Skip to main content

Adaptable security middlewares for FastAPI: API keys, rate limiting, IP whitelist

Project description

OS FastAPI Middlewares

Simple and adaptable: production-ready security middlewares for FastAPI, including API Key, Rate Limit, and IP Whitelist. Plug in in-memory or Redis providers, or implement your own.

  • API Key: validates a key from the request, optionally injects metadata into request.state
  • Rate Limit: enforces requests per time window and adds X-RateLimit-* headers
  • IP Whitelist: allows only approved IPs or networks (supports CIDR)

Docs: see docs/installation.md, docs/quickstart.md, and docs/advanced.md.

Installation

  • Basic: pip install os-fastapi-middleware
  • With Redis (optional): pip install os-fastapi-middleware[redis]

Requirements: Python >= 3.8, FastAPI >= 0.100, Starlette >= 0.27.

Quick example

from fastapi import FastAPI, Request
from os_fastapi_middleware.middleware import APIKeyMiddleware, RateLimitMiddleware, IPWhitelistMiddleware
from os_fastapi_middleware.providers import (
    InMemoryAPIKeyProvider,
    InMemoryRateLimitProvider,
    InMemoryIPWhitelistProvider,
)

app = FastAPI()

api_key_provider = InMemoryAPIKeyProvider(valid_keys={
    "account_123": "secret-key-123"
})
rate_limit_provider = InMemoryRateLimitProvider()
ip_whitelist_provider = InMemoryIPWhitelistProvider(allowed_ips=["127.0.0.1"]) 

app.add_middleware(RateLimitMiddleware, provider=rate_limit_provider, requests_per_window=100, window_seconds=60)
app.add_middleware(APIKeyMiddleware, provider=api_key_provider, include_metadata=True)
app.add_middleware(IPWhitelistMiddleware, provider=ip_whitelist_provider)

@app.get("/secure")
async def secure(request: Request):
    return {"hello": request.state.api_key_metadata["account_id"]}

More examples in examples/.

Per-route or route group usage

You can also apply validations selectively to specific routes or route groups using dependencies:

from fastapi import FastAPI, Depends, Request
from os_fastapi_middleware.dependencies import APIKeyDependency, RateLimitDependency, IPWhitelistDependency
from os_fastapi_middleware.providers import (
    InMemoryAPIKeyProvider,
    InMemoryRateLimitProvider,
    InMemoryIPWhitelistProvider,
)

app = FastAPI()

# Configure providers
api_key_provider = InMemoryAPIKeyProvider(valid_keys={"account_123": "secret-key-123"})
rate_limit_provider = InMemoryRateLimitProvider()
ip_whitelist_provider = InMemoryIPWhitelistProvider(allowed_ips=["127.0.0.1"])

# Create dependency instances
api_key_dep = APIKeyDependency(provider=api_key_provider)
rate_limit_dep = RateLimitDependency(provider=rate_limit_provider, requests_per_window=10, window_seconds=60)
ip_whitelist_dep = IPWhitelistDependency(provider=ip_whitelist_provider)

# Public route - no validation
@app.get("/public")
async def public():
    return {"message": "This is public"}

# Protected route - API key only
@app.get("/protected", dependencies=[Depends(api_key_dep)])
async def protected():
    return {"message": "API key validated"}

# Strict route - multiple validations
@app.get("/admin", dependencies=[Depends(ip_whitelist_dep), Depends(api_key_dep), Depends(rate_limit_dep)])
async def admin():
    return {"message": "Admin area with all protections"}

# Route group with shared dependencies
from fastapi import APIRouter
api_router = APIRouter(prefix="/api", dependencies=[Depends(api_key_dep)])

@api_router.get("/data")
async def get_data():
    return {"data": "protected by API key"}

@api_router.get("/stats")
async def get_stats():
    return {"stats": "also protected by API key"}

app.include_router(api_router)

See examples/selective_routes.py for more details.

Key features

  • Pluggable providers: in-memory, Redis, and base classes to customize
  • Clear configuration: sensible, named parameters
  • Rate limit headers: X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset
  • Works behind proxies (X-Forwarded-For) when enabled

Tests

Install dev dependencies and run:

pip install -e .[dev]
pytest -q

License

MIT. See LICENSE if available.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

os-fastapi-middleware-1.1.0.tar.gz (14.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

os_fastapi_middleware-1.1.0-py3-none-any.whl (16.8 kB view details)

Uploaded Python 3

File details

Details for the file os-fastapi-middleware-1.1.0.tar.gz.

File metadata

  • Download URL: os-fastapi-middleware-1.1.0.tar.gz
  • Upload date:
  • Size: 14.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for os-fastapi-middleware-1.1.0.tar.gz
Algorithm Hash digest
SHA256 c917c9a6e30ef483f3df4663f1e004b161aefc8f3f0e20bd8e5416f2cefc2b8a
MD5 ce4b81e947bfb9aa90db42a8c4d0bc59
BLAKE2b-256 5020ed9f0d701d85d4e5bc8dc6ef835d8535cfedd9c9234fb99436a383f0929b

See more details on using hashes here.

Provenance

The following attestation bundles were made for os-fastapi-middleware-1.1.0.tar.gz:

Publisher: workflow.yml on tcharrua-odds/os-fastapi-middleware

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file os_fastapi_middleware-1.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for os_fastapi_middleware-1.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c4d4681b4ce7de4e72e3daecebdf8840f84be2106565bc1d0b25502d53e53a1d
MD5 2254eb56fe7212f29717edba29fd9d53
BLAKE2b-256 307ac443f1690d430a7f10d45164696c80b28a488b9f12a83e634983d50acc32

See more details on using hashes here.

Provenance

The following attestation bundles were made for os_fastapi_middleware-1.1.0-py3-none-any.whl:

Publisher: workflow.yml on tcharrua-odds/os-fastapi-middleware

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page