Skip to main content

Adaptable security middlewares for FastAPI: API keys, rate limiting, IP whitelist

Project description

OS FastAPI Middlewares

Simple and adaptable: production-ready security middlewares for FastAPI, including API Key, Rate Limit, and IP Whitelist. Plug in in-memory or Redis providers, or implement your own.

  • API Key: validates a key from the request, optionally injects metadata into request.state
  • Rate Limit: enforces requests per time window and adds X-RateLimit-* headers
  • IP Whitelist: allows only approved IPs or networks (supports CIDR)

Docs: see docs/installation.md, docs/quickstart.md, and docs/advanced.md.

Installation

  • Basic: pip install os-fastapi-middleware
  • With Redis (optional): pip install os-fastapi-middleware[redis]

Requirements: Python >= 3.8, FastAPI >= 0.100, Starlette >= 0.27.

Quick example

from fastapi import FastAPI, Request
from os_fastapi_middleware.middleware import APIKeyMiddleware, RateLimitMiddleware, IPWhitelistMiddleware
from os_fastapi_middleware.providers import (
    InMemoryAPIKeyProvider,
    InMemoryRateLimitProvider,
    InMemoryIPWhitelistProvider,
)

app = FastAPI()

api_key_provider = InMemoryAPIKeyProvider(valid_keys={
    "account_123": "secret-key-123"
})
rate_limit_provider = InMemoryRateLimitProvider()
ip_whitelist_provider = InMemoryIPWhitelistProvider(allowed_ips=["127.0.0.1"]) 

app.add_middleware(RateLimitMiddleware, provider=rate_limit_provider, requests_per_window=100, window_seconds=60)
app.add_middleware(APIKeyMiddleware, provider=api_key_provider, include_metadata=True)
app.add_middleware(IPWhitelistMiddleware, provider=ip_whitelist_provider)

@app.get("/secure")
async def secure(request: Request):
    return {"hello": request.state.api_key_metadata["account_id"]}

More examples in examples/.

Per-route or route group usage

You can also apply validations selectively to specific routes or route groups using dependencies:

from fastapi import FastAPI, Depends, Request
from os_fastapi_middleware.dependencies import APIKeyDependency, RateLimitDependency, IPWhitelistDependency
from os_fastapi_middleware.providers import (
    InMemoryAPIKeyProvider,
    InMemoryRateLimitProvider,
    InMemoryIPWhitelistProvider,
)

app = FastAPI()

# Configure providers
api_key_provider = InMemoryAPIKeyProvider(valid_keys={"account_123": "secret-key-123"})
rate_limit_provider = InMemoryRateLimitProvider()
ip_whitelist_provider = InMemoryIPWhitelistProvider(allowed_ips=["127.0.0.1"])

# Create dependency instances
api_key_dep = APIKeyDependency(provider=api_key_provider)
rate_limit_dep = RateLimitDependency(provider=rate_limit_provider, requests_per_window=10, window_seconds=60)
ip_whitelist_dep = IPWhitelistDependency(provider=ip_whitelist_provider)

# Public route - no validation
@app.get("/public")
async def public():
    return {"message": "This is public"}

# Protected route - API key only
@app.get("/protected", dependencies=[Depends(api_key_dep)])
async def protected():
    return {"message": "API key validated"}

# Strict route - multiple validations
@app.get("/admin", dependencies=[Depends(ip_whitelist_dep), Depends(api_key_dep), Depends(rate_limit_dep)])
async def admin():
    return {"message": "Admin area with all protections"}

# Route group with shared dependencies
from fastapi import APIRouter
api_router = APIRouter(prefix="/api", dependencies=[Depends(api_key_dep)])

@api_router.get("/data")
async def get_data():
    return {"data": "protected by API key"}

@api_router.get("/stats")
async def get_stats():
    return {"stats": "also protected by API key"}

app.include_router(api_router)

See examples/selective_routes.py for more details.

Key features

  • Pluggable providers: in-memory, Redis, and base classes to customize
  • Clear configuration: sensible, named parameters
  • Rate limit headers: X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset
  • Works behind proxies (X-Forwarded-For) when enabled

Tests

Install dev dependencies and run:

pip install -e .[dev]
pytest -q

License

MIT. See LICENSE if available.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

os-fastapi-middleware-1.1.3.tar.gz (16.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

os_fastapi_middleware-1.1.3-py3-none-any.whl (20.0 kB view details)

Uploaded Python 3

File details

Details for the file os-fastapi-middleware-1.1.3.tar.gz.

File metadata

  • Download URL: os-fastapi-middleware-1.1.3.tar.gz
  • Upload date:
  • Size: 16.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for os-fastapi-middleware-1.1.3.tar.gz
Algorithm Hash digest
SHA256 640bb12371a0e798bd5ff1dd1694ed663181271e68f69d503c753fd057d026b1
MD5 a03e07764dc20f880355dfd53402bd00
BLAKE2b-256 aa3d9d28b9b97fd783d332b88343be63c92224e1da39ebdfcf5001d00b67c781

See more details on using hashes here.

Provenance

The following attestation bundles were made for os-fastapi-middleware-1.1.3.tar.gz:

Publisher: workflow.yml on tcharrua-odds/os-fastapi-middleware

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file os_fastapi_middleware-1.1.3-py3-none-any.whl.

File metadata

File hashes

Hashes for os_fastapi_middleware-1.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 f3d5bbbeed1938a48061773a3d7a1bbc316905b24e0a9a0431491103bf43355a
MD5 2b618954f576114b72af0ddde4b92135
BLAKE2b-256 cf3c038aea0371e05605ccb0796434ff56cbd6449cbc4308fca81d490e264219

See more details on using hashes here.

Provenance

The following attestation bundles were made for os_fastapi_middleware-1.1.3-py3-none-any.whl:

Publisher: workflow.yml on tcharrua-odds/os-fastapi-middleware

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page