Skip to main content

oidc-exchange

PyPI Python License: MIT

Python binding for oidc-exchange — a Rust service that validates ID tokens from third-party OIDC providers (Google, Apple, …) and exchanges them for self-issued access and refresh tokens.

The service is embedded in-process as a native extension (built with PyO3 + maturin). Handle requests synchronously or with async, or mount the built-in ASGI/WSGI apps in FastAPI, Starlette, Flask, or Django.

Install

pip install oidc-exchange

Ships as an abi3 wheel — one wheel per platform works on Python 3.10+: manylinux_2_28 x86_64/aarch64, win_amd64, and macosx_11_0_arm64. An sdist is published alongside for other platforms (needs a Rust toolchain to build).

Usage

ASGI (FastAPI / Starlette)

from fastapi import FastAPI
from oidc_exchange import OidcExchange

oidc = OidcExchange(config="./config.toml")
app = FastAPI()
app.mount("/auth", oidc.asgi_app())

WSGI (Flask / Django)

from oidc_exchange import OidcExchange

oidc = OidcExchange(config_string="""
[server]
issuer = "https://auth.example.com"
…
""")
application = oidc.wsgi_app()

Direct request handling

from urllib.parse import urlencode

resp = oidc.handle_request_sync({
    "method": "POST",
    "path": "/token",
    "headers": {"content-type": "application/x-www-form-urlencoded"},
    "body": urlencode({
        "grant_type": "authorization_code",
        "code": "abc123",
        "redirect_uri": "https://app.example.com/callback",
        "provider": "google",
    }).encode(),
})
# resp -> {"status": 200, "headers": {...}, "body": b"…"}

# or await the async variant (runs the blocking call in the default executor):
resp = await oidc.handle_request(request)

API

class OidcExchange:
    def __init__(self, *, config: str | None = None, config_string: str | None = None) -> None: ...
    def handle_request_sync(self, request: dict) -> dict: ...
    async def handle_request(self, request: dict) -> dict: ...
    def asgi_app(self) -> Any: ...   # mountable ASGI application
    def wsgi_app(self) -> Any: ...   # mountable WSGI application
    def shutdown(self) -> None: ...

A request dict is {"method", "path", "headers": dict[str, str], "body": bytes}; the response is {"status", "headers": dict[str, str], "body": bytes}. The full service is exposed — /token, /revoke, /keys, /.well-known/openid-configuration, /health, and the internal admin API.

Framework examples

See the main repo's Python examples: FastAPI, Flask, Django.

Configuration

TOML config — providers, token TTLs, registration policy, key management, and storage. See the configuration guide.

Behaviour change

Construction now fails when a ${VAR} placeholder is unresolved, empty, or malformed instead of using that placeholder as literal configuration text. Set every referenced environment variable before constructing OidcExchange.

Published to PyPI via OIDC trusted publishing. MIT licensed.

Metadata

Release files for oidc-exchange 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for oidc-exchange 0.4.0
File Size Uploaded
oidc_exchange-0.4.0.tar.gz 663.7 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for oidc-exchange 0.4.0
File
oidc_exchange-0.4.0-cp310-abi3-win_amd64.whl CPython 3.10 abi3 Windows x86-64 Details
oidc_exchange-0.4.0-cp310-abi3-manylinux_2_28_x86_64.whl CPython 3.10 abi3 Linux glibc 2.28+ x86-64 Details
oidc_exchange-0.4.0-cp310-abi3-manylinux_2_28_aarch64.whl CPython 3.10 abi3 Linux glibc 2.28+ ARM64 Details
oidc_exchange-0.4.0-cp310-abi3-macosx_11_0_arm64.whl CPython 3.10 abi3 macOS 11.0+ ARM64 Details

Total release size: 56.2 MB

Release files / oidc_exchange-0.4.0.tar.gz

Download URL oidc_exchange-0.4.0.tar.gz
Size 663.7 kB
Tags Source
SHA-256 checksum
How to use checksums
f9d90f1674ea12b16d7a11147fca1ed89d54167d445dcc82ead3ff36730564b9
BLAKE2b-256 checksum
How to use checksums
bc098a31f290a5da6fb1411dc122b90984fba6b01be1352420fc537cbab94d7c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / oidc_exchange-0.4.0-cp310-abi3-win_amd64.whl

Download URL oidc_exchange-0.4.0-cp310-abi3-win_amd64.whl
Size 12.3 MB
Tags CPython 3.10 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
bc53571dcc569d96e43a9fcaf62d70767675781e4db395f8756146dd8c8c9568
BLAKE2b-256 checksum
How to use checksums
c6fd9362199d0fcefe182c0fae63fb90c9ec6da859463d47b3f59907de204da7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / oidc_exchange-0.4.0-cp310-abi3-manylinux_2_28_x86_64.whl

Download URL oidc_exchange-0.4.0-cp310-abi3-manylinux_2_28_x86_64.whl
Size 15.1 MB
Tags CPython 3.10 Linux glibc 2.28+ x86-64 abi3
SHA-256 checksum
How to use checksums
adc073490d091f17a2041ed8ac525e2b88a1580d3a53d6993a5e840a2050929f
BLAKE2b-256 checksum
How to use checksums
4bdd4e3aa64a44ae7501477d45f8850c7cb878f44e848ebdce39bff78d27d120
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / oidc_exchange-0.4.0-cp310-abi3-manylinux_2_28_aarch64.whl

Download URL oidc_exchange-0.4.0-cp310-abi3-manylinux_2_28_aarch64.whl
Size 15.1 MB
Tags CPython 3.10 Linux glibc 2.28+ ARM64 abi3
SHA-256 checksum
How to use checksums
5b14b66ab1e2f41293a9f41c8057b9cddac114a60db37035730494e13a75a2bd
BLAKE2b-256 checksum
How to use checksums
adfd2255b8089838e539c58ca0cb78d0d80b58f11b52de49d643086e3b2a9fa2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / oidc_exchange-0.4.0-cp310-abi3-macosx_11_0_arm64.whl

Download URL oidc_exchange-0.4.0-cp310-abi3-macosx_11_0_arm64.whl
Size 13.1 MB
Tags CPython 3.10 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
7e5364a90077b2d6b3c7a5e8fdd8e9f6bc990958653e5f200e1184e67e36f73e
BLAKE2b-256 checksum
How to use checksums
d580dfb8ae9b45bd3f12277da92885128611a281da26cc1c32fab988495ec10e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release history Release notifications | RSS feed

0.4.1

5 release files

This release

0.4.0 This release

5 release files

0.3.0

5 release files

0.2.0

5 release files

0.1.1

5 release files

0.1.0

5 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page