NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #253 most downloaded on PyPI
The ultimate Python library in building OAuth and OpenID Connect servers and clients.
Last release 1 months ago
30 Aug 2026
Ships fairly regularly
a new release about every 6 weeks
Nearly every release is documented
notes for 57 of 58 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
64 releases · first in 2017
Prefer id_token_signed_response_alg client metadata to guess algs by @azmeuk in #888
id_token_signed_response_alg client metadata to guess algs by @azmeuk in #888Full Changelog: v1.7.2...v1.8.0
One column per quarter.
Released on Aug 30, 2026
Breaking change: authlib.integrations.httpx_client is now powered by httpx2 instead of httpx. Install httpx2 to keep using this integration; the public import path and class names are unchanged. When httpx2 is not installed, the integration falls back to httpx and emits an AuthlibDeprecationWarning. This fallback will be removed in a future release. 904
Breaking change: the client metadata id_token_signed_response_alg now takes precedence over get_jwt_config()["alg"] when signing OIDC id_token, in line with OpenID Connect Registration 1.0 Section 2. get_jwt_config()["alg"] is now used as a server-wide default when the client did not configure an algorithm. Override get_client_algorithm(client) if you need the previous behaviour. 806
Fix is_secure_transport() accepting cleartext URIs whose userinfo component looks like a loopback host, such as http://localhost:80@attacker.test/cb. The loopback exemption is now matched on the parsed host, and no longer requires an explicit port.
Reject URIs with a userinfo component during client and server metadata validation, as in https://client.test@attacker.test/cb. URIs that urlparse refuses to parse, such as http://[not-an-ip]/, are also rejected instead of raising an unhandled ValueError.
Cast the sub claim to a string in the RFC 9068 and RFC 7523 JWTBearerTokenGenerator, as required by RFC 7519 Section 4.1.2. joserfc 1.7.3 started validating this claim and rejected the previously emitted non-string values (e.g. an integer get_user_id()). 910 911
Require joserfc>=1.6.1 and cryptography>=45.0.1. The RFC 9068 amr validation uses InvalidClaimError's description argument, added in joserfc 1.6.1.
Declare lower bounds for the optional integration dependencies and test them in CI against their minimum versions with uv's lowest-direct resolution.
The token endpoint answers malformed RFC 7523 assertions with an invalid_client or invalid_grant error instead of raising an unhandled exception. JWTBearerGrant.resolve_issuer_client() may return None for an unknown issuer.
The RFC 9068 JWTBearerTokenValidator answers with an invalid_token error for any JoseError raised while decoding an access token, instead of only DecodeError. An unknown kid used to raise an unhandled InvalidKeyIdError. 891
Add a leeway parameter to the RFC 7523 JWTBearerTokenValidator, which used to be hardcoded to 60 seconds. 903
sign_jwt_bearer_assertion() generates a default jti claim when the caller did not provide one, as 7523 §3 recommends against replay attacks. This matches what OAuth2Session already did for client assertions. 897
Add optional client_id parameter to AssertionClient (and its AssertionSession / httpx wrappers) so it can be sent in the token endpoint request body per 7521 §4.1 and 6749 §3.2.1. 476
The OpenID Connect client no longer rejects an id_token whose JWS header carries unregistered parameters. 902
Omit the nonce and auth_time claims from the id_token instead of emitting them with a null value. 921
DeviceAuthorizationEndpoint saves the device credential with the authenticated client id. It used to read request.payload.client_id, which is None when the client authenticates with client_secret_basic. 798 908
Fix the OAuth 1.0a InsecureTransportError description telling users that OAuth 2 must use HTTPS. 919
Fix the readme links by @azmeuk in #886
Released on May 6, 2026
Fix PrivateKeyJWT rejecting ECKey private keys (e.g. for ES256). The client private key is no longer forcibly imported as an RSAKey; joserfc's key auto-detection is used instead. 852
Allow ClientSecretJWT and PrivateKeyJWT to sign client assertions with non-recommended algorithms (e.g. RS384) when explicitly set via the alg parameter. 883
Validate BCP 47 language tags in ui_locales_supported, claims_locales_supported and UserInfo.locale. 873
Fix AuthlibDeprecationWarning being emitted on import when using integrations that do not use authlib.jose directly. :issue: 880
Released on may 4, 2026
AuthlibDeprecationWarning being emitted on import when using integrationsauthlib.jose directly. :issue:880redirect_uri on InvalidScopeErrorOpenIDImplicitGrant and OpenIDHybridGrant.redirect_uri on InvalidScopeError in OpenIDImplicitGrant and OpenIDHybridGrant.Full Changelog: v1.7.0...v1.7.1
Authorization and token endpoints request empty scope parameter management by @azmeuk in #847
expires_at behavior when its value is 0 by @azmeuk in #854get_jwt_config by @lepture in #858Full Changelog: v1.6.10...v1.7.0
Released on Apr 18, 2026
Add support for OpenID Connect RP-Initiated Logout 1.0. See specs/rpinitiated for details. 500
Per RFC 6749 Section 3.3, the scope parameter is now optional at both authorization and token endpoints. client.get_allowed_scope() is called to determine the default scope when omitted. 845
Stop support for Python 3.9, start support Python 3.14. 850
Allow AuthorizationServerMetadata.validate() to compose with RFC extension classes.
