Skip to main content

simple_module_users

Email+password user management for simple_module apps. Replaces Keycloak/Auth0 for the common case: local accounts, admin invites, password reset, optional public signup. Built on fastapi-users.

Install

pip install simple_module_users

Pre-wired into any app scaffolded with smpy new.

What it provides

  • Email + password registration, login, logout, password reset.
  • Admin invite flow — admin enters an email, recipient clicks a link, sets a password, is logged in.
  • Public signup toggle (SM_USERS_ALLOW_SIGNUP, default false).
  • Bootstrap admin via env vars (SM_USERS_BOOTSTRAP_EMAIL + SM_USERS_BOOTSTRAP_PASSWORD) — idempotent, only creates if the users table is empty.
  • smpy users create-admin CLI for ad-hoc admin creation.
  • Inertia pages for login/register/invite-accept/admin-invite.
  • Console mailer (logs to stdout) or SMTP mailer (SM_USERS_MAILER=smtp).

Usage

CLI:

uv run smpy users create-admin --email admin@example.com --password 'change-me'

Bootstrap-on-boot (.env):

SM_USERS_BOOTSTRAP_EMAIL=admin@example.com
SM_USERS_BOOTSTRAP_PASSWORD=change-me

Program:

from auth.deps import CurrentUser  # type: ignore[import-not-found]


@router.get("/profile")
async def profile(user: CurrentUser):
    return {"email": user.email}

Depends on

  • simple_module_core, simple_module_db, simple_module_hosting, simple_module_settings, simple_module_auth
  • fastapi-users[sqlalchemy,oauth]>=15,<16, aiosmtplib, cachetools, typer

Social sign-in (Google, GitHub, Microsoft, OIDC)

OAuth providers are configured in the admin UI at /settings/modules → Users (no environment variables). Each provider activates once its client id and secret are set; the secret is masked in the UI. Changes apply live — no restart.

Microsoft (Entra ID). Register an app in the Entra admin center and set the redirect URI to <base-url>/api/users/auth/microsoft/callback. Configure under the Microsoft OAuth group:

  • oauth_microsoft_client_id, oauth_microsoft_client_secret
  • oauth_microsoft_tenantcommon (any work/school or personal account, the default), organizations (work/school only), or your tenant GUID to restrict sign-in to one tenant.

Each provider's callback URL is <base-url>/api/users/auth/<provider>/callback (google, github, microsoft, oidc).

Note: for Microsoft guest/external accounts the identity email comes from the Graph userPrincipalName, which may not be a plain email (e.g. user_ext.com#EXT#@tenant.onmicrosoft.com). For tenant members it is the user's email.

Migrating from SM_USERS_OAUTH_* env vars

Earlier versions read provider credentials from SM_USERS_OAUTH_* environment variables. These are no longer read at runtime. Migrate existing values into the settings store once with:

uv run smpy settings import-from-env

License

MIT — see LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

simple_module_users-0.0.32.tar.gz (109.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

simple_module_users-0.0.32-py3-none-any.whl (106.8 kB view details)

Uploaded Python 3

File details

Details for the file simple_module_users-0.0.32.tar.gz.

File metadata

  • Download URL: simple_module_users-0.0.32.tar.gz
  • Upload date:
  • Size: 109.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for simple_module_users-0.0.32.tar.gz
Algorithm Hash digest
SHA256 3784c73fcb2dcb4ca6f41db63084f4cb464b0fb2de88a47c2996bf38ba5a766f
MD5 3ee86e3892b656348051230d367dc33d
BLAKE2b-256 dcf53530881930622b74ed2a55998dc0e71af77c254e90a5fd882dc17c17ced5

See more details on using hashes here.

Provenance

The following attestation bundles were made for simple_module_users-0.0.32.tar.gz:

Publisher: release.yml on antosubash/simple_module_python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file simple_module_users-0.0.32-py3-none-any.whl.

File metadata

File hashes

Hashes for simple_module_users-0.0.32-py3-none-any.whl
Algorithm Hash digest
SHA256 2236d1ddf2d9633fc66b35f7742db9aef966d6a5777b07017366f90d5a731564
MD5 c0664266635f78d00bd388af27718a05
BLAKE2b-256 6eb0677bbf3e8814ab6f68c13429458f53c6e77d236a69a4e28c9d2c8a5720e8

See more details on using hashes here.

Provenance

The following attestation bundles were made for simple_module_users-0.0.32-py3-none-any.whl:

Publisher: release.yml on antosubash/simple_module_python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.0.33

2 files

This release

0.0.32 This release

2 files

0.0.31

2 files

0.0.30

2 files

0.0.29

2 files

0.0.28

2 files

0.0.27

2 files

0.0.26

2 files

0.0.25

2 files

0.0.24

2 files

0.0.23

2 files

0.0.22

2 files

0.0.21

2 files

0.0.20

2 files

0.0.19

2 files

0.0.18

2 files

0.0.17

2 files

0.0.16

2 files

0.0.15

2 files

0.0.14

2 files

0.0.13

2 files

0.0.12

2 files

0.0.11

2 files

0.0.10

2 files

0.0.9

2 files

0.0.8

2 files

0.0.7

2 files

0.0.6

2 files

0.0.5

2 files

0.0.4

2 files

0.0.3

2 files

0.0.2

2 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page