This release is a pre-release and may not be stable for production use.
swarmauri_tokens_introspection
An OAuth 2.0 token introspection service plugin implementing RFC 7662 for verifying opaque access tokens.
Features
- Asynchronous token verification against a remote introspection endpoint using
httpx - Supports
client_secret_basic,client_secret_post, and bearer authentication schemes - Caches positive and negative introspection results with configurable TTLs and expiry-aware caching
- Validates standard claims (
exp,nbf,iat) with optional issuer and audience enforcement - Optional JWKS passthrough for issuers that also publish signing keys via
jwks_url - Strictly verification-only:
mint()raisesNotImplementedErrorbecause opaque tokens are produced by the authorization server
Installation
Choose the toolchain that matches your project:
pip install swarmauri_tokens_introspection
poetry add swarmauri_tokens_introspection
uv add swarmauri_tokens_introspection
The package exposes an async API, so ensure your environment includes an event loop (e.g., asyncio) when calling it.
Usage
The example below demonstrates how to exercise the service with a mocked introspection endpoint. The same API works against a live OAuth 2.0 Authorization Server?simply omit the mock transport and let httpx reach your configured endpoint.
"""Execute the README example with `python README_example.py`."""
import asyncio
import httpx
from swarmauri_tokens_introspection import IntrospectionTokenService
async def main() -> None:
async def handler(request: httpx.Request) -> httpx.Response:
assert request.method == "POST"
assert request.url == httpx.URL("https://auth.example.com/introspect")
assert request.headers["Authorization"].startswith("Basic ")
form = dict(httpx.QueryParams(request.content.decode()))
assert form["token"] == "opaque-token"
return httpx.Response(
200,
json={
"active": True,
"sub": "user-123",
"scope": "profile email",
"exp": 2_147_483_647,
},
)
transport = httpx.MockTransport(handler)
service = IntrospectionTokenService(
"https://auth.example.com/introspect",
client_id="id",
client_secret="secret",
cache_ttl_s=300,
)
# Inject the mock transport; in production you would not override the client.
service._client = httpx.AsyncClient(transport=transport)
claims = await service.verify("opaque-token")
print(claims["sub"]) # user-123
await service.aclose()
if __name__ == "__main__":
asyncio.run(main())
Caching and validation highlights
- Positive responses respect both
cache_ttl_sand theexpclaim (including the configured leeway). - Negative introspection results are cached for
negative_ttl_sseconds to shield your AS from repeated invalid requests. - Local validation enforces
exp,nbf, andiatdrift usingleeway_s, and supports issuer/audience pinning. - Configuring
jwks_urlenablesjwks()passthrough for deployments that expose signing keys alongside introspection.
License
Apache-2.0 ? Swarmauri
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_tokens_introspection 0.11.0.dev1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_tokens_introspection-0.11.0.dev1.tar.gz | 10.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_tokens_introspection-0.11.0.dev1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 22.4 kB
Release files / swarmauri_tokens_introspection-0.11.0.dev1.tar.gz
| Download URL | swarmauri_tokens_introspection-0.11.0.dev1.tar.gz |
|---|---|
| Size | 10.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
20b70ee8452f14c3114f429d784c6e96a2891fc9cf45c6ea842ba1826d0164f9
|
|
BLAKE2b-256 checksum How to use checksums |
5189b397698074ed700e6367bb28c1443193e3441c3d93a079fd653eda36bb9e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_tokens_introspection-0.11.0.dev1-py3-none-any.whl
| Download URL | swarmauri_tokens_introspection-0.11.0.dev1-py3-none-any.whl |
|---|---|
| Size | 11.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8063332f60ad71162baea2dd87760869d420eec6cc0f58b7bf70f8a0f3b3a3d8
|
|
BLAKE2b-256 checksum How to use checksums |
080bc2d23a2521b990f8f450ed66367bfa2eb7c33ec483e2dc6d2e3d8dddf846
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|