oidc-exchange
Python binding for oidc-exchange — a Rust service that validates ID tokens from third-party OIDC providers (Google, Apple, …) and exchanges them for self-issued access and refresh tokens.
The service is embedded in-process as a native extension (built with PyO3 + maturin). Handle requests synchronously or with async, or mount the built-in ASGI/WSGI apps in FastAPI, Starlette, Flask, or Django.
Install
pip install oidc-exchange
Ships as an abi3 wheel — one wheel per platform works on Python 3.10+: manylinux_2_28 x86_64/aarch64, win_amd64, and macosx_11_0_arm64. An sdist is published alongside for other platforms (needs a Rust toolchain to build).
Usage
ASGI (FastAPI / Starlette)
from fastapi import FastAPI
from oidc_exchange import OidcExchange
oidc = OidcExchange(config="./config.toml")
app = FastAPI()
app.mount("/auth", oidc.asgi_app())
WSGI (Flask / Django)
from oidc_exchange import OidcExchange
oidc = OidcExchange(config_string="""
[server]
issuer = "https://auth.example.com"
…
""")
application = oidc.wsgi_app()
Direct request handling
from urllib.parse import urlencode
resp = oidc.handle_request_sync({
"method": "POST",
"path": "/token",
"headers": {"content-type": "application/x-www-form-urlencoded"},
"body": urlencode({
"grant_type": "authorization_code",
"code": "abc123",
"redirect_uri": "https://app.example.com/callback",
"provider": "google",
}).encode(),
})
# resp -> {"status": 200, "headers": {...}, "body": b"…"}
# or await the async variant (runs the blocking call in the default executor):
resp = await oidc.handle_request(request)
API
class OidcExchange:
def __init__(self, *, config: str | None = None, config_string: str | None = None) -> None: ...
def handle_request_sync(self, request: dict) -> dict: ...
async def handle_request(self, request: dict) -> dict: ...
def asgi_app(self) -> Any: ... # mountable ASGI application
def wsgi_app(self) -> Any: ... # mountable WSGI application
def shutdown(self) -> None: ...
A request dict is {"method", "path", "headers": dict[str, str], "body": bytes}; the response is {"status", "headers": dict[str, str], "body": bytes}. The full service is exposed — /token, /revoke, /keys, /.well-known/openid-configuration, /health, and the internal admin API.
Framework examples
See the main repo's Python examples: FastAPI, Flask, Django.
Configuration
TOML config — providers, token TTLs, registration policy, key management, and storage. See the configuration guide.
Behaviour change
Construction now fails when a ${VAR} placeholder is unresolved, empty, or malformed instead of
using that placeholder as literal configuration text. Set every referenced environment variable
before constructing OidcExchange.
Links
Published to PyPI via OIDC trusted publishing. MIT licensed.
Metadata
Release files for oidc-exchange 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| oidc_exchange-0.3.0.tar.gz | 654.6 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| oidc_exchange-0.3.0-cp310-abi3-win_amd64.whl | CPython 3.10 | abi3 | Windows x86-64 | Details |
| oidc_exchange-0.3.0-cp310-abi3-manylinux_2_28_x86_64.whl | CPython 3.10 | abi3 | Linux glibc 2.28+ x86-64 | Details |
| oidc_exchange-0.3.0-cp310-abi3-manylinux_2_28_aarch64.whl | CPython 3.10 | abi3 | Linux glibc 2.28+ ARM64 | Details |
| oidc_exchange-0.3.0-cp310-abi3-macosx_11_0_arm64.whl | CPython 3.10 | abi3 | macOS 11.0+ ARM64 | Details |
Total release size: 57.2 MB
Release files / oidc_exchange-0.3.0.tar.gz
| Download URL | oidc_exchange-0.3.0.tar.gz |
|---|---|
| Size | 654.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3759572725ba38d62976f10868c7c810fbdb63cddcb4069f5884d6981e5c4efd
|
|
BLAKE2b-256 checksum How to use checksums |
c562fa75d7baf5370b74cc913abd79defc95d48f73b5208e3e5c7cf9485b7833
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / oidc_exchange-0.3.0-cp310-abi3-win_amd64.whl
| Download URL | oidc_exchange-0.3.0-cp310-abi3-win_amd64.whl |
|---|---|
| Size | 12.6 MB |
| Tags | CPython 3.10 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
ac78ae6ab40a0e9fcd179ee872b791ef420c08ae5333e0804b41914dfdb49a86
|
|
BLAKE2b-256 checksum How to use checksums |
4c58bbf756d8f040263af3089c7c297d9c05c5395c3f3b2c2f12e654cda78060
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / oidc_exchange-0.3.0-cp310-abi3-manylinux_2_28_x86_64.whl
| Download URL | oidc_exchange-0.3.0-cp310-abi3-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 15.3 MB |
| Tags | CPython 3.10 Linux glibc 2.28+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
2cfaa5950c690f93ddf8bd97a21f60a0efab643145898993255e2bb6fb5c2ab2
|
|
BLAKE2b-256 checksum How to use checksums |
2204317c046e168c8fe1b3665a98a885b188dd1a752999fe049e3f3c44c0338a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / oidc_exchange-0.3.0-cp310-abi3-manylinux_2_28_aarch64.whl
| Download URL | oidc_exchange-0.3.0-cp310-abi3-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 15.3 MB |
| Tags | CPython 3.10 Linux glibc 2.28+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
448faf55270e67fb2f1c1e4a20ac315e6918f5d451a24bf057a5bb8a9bc3cdb3
|
|
BLAKE2b-256 checksum How to use checksums |
1bc05d0d1f96ff4042e66a10001ca1cd9891839107d089876b498b799cd66dee
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / oidc_exchange-0.3.0-cp310-abi3-macosx_11_0_arm64.whl
| Download URL | oidc_exchange-0.3.0-cp310-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 13.3 MB |
| Tags | CPython 3.10 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
5dcb8d3a129ecae3de76c4a0e488fa91e6a4d554d1f8848b7648017ce06f58fb
|
|
BLAKE2b-256 checksum How to use checksums |
a7ae445eee86cb81098af60657f409a5ff41d910aea5cfdff406a3670ea7f4f2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency log