Authlib

The ultimate Python library for building OAuth 1/2 and OpenID Connect clients and servers.

Library
PyPI
v1.8.0
5,425 stars
BSD 3-Clause License

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
87 /100 Excellent
Development Activity 76
Maintenance 92
Community 80
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
80 /100 Excellent
Architecture 84
Code Quality 85
Innovation 80
Learning Curve 70

Authlib is a comprehensive Python library for OAuth 1.0, OAuth 2.0, and OpenID Connect, covering both the client side (consuming third-party OAuth providers) and the server side (implementing your own OAuth/OIDC provider). It bundles a full JOSE implementation — JWS, JWK, JWA, and JWT — used internally for token signing/verification and exposed directly for applications that need to issue or validate JSON Web Tokens on their own.

Rather than being tied to one web framework, Authlib ships dedicated integration modules for Flask, Django, Starlette/FastAPI, and generic requests/httpx HTTP clients, so the same core OAuth/OIDC logic can back a Django-based identity provider, a Flask API consuming Google/GitHub login, or an async FastAPI service, all through framework-specific adapters over shared primitives. It is licensed under BSD-3-Clause with an optional commercial license available for companies wanting paid support or additional features.

What You Get

  • OAuth 1.0 and OAuth 2.0 client implementations for consuming third-party providers (Google, GitHub, etc.)
  • OAuth 2.0 and OpenID Connect server/provider implementations for building your own identity provider
  • A full JOSE stack: JWS, JWK, JWA, and JWT signing/verification, usable standalone
  • Framework-specific integrations for Flask, Django, and Starlette (both client and OAuth-provider sides)
  • requests and httpx OAuth-aware HTTP client wrappers for calling authenticated APIs
  • SQLAlchemy-backed OAuth2 provider mixins (sqla_oauth2) for persisting tokens and clients

Common Use Cases

  • Adding ‘Login with Google/GitHub/etc.’ OAuth client flows to a Flask, Django, or FastAPI app
  • Building a custom OAuth 2.0 / OpenID Connect provider to issue tokens to first-party or third-party clients
  • Issuing and validating JWTs for API authentication independent of any OAuth flow
  • Signing and verifying JOSE payloads (JWS/JWK/JWA) in services that need standards-compliant crypto primitives
  • Persisting OAuth2 clients, tokens, and authorization codes via the SQLAlchemy provider mixins

Under The Hood

Architecture - The package is organized by protocol layer under authlib/: jose/ (bridging to the joserfc dependency for JWS/JWK/JWA/JWT), oauth1/ and oauth2/ for the respective protocol implementations, oidc/ for OpenID Connect on top of OAuth2, and integrations/ housing framework adapters (flask_client, flask_oauth2, django_client, django_oauth2, starlette_client, httpx_client, requests_client, sqla_oauth2). This layering means the framework integrations are thin adapters over shared, framework-agnostic OAuth/OIDC/JOSE core logic rather than separate reimplementations per framework.

Tech Stack - Python 3.10+, with cryptography and joserfc as its only two runtime dependencies per pyproject.toml — Authlib delegates the actual cryptographic primitives to cryptography and increasingly to the joserfc library for JOSE operations (the README notes authlib.jose is being deprecated in favor of joserfc). Built with setuptools, tested via GitHub Actions with Codecov coverage and SonarCloud maintainability tracking.

Code Quality - The tests/ directory contains 115 test files, organized to mirror the source layout (separate suites per framework integration and per protocol). CI badges for build status, code coverage, and SonarCloud maintainability rating are all surfaced in the README, and the project participates in Tidelift’s subscription program, signaling formalized security/maintenance practices beyond a typical hobby project.

API Design - Authlib’s client-side API centers on a OAuth registry object (oauth.register('google', ...)) that Flask/Django/Starlette apps use to declare providers and then call .authorize_redirect()/.authorize_access_token(), while the provider-side API composes AuthorizationServer and grant-type classes (AuthorizationCodeGrant, etc.) that applications subclass to hook in their own user/client models. This ‘compose from framework-provided base classes’ pattern gives OAuth server implementers full control over persistence and business logic at the cost of more upfront wiring than a fully batteries-included auth-as-a-service SDK.

Used by 13 apps in this directory

Python
89%
Apache 2.0

Apache Airflow

Data Engineering

46,995

Define, schedule, and monitor complex data workflows as Python code — with a powerful UI, 80+ provider integrations, and battle-tested scalability across thousands of production deployments.

View details
96
Repo Health
89
Technical
64
Dependency
Built with
Python 89%
Updated 5 days ago
Python
44%
MIT

/dev/push

Developer Tools · Devops

4,757

Self-hosted, open-source Vercel alternative that deploys Python, Node.js, PHP, and any Docker-compatible app from a Git push, with zero-downtime rollouts and real-time logs.

View details
44
Repo Health
68
Technical
73
Dependency
Built with
Python 44%
HTML 31%
CSS 17%
Updated 7 months ago
Python
51%
AGPL 3.0

Khoj

AI Assistants · Knowledge Management · Productivity

37,526

A self-hostable AI second brain that chats with your documents, searches the web, builds custom agents, and runs entirely on your own LLM.

View details
63
Repo Health
82
Technical
66
Dependency
Built with
Python 51%
TypeScript 36%
Updated 2 months ago
Python
86%
Apache 2.0

knowhere

AI Development · AI Memory · Developer Tools

3,541

Transform messy, unstructured documents into persistent, navigable memory that AI agents can actually use.

View details
82
Repo Health
75
Technical
66
Dependency
Built with
Python 86%
HTML 14%
Updated 1 weeks ago
Python
37%
Other

Open WebUI

AI Agents · AI Assistants

153,390

The extensible, privacy-first AI platform that runs Ollama, OpenAI, and any LLM backend behind a polished, feature-packed web interface.

View details
91
Repo Health
75
Technical
66
Dependency
Built with
Python 37%
Svelte 34%
JavaScript 21%
Updated 5 days ago
TypeScript
95%
Other

OpenHands

AI Code Assistants · AI Development

89,328

The self-hosted developer control center for running AI coding agents — locally, in Docker, on VMs, or across cloud backends — with automation workflows for GitHub, Slack, and more.

View details
91
Repo Health
82
Technical
67
Dependency
Built with
TypeScript 95%
Updated 6 days ago
Python
49%
Other

Arize Phoenix

Analytics · Devops · Monitoring

11,641

Open-source AI observability platform for tracing, evaluating, and debugging LLM applications with built-in intelligence and MCP support.

View details
90
Repo Health
88
Technical
67
Dependency
Built with
Python 49%
TypeScript 42%
Updated 5 days ago
Python
65%
Apache 2.0

Polar

Developer Tools · Ecommerce · Invoicing Finance

10,293

Open source payments infrastructure that turns software into a business — subscriptions, usage-based billing, digital products, and merchant-of-record compliance in one platform.

View details
90
Repo Health
82
Technical
66
Dependency
Built with
Python 65%
TypeScript 28%
Updated 5 days ago
Python
46%
Other

Redash

Analytics · Data Engineering

28,817

Redash lets anyone connect to 35+ SQL and NoSQL data sources, write a query in the browser, and turn the result into a shared dashboard — no separate BI suite required.

View details
92
Repo Health
74
Technical
60
Dependency
Built with
Python 46%
JavaScript 30%
TypeScript 17%
Updated 5 days ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers