Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Multi-provider external authentication for Plone

pas.plugins.identity

PyPI Python versions

Documentation CI

GitHub contributors GitHub Repo stars

The backend package for multi-provider external authentication in Plone, built on authlib. See also the frontend package @plone-collective/volto-identity.

One canonical Plone user id maps to many external identities — GitHub, Google, another Plone site, any OpenID Connect provider, an emailed magic link — for the same human, without running a separate identity broker.

Features

  • Identity linking. One account, many providers. The identity key is (provider, subject), and an identity already linked to somebody is never silently re-attached: a collision is a hard error, not a merge.
  • Providers configured through the web. A control panel with a form generated from each driver's published schema, so a driver describes its own settings and the frontend composes rather than describes them. Client secrets are write-only through every API surface, GenericSetup export included.
  • Five shipped drivers. github, google, oidc-generic, plone-identity (another Plone site running this package's server layer), and email for magic-link sign-in. Writing another means subclassing BaseDriver and registering a utility.
  • Magic-link sign-in. Single-use signed tokens, at most fifteen minutes, rate limited per address and per IP, answering identically for known and unknown addresses.
  • An audit log. Successes and refusals, per user or site-wide, bounded and purged on write. IP address and user agent are off by default, and the sink is a utility a deployment can replace.
  • A documented event contract, which is what the audit log, the profile machinery and your own integrations all consume. Nothing reaches into anything else.
  • Content-backed profiles and groups, with user properties, enumeration and group membership served entirely from a dedicated catalog. No content object is woken to answer them, and the test suite asserts that rather than claiming it.
  • Federated group membership. Each provider's grants are recorded separately, so signing in through one never revokes what another gave you, and local grants survive both.
  • Migrations from pas.plugins.authomatic and pas.plugins.oidc. Dry-run by default, idempotent, and they report what they would do before you let them do it.
  • Core installs alone. uv add pas.plugins.identity with no extras is a tested configuration, enforced in CI by an import-linter contract rather than by discipline.

Layers and extras

The package installs as a core, with one optional layer beside it. [server] is that layer, and it brings a GenericSetup profile of its own. [sql] is an extra rather than a layer: it adds one audit sink and installs no profile.

Profile What it adds
pas.plugins.identity:default Sign in with external providers, identity linking, the audit log, the control panel, and the content types users and groups are.
pas.plugins.identity.server:default An OAuth 2.1 and OpenID Connect authorization server, so the site can be a provider for others.
Extra Adds Profile
[server] The authorization server layer. pas.plugins.identity.server:default
[sql] An audit sink writing a row per event to a relational database. Needs IDENTITY_AUDIT_DSN. none — name sql in audit_sinks.

Core never imports from the server layer, and CI fails the build if it starts to. Read the layers page for why the boundary is more than tidiness.

Not in scope

  • Being an identity broker. Providers are configured on the site and mapped onto its own users; this package does not proxy one provider to another.
  • Merging two existing accounts. A colliding identity is refused rather than reconciled, because a merge that guesses is worse than a refusal that explains.
  • Storing credentials in a Dexterity field. Passwords stay in source_users, or in an annotation for a site that opts into ICredentialStorage. A field would be serialized, exported, indexed and versioned: four disclosure paths, each of which has to be remembered separately.
  • SAML. Nothing here precludes a driver for it; none ships.

Documentation

Full documentation is published at collective.github.io/pas-plugins-identity, and its source lives in docs/ at the repository root.

The pages closest to this package:

Installation

Requires Plone 6.2 and Python 3.12 or later.

Install pas.plugins.identity with uv.

uv add pas.plugins.identity

For the authorization server as well:

uv add "pas.plugins.identity[server]"

Create the Plone site.

make create-site

Then install pas.plugins.identity from the add-ons control panel, and configure a provider in Site Setup > Identity providers.

Contribute

Prerequisites ✅

Installation 🔧

  1. Clone this repository.

    git clone git@github.com:collective/pas-plugins-identity.git
    cd pas-plugins-identity/backend
    
  2. Install this code base.

    make install
    

Tests

make test

Part of the suite drives a real OpenID Connect provider in a container and is marked docker. To run everything else:

uv run pytest -m "not docker"

License

The project is licensed under GPLv2.

Credits and acknowledgements 🙏

Generated using Cookieplone (2.0.0b3) and cookieplone-templates (91c8455) on 2026-08-20 18:32:15.036687. A special thanks to all contributors and supporters!

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pas_plugins_identity-1.0.0a4.tar.gz (767.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pas_plugins_identity-1.0.0a4-py3-none-any.whl (470.8 kB view details)

Uploaded Python 3

File details

Details for the file pas_plugins_identity-1.0.0a4.tar.gz.

File metadata

  • Download URL: pas_plugins_identity-1.0.0a4.tar.gz
  • Upload date:
  • Size: 767.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.10 {"installer":{"name":"uv","version":"0.12.10","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for pas_plugins_identity-1.0.0a4.tar.gz
Algorithm Hash digest
SHA256 3e88b4947d00d28ee705901bec43749ab84e416c0772a25758c5706a15aacff6
MD5 cb870bcc8e03494cda65a5e77a6dc82a
BLAKE2b-256 416f468e5ba9b4aa08eee00e2e1305aa3f1b179a41e81e0b1c580bd3e4c788a6

See more details on using hashes here.

File details

Details for the file pas_plugins_identity-1.0.0a4-py3-none-any.whl.

File metadata

  • Download URL: pas_plugins_identity-1.0.0a4-py3-none-any.whl
  • Upload date:
  • Size: 470.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.10 {"installer":{"name":"uv","version":"0.12.10","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for pas_plugins_identity-1.0.0a4-py3-none-any.whl
Algorithm Hash digest
SHA256 5993f6e1d8b751f8fab8271e28c67d4e95cb3d1e4122d6498ae9eab417af5274
MD5 c21a47d3e61412e2fce0c9b36d22217f
BLAKE2b-256 9f77fae95a97f71890ad2a085c5bb52dd5d28153dfb45a279633040b9b6714d9

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

1.0.0a4 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page