Skip to main content


Official Python SDK

PyPI version License: MIT Python versions

Scalekit is the auth stack for AI apps - from human authentication to agent authorization. Build secure AI products faster with authentication for humans (SSO, passwordless, full-stack auth) and agents (MCP/APIs, delegated actions), all unified on one platform. This Python SDK enables both traditional B2B authentication and cutting-edge agentic workflows.

🤖 Agent-First Features

  • 🔐 Agent Identity: Agents as first-class actors with human ownership and org context
  • 🎯 MCP-Native OAuth 2.1: Purpose-built for Model Context Protocol with DCR/PKCE support
  • ⏰ Ephemeral Credentials: Time-bound, task-based authorization (minutes, not days)
  • 🔒 Token Vault: Per-user, per-tool token storage with rotation and progressive consent
  • 👥 Human-in-the-Loop: Step-up authentication when risk crosses thresholds
  • 📊 Immutable Audit: Track which user initiated, which agent acted, what resource was accessed

👨‍💼 Human Authentication

  • 🔐 Enterprise SSO: Support for SAML and OIDC protocols
  • 👥 SCIM Provisioning: Automated user provisioning and deprovisioning
  • 🚀 Passwordless Authentication: Magic links, OTP, and modern auth flows
  • 🏢 Multi-tenant Architecture: Organization-level authentication policies
  • 📱 Social Logins: Support for popular social identity providers
  • 🛡️ Full-Stack Auth: Complete IdP-of-record solution for B2B SaaS
  • 🐍 Pythonic API: Clean, intuitive interface following Python conventions
📚 Documentation • 🚀 SSO Quickstart • 💻 API Reference

Pre-requisites

  1. Sign up for a Scalekit account.
  2. Get your env_url, client_id and client_secret from the Scalekit dashboard.

Installation

Install Scalekit SDK using your preferred package manager.

pip install scalekit-sdk-python

Usage

from scalekit import ScalekitClient

sc = ScalekitClient(
  env_url, 
  client_id, 
  client_secret
)

# Use the sc object to interact with the Scalekit API
auth_url = sc.get_authorization_url(
  "https://acme-corp.com/redirect-uri",
  state="state",
  connection_id="con_123456789"
)
Minimum Requirements

To use the Scalekit Python SDK, you must have the following:

Component Version
Python 3.8+

Tip: Although Python 3.8 meets the minimum requirement, using a more recent version (such as Python 3.9 or later) is advisable.

Examples - SSO with FastAPI

Below is a simple code sample that showcases how to implement Single Sign-on using Scalekit SDK

from fastapi import FastAPI, Request, Response
from scalekit import ScalekitClient
import uvicorn

app = FastAPI()

sc = ScalekitClient(
  env_url, 
  client_id, 
  client_secret
)

redirect_uri = "http://localhost:8000/auth/callback"

@app.get("/auth/login")
async def auth_login(request: Request):
  auth_url = sc.get_authorization_url(
    redirect_uri,
    state="state",
    connection_id="con_123456789"
  )
  return Response(status_code=302, headers={"Location": auth_url})

@app.get("/auth/callback")
async def auth_callback(request: Request):
  code = request.query_params.get("code")
  token = sc.authenticate_with_code(
    code, 
    redirect_uri
  )
  response = JSONResponse(content=token)
  response.set_cookie("access_token", token["access_token"])

  return response

if __name__ == "__main__":
  uvicorn.run(app, port=8080)

📱 Example Apps

Explore fully functional sample applications built with popular Python frameworks and the Scalekit SDK:

Framework Repository Description
FastAPI scalekit-fastapi-example Modern async Python API framework

Full Stack Auth — encrypted-session middleware for Flask, FastAPI, and Django

The example above is for Modular SSO: Scalekit brokers the OAuth exchange with your customer's own IdP via a connection_id, and your app owns its own session however it likes.

If instead Scalekit hosts your login UI and you want it to also manage the session lifecycle for you (Full Stack Auth), scalekit-sdk-python ships optional Flask, FastAPI, and Django extras that handle the encrypted session cookie, transparent token refresh, CSRF-safe login/callback, and full logout for you — no hand-rolled cookies, no manual refresh timing.

Register these under Dashboard → Authentication → Redirects before testing:

  • Redirect URI — your redirect_uri (the /callback path). Scalekit rejects the exchange if this doesn't match exactly.
  • Post Logout Redirect URI — where users land after full logout. A relative path gets auto-absolutized against the request host, but the resulting absolute URL must still be registered.
  • Initiate Login URL — your /login path. Scalekit redirects here (not /callback) for a bookmarked login page, an IdP portal tile, or an invite/magic link — the login view already handles this correctly, including the idp_initiated_login case, with no extra code required.

pip install "scalekit-sdk-python[flask]" # or "scalekit-sdk-python[fastapi]" or "scalekit-sdk-python[django]"

