Skip to main content

oidc-exchange

PyPI Python License: MIT

Python binding for oidc-exchange — a Rust service that validates ID tokens from third-party OIDC providers (Google, Apple, …) and exchanges them for self-issued access and refresh tokens.

The service is embedded in-process as a native extension (built with PyO3 + maturin). Handle requests synchronously or with async, or mount the built-in ASGI/WSGI apps in FastAPI, Starlette, Flask, or Django.

Install

pip install oidc-exchange

Ships as an abi3 wheel — one wheel per platform works on Python 3.10+: manylinux_2_28 x86_64/aarch64, win_amd64, and macosx_11_0_arm64. An sdist is published alongside for other platforms (needs a Rust toolchain to build).

Usage

ASGI (FastAPI / Starlette)

from fastapi import FastAPI
from oidc_exchange import OidcExchange

oidc = OidcExchange(config="./config.toml")
app = FastAPI()
app.mount("/auth", oidc.asgi_app())

WSGI (Flask / Django)

from oidc_exchange import OidcExchange

oidc = OidcExchange(config_string="""
[server]
issuer = "https://auth.example.com"
…
""")
application = oidc.wsgi_app()

Direct request handling

from urllib.parse import urlencode

resp = oidc.handle_request_sync({
    "method": "POST",
    "path": "/token",
    "headers": {"content-type": "application/x-www-form-urlencoded"},
    "body": urlencode({
        "grant_type": "authorization_code",
        "code": "abc123",
        "redirect_uri": "https://app.example.com/callback",
        "provider": "google",
    }).encode(),
})
# resp -> {"status": 200, "headers": {...}, "body": b"…"}

# or await the async variant (runs the blocking call in the default executor):
resp = await oidc.handle_request(request)

API

class OidcExchange:
    def __init__(self, *, config: str | None = None, config_string: str | None = None) -> None: ...
    def handle_request_sync(self, request: dict) -> dict: ...
    async def handle_request(self, request: dict) -> dict: ...
    def asgi_app(self) -> Any: ...   # mountable ASGI application
    def wsgi_app(self) -> Any: ...   # mountable WSGI application
    def shutdown(self) -> None: ...

A request dict is {"method", "path", "headers": dict[str, str], "body": bytes}; the response is {"status", "headers": dict[str, str], "body": bytes}. The full service is exposed — /token, /revoke, /keys, /.well-known/openid-configuration, /health, and the internal admin API.

Framework examples

See the main repo's Python examples: FastAPI, Flask, Django.

Configuration

TOML config — providers, token TTLs, registration policy, key management, and storage. See the configuration guide.

Behaviour change

Construction now fails when a ${VAR} placeholder is unresolved, empty, or malformed instead of using that placeholder as literal configuration text. Set every referenced environment variable before constructing OidcExchange.

Links

Published to PyPI via OIDC trusted publishing. MIT licensed.

Metadata

Release files for oidc-exchange 0.4.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for oidc-exchange 0.4.1
File Size Uploaded
oidc_exchange-0.4.1.tar.gz 677.2 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for oidc-exchange 0.4.1
File
oidc_exchange-0.4.1-cp310-abi3-win_amd64.whl CPython 3.10 abi3 Windows x86-64 Details
oidc_exchange-0.4.1-cp310-abi3-manylinux_2_28_x86_64.whl CPython 3.10 abi3 Linux glibc 2.28+ x86-64 Details
oidc_exchange-0.4.1-cp310-abi3-manylinux_2_28_aarch64.whl CPython 3.10 abi3 Linux glibc 2.28+ ARM64 Details
oidc_exchange-0.4.1-cp310-abi3-macosx_11_0_arm64.whl CPython 3.10 abi3 macOS 11.0+ ARM64 Details

Total release size: 57.8 MB

Release files / oidc_exchange-0.4.1.tar.gz

Download URL oidc_exchange-0.4.1.tar.gz
Size 677.2 kB
Tags Source
SHA-256 checksum
How to use checksums
abe9a2cbec4ad707be4277696bc477667856d7cc53c9a55ef25c5e8a364ad740
BLAKE2b-256 checksum
How to use checksums
c581df2abb4d45d6142c65345096d4f1755460b3d62358a37c725cfcd0f0a1d0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / oidc_exchange-0.4.1-cp310-abi3-win_amd64.whl

Download URL oidc_exchange-0.4.1-cp310-abi3-win_amd64.whl
Size 12.7 MB
Tags CPython 3.10 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
4efb6302da0c1fd34c43e88bbb4d0441411552930aa619276b6275d36fb7efb1
BLAKE2b-256 checksum
How to use checksums
782459eb7831c1dd8c4ff523e5d9e1e0b185b1cbff33ad8de99eeb4accdb5834
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / oidc_exchange-0.4.1-cp310-abi3-manylinux_2_28_x86_64.whl

Download URL oidc_exchange-0.4.1-cp310-abi3-manylinux_2_28_x86_64.whl
Size 15.4 MB
Tags CPython 3.10 Linux glibc 2.28+ x86-64 abi3
SHA-256 checksum
How to use checksums
5c0ec3e040987be18a635e680c44ba72067a198897b7c6ef53243616cdd69cfe
BLAKE2b-256 checksum
How to use checksums
4054205b39af84bcef564c5f65ae3d0b02764411e9e3a2a8cadfc035f61e1e17
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / oidc_exchange-0.4.1-cp310-abi3-manylinux_2_28_aarch64.whl

Download URL oidc_exchange-0.4.1-cp310-abi3-manylinux_2_28_aarch64.whl
Size 15.5 MB
Tags CPython 3.10 Linux glibc 2.28+ ARM64 abi3
SHA-256 checksum
How to use checksums
9b53e9e2d880675a11db11a9e99926bba623e6218ebe1637b4487185373a5546
BLAKE2b-256 checksum
How to use checksums
35c345610c6436dc7d2160c8d7a602b1ee88ded27013b5bf29c00d91bf46c2c6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / oidc_exchange-0.4.1-cp310-abi3-macosx_11_0_arm64.whl

Download URL oidc_exchange-0.4.1-cp310-abi3-macosx_11_0_arm64.whl
Size 13.5 MB
Tags CPython 3.10 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
96d865ce97cd1741a9241d4d89d215dcbbbf8313fea90ca570b85f2ff4234ab7
BLAKE2b-256 checksum
How to use checksums
cda0a09f5b2334a7de35bbcf52200b34cb048efcedc0a1f4e496a20bda470cd3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.4.1 This release

5 release files

0.4.0

5 release files

0.3.0

5 release files

0.2.0

5 release files

0.1.1

5 release files

0.1.0

5 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page