation
AuthContext Claim accessor (groups, scopes, etc.)
WebhookVerifier / VerifiedEvent Webhook HMAC + dedupe
nexgensis_auth_client.django.* Django/DRF integration
nexgensis_auth_client.testing.* Test fixtures

See docs/PRODUCT_INTEGRATION_GUIDE.md in the CentralAuth repo for the full guide.

Metadata

Release files for nexgensis-auth-client 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for nexgensis-auth-client 0.1.0
File Size Uploaded
nexgensis_auth_client-0.1.0.tar.gz 29.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for nexgensis-auth-client 0.1.0
File Interpreter ABI Platform
nexgensis_auth_client-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 61.2 kB

Release files / nexgensis_auth_client-0.1.0.tar.gz

Download URL nexgensis_auth_client-0.1.0.tar.gz
Size 29.4 kB
Tags Source
SHA-256 checksum
How to use checksums
2ededc8f8d348ef258cb106566d8984e6ab3c37d3d4a4e6a5659318d3d47a773
BLAKE2b-256 checksum
How to use checksums
d74eb8d46a83d84f2a4e43f8b600354251420dd70a9b220abd6e40f3426dbbeb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.15

Release files / nexgensis_auth_client-0.1.0-py3-none-any.whl

Download URL nexgensis_auth_client-0.1.0-py3-none-any.whl
Size 31.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
74ddeef21916040ea3c34de7393077ddebabac95cec351afb9e05f7a904bc00f
BLAKE2b-256 checksum
How to use checksums
3fb2d43f8c0db3d52f2fc6251f67a019deab601d82e8f2f5a5bb2eb73b81a980
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.15

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page