Skip to main content

An OAuth 2.0 client library for Python, with requests integration.

Project description

A Python OAuth 2.0 client, able to make backend requests to any OAuth2.0/OIDC compliant Authorization Server Token Endpoint.

It comes with a requests add-on to handle OAuth 2.0 Bearer based authorization. It can also act as an OAuth 2.0 client, to automatically get and renew access tokens, based on the Client Credentials and Authorization Code (+ Refresh token) grants.

Use it like this:

If you already managed to obtain an access token, you can simply use the BearerAuth authorization:

token = "an_access_token"
resp = requests.get("https://my.protected.api/endpoint", auth=BearerAuth(token))

If you want requests to fetch an access token automatically with OAuth2.0 Client Credentials grant, using a client_id and client_secret against a given Token Endpoint:

client = OAuth2Client(token_endpoint, ClientSecretPost("client_id", "client_secret"))
auth = OAuth2ClientCredentialsAuth(client, audience=audience) # pass scope, resource, audience or whatever param the AS use to grant you access
response = requests.get("https://my.protected.api/endpoint", auth=auth)

If you want to use the authorization code grant, you must first manage to obtain an authorization code, then exchange that code for an initial access token:

authorization_handler = AuthorizationCodeHandler(
    authorization_endpoint,
    client_id,
    redirect_uri=redirect_uri,
    scope=scope,
    audience=audience,
)
print(authorization_request.request) # redirect the user to that URL to get a code

# once the user is successfully authenticated and authorized, the AS will respond with a redirection to the redirect_uri
# the code is one of those parameters, but you must also validate the state
params = input("Please enter the path and/or params obtained on the redirect_uri: ")
code = authorization_handler.validate_callback(params)

# initialize a OAuth2Client, same way as before
client = OAuth2Client(token_endpoint, ClientSecretPost(client_id, client_secret))

# once you have the code, you can exchange it manually for a token:
token = client.authorization_code(code=code, redirect_uri=redirect_uri)
resp = requests.post("https://your.protected.api/endpoint", auth=BearerAuthorization(token))

# or you can use the OAuth2AuthorizationCodeAuth auth scheme:
auth = OAuth2AuthorizationCodeAuth(client, code)
resp = requests.post("https://your.protected.api/endpoint", auth=auth)
# OAuth20AuthorizationCode will take care of refreshing the token automatically once it is expired,
# using the refresh token, if available

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

requests_oauth2client-0.9.1.tar.gz (13.2 kB view details)

Uploaded Source

File details

Details for the file requests_oauth2client-0.9.1.tar.gz.

File metadata

  • Download URL: requests_oauth2client-0.9.1.tar.gz
  • Upload date:
  • Size: 13.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.2.0 pkginfo/1.5.0.1 requests/2.25.1 setuptools/49.2.1 requests-toolbelt/0.9.1 tqdm/4.48.2 CPython/3.6.8

File hashes

Hashes for requests_oauth2client-0.9.1.tar.gz
Algorithm Hash digest
SHA256 dc97ead8d0d4e726948c20ba2bfe78bd6b39a50557a6838a6261f3f6e9b79db0
MD5 1c0f1d1220578ad07432b4579c3c1c04
BLAKE2b-256 5aeaedb0da8ab6da4951c8d7f13d4da11d70a9fabd976d9c670844636767d9e8

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page