Skip to main content

Adaptable security middlewares for FastAPI: API keys, rate limiting, IP whitelist

Project description

OS FastAPI Middlewares

Simple and adaptable: production-ready security middlewares for FastAPI, including API Key, Rate Limit, and IP Whitelist. Plug in in-memory or Redis providers, or implement your own.

  • API Key: validates a key from the request, optionally injects metadata into request.state
  • Rate Limit: enforces requests per time window and adds X-RateLimit-* headers
  • IP Whitelist: allows only approved IPs or networks (supports CIDR)

Docs: see docs/installation.md, docs/quickstart.md, and docs/advanced.md.

Installation

  • Basic: pip install os-fastapi-middleware
  • With Redis (optional): pip install os-fastapi-middleware[redis]

Requirements: Python >= 3.8, FastAPI >= 0.100, Starlette >= 0.27.

Quick example

from fastapi import FastAPI, Request
from os_fastapi_middleware.middleware import APIKeyMiddleware, RateLimitMiddleware, IPWhitelistMiddleware
from os_fastapi_middleware.providers import (
    InMemoryAPIKeyProvider,
    InMemoryRateLimitProvider,
    InMemoryIPWhitelistProvider,
)

app = FastAPI()

api_key_provider = InMemoryAPIKeyProvider(valid_keys={
    "account_123": "secret-key-123"
})
rate_limit_provider = InMemoryRateLimitProvider()
ip_whitelist_provider = InMemoryIPWhitelistProvider(allowed_ips=["127.0.0.1"]) 

app.add_middleware(RateLimitMiddleware, provider=rate_limit_provider, requests_per_window=100, window_seconds=60)
app.add_middleware(APIKeyMiddleware, provider=api_key_provider, include_metadata=True)
app.add_middleware(IPWhitelistMiddleware, provider=ip_whitelist_provider)

@app.get("/secure")
async def secure(request: Request):
    return {"hello": request.state.api_key_metadata["account_id"]}

More examples in examples/.

Per-route or route group usage

You can also apply validations selectively to specific routes or route groups using dependencies:

from fastapi import FastAPI, Depends, Request
from os_fastapi_middleware.dependencies import APIKeyDependency, RateLimitDependency, IPWhitelistDependency
from os_fastapi_middleware.providers import (
    InMemoryAPIKeyProvider,
    InMemoryRateLimitProvider,
    InMemoryIPWhitelistProvider,
)

app = FastAPI()

# Configure providers
api_key_provider = InMemoryAPIKeyProvider(valid_keys={"account_123": "secret-key-123"})
rate_limit_provider = InMemoryRateLimitProvider()
ip_whitelist_provider = InMemoryIPWhitelistProvider(allowed_ips=["127.0.0.1"])

# Create dependency instances
api_key_dep = APIKeyDependency(provider=api_key_provider)
rate_limit_dep = RateLimitDependency(provider=rate_limit_provider, requests_per_window=10, window_seconds=60)
ip_whitelist_dep = IPWhitelistDependency(provider=ip_whitelist_provider)

# Public route - no validation
@app.get("/public")
async def public():
    return {"message": "This is public"}

# Protected route - API key only
@app.get("/protected", dependencies=[Depends(api_key_dep)])
async def protected():
    return {"message": "API key validated"}

# Strict route - multiple validations
@app.get("/admin", dependencies=[Depends(ip_whitelist_dep), Depends(api_key_dep), Depends(rate_limit_dep)])
async def admin():
    return {"message": "Admin area with all protections"}

# Route group with shared dependencies
from fastapi import APIRouter
api_router = APIRouter(prefix="/api", dependencies=[Depends(api_key_dep)])

@api_router.get("/data")
async def get_data():
    return {"data": "protected by API key"}

@api_router.get("/stats")
async def get_stats():
    return {"stats": "also protected by API key"}

app.include_router(api_router)

See examples/selective_routes.py for more details.

Key features

  • Pluggable providers: in-memory, Redis, and base classes to customize
  • Clear configuration: sensible, named parameters
  • Rate limit headers: X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset
  • Works behind proxies (X-Forwarded-For) when enabled

Tests

Install dev dependencies and run:

pip install -e .[dev]
pytest -q

License

MIT. See LICENSE if available.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

os-fastapi-middleware-1.1.5.tar.gz (17.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

os_fastapi_middleware-1.1.5-py3-none-any.whl (21.5 kB view details)

Uploaded Python 3

File details

Details for the file os-fastapi-middleware-1.1.5.tar.gz.

File metadata

  • Download URL: os-fastapi-middleware-1.1.5.tar.gz
  • Upload date:
  • Size: 17.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for os-fastapi-middleware-1.1.5.tar.gz
Algorithm Hash digest
SHA256 0cc222ddebe301730e754e6e70764730ac7fb43b43c4b7bb352079e8d551b629
MD5 3f14964b59da2fb981103ec6437484c0
BLAKE2b-256 0f753d601a60869e76fbef5c261922c8459ece7bbbaf6b210691c68d8c9b706c

See more details on using hashes here.

Provenance

The following attestation bundles were made for os-fastapi-middleware-1.1.5.tar.gz:

Publisher: workflow.yml on tcharrua-odds/os-fastapi-middleware

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file os_fastapi_middleware-1.1.5-py3-none-any.whl.

File metadata

File hashes

Hashes for os_fastapi_middleware-1.1.5-py3-none-any.whl
Algorithm Hash digest
SHA256 319124f609e573c573003961c5c5936f6bc0f6e13d5274832b7a0402adb59a55
MD5 e95c07bb53f09dcddd5966b7cd668dcc
BLAKE2b-256 516f0374bdc0486c2b1adb0e7dba398c733150a7b98549e8292c492a933e0602

See more details on using hashes here.

Provenance

The following attestation bundles were made for os_fastapi_middleware-1.1.5-py3-none-any.whl:

Publisher: workflow.yml on tcharrua-odds/os-fastapi-middleware

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page