Skip to main content

Adaptable security middlewares for FastAPI: API keys, rate limiting, IP whitelist

Project description

OS FastAPI Middlewares

Simple and adaptable: production-ready security middlewares for FastAPI, including API Key, Rate Limit, and IP Whitelist. Plug in in-memory or Redis providers, or implement your own.

  • API Key: validates a key from the request, optionally injects metadata into request.state
  • Rate Limit: enforces requests per time window and adds X-RateLimit-* headers
  • IP Whitelist: allows only approved IPs or networks (supports CIDR)

Docs: see docs/installation.md, docs/quickstart.md, and docs/advanced.md.

Installation

  • Basic: pip install os-fastapi-middleware
  • With Redis (optional): pip install os-fastapi-middleware[redis]

Requirements: Python >= 3.8, FastAPI >= 0.100, Starlette >= 0.27.

Quick example

from fastapi import FastAPI, Request
from os_fastapi_middleware.middleware import APIKeyMiddleware, RateLimitMiddleware, IPWhitelistMiddleware
from os_fastapi_middleware.providers import (
    InMemoryAPIKeyProvider,
    InMemoryRateLimitProvider,
    InMemoryIPWhitelistProvider,
)

app = FastAPI()

api_key_provider = InMemoryAPIKeyProvider(valid_keys={
    "account_123": "secret-key-123"
})
rate_limit_provider = InMemoryRateLimitProvider()
ip_whitelist_provider = InMemoryIPWhitelistProvider(allowed_ips=["127.0.0.1"]) 

app.add_middleware(RateLimitMiddleware, provider=rate_limit_provider, requests_per_window=100, window_seconds=60)
app.add_middleware(APIKeyMiddleware, provider=api_key_provider, include_metadata=True)
app.add_middleware(IPWhitelistMiddleware, provider=ip_whitelist_provider)

@app.get("/secure")
async def secure(request: Request):
    return {"hello": request.state.api_key_metadata["account_id"]}

More examples in examples/.

Per-route or route group usage

You can also apply validations selectively to specific routes or route groups using dependencies:

from fastapi import FastAPI, Depends, Request
from os_fastapi_middleware.dependencies import APIKeyDependency, RateLimitDependency, IPWhitelistDependency
from os_fastapi_middleware.providers import (
    InMemoryAPIKeyProvider,
    InMemoryRateLimitProvider,
    InMemoryIPWhitelistProvider,
)

app = FastAPI()

# Configure providers
api_key_provider = InMemoryAPIKeyProvider(valid_keys={"account_123": "secret-key-123"})
rate_limit_provider = InMemoryRateLimitProvider()
ip_whitelist_provider = InMemoryIPWhitelistProvider(allowed_ips=["127.0.0.1"])

# Create dependency instances
api_key_dep = APIKeyDependency(provider=api_key_provider)
rate_limit_dep = RateLimitDependency(provider=rate_limit_provider, requests_per_window=10, window_seconds=60)
ip_whitelist_dep = IPWhitelistDependency(provider=ip_whitelist_provider)

# Public route - no validation
@app.get("/public")
async def public():
    return {"message": "This is public"}

# Protected route - API key only
@app.get("/protected", dependencies=[Depends(api_key_dep)])
async def protected():
    return {"message": "API key validated"}

# Strict route - multiple validations
@app.get("/admin", dependencies=[Depends(ip_whitelist_dep), Depends(api_key_dep), Depends(rate_limit_dep)])
async def admin():
    return {"message": "Admin area with all protections"}

# Route group with shared dependencies
from fastapi import APIRouter
api_router = APIRouter(prefix="/api", dependencies=[Depends(api_key_dep)])

@api_router.get("/data")
async def get_data():
    return {"data": "protected by API key"}

@api_router.get("/stats")
async def get_stats():
    return {"stats": "also protected by API key"}

app.include_router(api_router)

See examples/selective_routes.py for more details.

Key features

  • Pluggable providers: in-memory, Redis, and base classes to customize
  • Clear configuration: sensible, named parameters
  • Rate limit headers: X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset
  • Works behind proxies (X-Forwarded-For) when enabled

Tests

Install dev dependencies and run:

pip install -e .[dev]
pytest -q

License

MIT. See LICENSE if available.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

os-fastapi-middleware-1.1.9.tar.gz (19.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

os_fastapi_middleware-1.1.9-py3-none-any.whl (23.1 kB view details)

Uploaded Python 3

File details

Details for the file os-fastapi-middleware-1.1.9.tar.gz.

File metadata

  • Download URL: os-fastapi-middleware-1.1.9.tar.gz
  • Upload date:
  • Size: 19.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for os-fastapi-middleware-1.1.9.tar.gz
Algorithm Hash digest
SHA256 10dd2e42de615918d2af62042a8f6a767dcdfc2504b55d5aa0693a11c684ea3b
MD5 4f2b8661ff7156f8608aed0e7ee74108
BLAKE2b-256 17a489c8135b864ec39eb48af8ef6946ddc708c3f433178038f4b1a1579acd60

See more details on using hashes here.

Provenance

The following attestation bundles were made for os-fastapi-middleware-1.1.9.tar.gz:

Publisher: workflow.yml on tcharrua-odds/os-fastapi-middleware

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file os_fastapi_middleware-1.1.9-py3-none-any.whl.

File metadata

File hashes

Hashes for os_fastapi_middleware-1.1.9-py3-none-any.whl
Algorithm Hash digest
SHA256 5f152b04c0c2094b5a7bb92ddd426381c1ed257a766d2c8a8b9de1904f7925ac
MD5 f5e48b19cdc5d66651b4da60d45e55a8
BLAKE2b-256 5e1d4bc9a8d7ff1a398d7f27495e5e062cc4648017bbc5afe9c7650fff46a731

See more details on using hashes here.

Provenance

The following attestation bundles were made for os_fastapi_middleware-1.1.9-py3-none-any.whl:

Publisher: workflow.yml on tcharrua-odds/os-fastapi-middleware

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page