# Flask
import os
from flask import Flask
from scalekit.frameworks.flask import ScalekitAuth

app = Flask(__name__)
auth = ScalekitAuth(
    app,
    env_url=os.environ["SCALEKIT_ENV_URL"],
    client_id=os.environ["SCALEKIT_CLIENT_ID"],
    client_secret=os.environ["SCALEKIT_CLIENT_SECRET"],
    redirect_uri="https://myapp.com/callback",
    cookie_encryption_secret=os.environ["COOKIE_ENCRYPTION_SECRET"],  # openssl rand -base64 32
)  # registers /login, /callback, /logout

@app.route("/account")
@auth.requires_auth
def account():
    return {"email": auth.current_user["email"]}
# FastAPI -- protect routes with Depends(), FastAPI's idiomatic mechanism
import os
from fastapi import Depends, FastAPI
from scalekit.frameworks.fastapi import ScalekitAuth

app = FastAPI()
auth = ScalekitAuth(
    env_url=os.environ["SCALEKIT_ENV_URL"],
    client_id=os.environ["SCALEKIT_CLIENT_ID"],
    client_secret=os.environ["SCALEKIT_CLIENT_SECRET"],
    redirect_uri="https://myapp.com/callback",
    cookie_encryption_secret=os.environ["COOKIE_ENCRYPTION_SECRET"],
)
auth.install(app)  # registers /login, /callback, /logout

@app.get("/account")
async def account(user: dict = Depends(auth.requires_auth)):
    return {"email": user["email"]}
# Django -- settings.py
import os

MIDDLEWARE = [..., "scalekit.frameworks.django.ScalekitAuthMiddleware"]
SCALEKIT_ENV_URL = os.environ["SCALEKIT_ENV_URL"]
SCALEKIT_CLIENT_ID = os.environ["SCALEKIT_CLIENT_ID"]
SCALEKIT_CLIENT_SECRET = os.environ["SCALEKIT_CLIENT_SECRET"]
SCALEKIT_REDIRECT_URI = "https://myapp.com/callback"
SCALEKIT_COOKIE_ENCRYPTION_SECRET = os.environ["COOKIE_ENCRYPTION_SECRET"]

# urls.py
from django.urls import include, path
urlpatterns = [path("", include("scalekit.frameworks.django")), ...]  # /login, /callback, /logout

# views.py
from django.http import JsonResponse
from scalekit.frameworks.django import login_required

@login_required
def account(request):
    return JsonResponse(request.scalekit_user)

See examples/flask, examples/fastapi, and examples/django for complete, runnable versions. For a fuller production-oriented sample app, see the framework repos above.

🔗 Helpful Links

📖 Quickstart Guides

📚 Documentation & Reference

🛠️ Additional Resources

License

This project is licensed under the MIT license. See the LICENSE file for more information.

Release files for scalekit-sdk-python 2.18.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for scalekit-sdk-python 2.18.0
File Size Uploaded
scalekit_sdk_python-2.18.0.tar.gz 617.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for scalekit-sdk-python 2.18.0
File Interpreter ABI Platform
scalekit_sdk_python-2.18.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.3 MB

Release files / scalekit_sdk_python-2.18.0.tar.gz

Download URL scalekit_sdk_python-2.18.0.tar.gz
Size 617.8 kB
Tags Source
SHA-256 checksum
How to use checksums
ff2d888c041561ff1ab98a397ac72380dbc39e39aa8077f27c826fa910123868
BLAKE2b-256 checksum
How to use checksums
169ebe4ba0ae244cb9418317c316306c8c1df5995c833dcdc1fb71a53fc90c9c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release files / scalekit_sdk_python-2.18.0-py3-none-any.whl

Download URL scalekit_sdk_python-2.18.0-py3-none-any.whl
Size 639.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c3d1a2ba8b232ada68f81cd2be31432d77a7d72e41f5a929b0665177a2e44693
BLAKE2b-256 checksum
How to use checksums
ed420475a99f29bf495c30a309b2e28bfb0b7162d0c832b31f5e09690bc87925
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release history Release notifications | RSS feed

2.19.1

2 release files

2.19.0

2 release files

This release

2.18.0 This release

2 release files

2.17.0

2 release files

2.16.0

2 release files

2.15.0

2 release files

2.14.0

2 release files

2.10.0

2 release files

2.9.0

2 release files

2.8.0

2 release files

2.7.3

2 release files

2.7.2

2 release files

2.7.1

2 release files

2.6.1

2 release files

2.6.0

2 release files

2.5.0

2 release files

2.4.17

2 release files

2.4.16

2 release files

2.4.15

2 release files

2.4.14

2 release files

2.4.13

2 release files

2.4.12

2 release files

2.4.10

2 release files

2.4.9

2 release files

2.4.8

2 release files

2.4.7

2 release files

2.4.6

2 release files

2.4.5

2 release files

2.4.4

2 release files

2.4.3

2 release files

2.4.2

2 release files

2.4.1

2 release files

2.4.0

2 release files

2.3.3

2 release files

2.3.2

2 release files

2.3.1

2 release files

2.3.0

2 release files

2.2.2

2 release files

2.2.1

2 release files

2.2.0

2 release files

2.0.1

2 release files

2.0.0

2 release files

1.1.0

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page