Fix expires_at=0 being incorrectly treated as None. 530
Allow ResourceProtector decorator to be used without parentheses. 604
Implement RFC9700 PKCE downgrade countermeasure.
Set User-Agent header when fetching server metadata and JWKs. 704
RFC7523 accepts the issuer URL as a valid audience. 730
Fix InvalidTokenError extra attributes being wrapped instead of passed as individual key=value pairs in the WWW-Authenticate header. 872
Upgrade Guide: joserfc_upgrade.
Fix redirecting to unvalidated redirect_uri on InvalidScopeError in OpenIDImplicitGrant and OpenIDHybridGrant .
Released on may 4, 2026
redirect_uri on InvalidScopeErrorOpenIDImplicitGrant and OpenIDHybridGrant.redirect_uri on InvalidScopeError in OpenIDImplicitGrant and OpenIDHybridGrant.Fix CSRF issue with starlette client
Full Changelog: v1.6.10...v1.6.11
Released on Apr 16, 2026
Fix CSRF vulnerability in the Starlette OAuth client when a cache is configured.
Fix redirecting to unvalidated redirect_uri on UnsupportedResponseTypeError .
Full Changelog: v1.6.9...v1.6.10
redirect_uri on UnsupportedResponseTypeError.Released on Apr 13, 2026
Fix redirecting to unvalidated redirect_uri on UnsupportedResponseTypeError.
Remove deprecated algorithm from default registry
Full Changelog: v1.6.8...v1.6.9
jose modulejwk automaticallyES256K into default jwt algorithmscek when cek length doesn't matchReleased on Mar 2, 2026
Not using header's jwk automatically.
Add ES256K into default jwt algorithms.
Remove deprecated algorithm from default registry.
Generate random cek when cek length doesn't match.
Add EdDSA to default jwt instance.
Full Changelog: v1.6.7...v1.6.8
EdDSA to default jwt instance.Set supported algorithms for the default jwt instance.
Full Changelog: https://github.com/authlib/authlib/compare/v1.6.6...v1.6.7
Set supported algorithms for the default jwt instance.
Released on Feb 6, 2026
Set supported algorithms for the default jwt instance.
fix(ClientAuth): fix incorrect signature when Content-Type is x-www-form-urlencoded by @shc261392 in https://github.com/authlib/authlib/pull/778
expires_in when expires_at is unparsable by @bendavis78 in https://github.com/authlib/authlib/pull/842get_jwt_config takes a client parameter. by @azmeuk in https://github.com/authlib/authlib/pull/844Full Changelog: https://github.com/authlib/authlib/compare/v1.6.5...v1.6.6
Released on Jan 9, 2026
get_jwt_config takes a client parameter, 844.
Fix incorrect signature when Content-Type is x-www-form-urlencoded for OAuth 1.0 Client, 778.
Use expires_in in OAuth2Token when expires_at is unparsable, 842.
Always track state in session for OAuth client integrations.
Add a request param to RFC7591 generate_client_info and generate_client_secret methods by @azmeuk in https://github.com/authlib/authlib/pull/825
request param to RFC7591 generate_client_info and generate_client_secret methods by @azmeuk in https://github.com/authlib/authlib/pull/825Full Changelog: https://github.com/authlib/authlib/compare/v1.6.4...v1.6.5
Released on Oct 2, 2025
RFC7591 generate_client_info and generate_client_secret take a request parameter.
Add size limitation when decode JWS/JWE to prevent DoS.
Add size limitation for DEF JWE zip algorithm.
fix(jose): prevent public/unprotected header overwriting protected header by @lepture in https://github.com/authlib/authlib/pull/809
InsecureTransportError raising by @azmeuk in https://github.com/authlib/authlib/pull/810Full Changelog: https://github.com/authlib/authlib/compare/v1.6.3...v1.6.4
Released on Sep 17, 2025
Fix InsecureTransportError error raising. 795
Fix response_mode=form_post with Starlette client. 793
Validate crit header value, reject unprotected header in crit header.
Add diff-cover check in GHA by @azmeuk in https://github.com/authlib/authlib/pull/803
id_token_signed_response_alg client metadata by @azmeuk in https://github.com/authlib/authlib/pull/802Full Changelog: https://github.com/authlib/authlib/compare/v1.6.2...v1.6.3
Released on Aug 26, 2025
OIDC id_token are signed according to id_token_signed_response_alg client metadata. 755
Allow insecure transport for 127.0.0.1 for debugging by @geigerzaehler in https://github.com/authlib/authlib/pull/788
Full Changelog: https://github.com/authlib/authlib/compare/v1.6.1...v1.6.2
Released on Aug 23, 2025
Temporarily restore OAuth2Request body parameter. 781 791
Allow 127.0.0.1 in insecure transport mode. 788
Raise MissingCodeException when the code parameter is missing. 793 794
Fix id_token generation with EdDSA algs. 799 800
Filter key set with additional "alg" and "use" parameters.
Released on Jul 20, 2025
Filter key set with additional "alg" and "use" parameters.
Restore and deprecate OAuth2Request body parameter. 781
Fix issue when RFC9207 is enabled and the authorization endpoint response is not a redirection. pull request #733
Released on May 22, 2025
Fix issue when RFC9207 is enabled and the authorization endpoint response is not a redirection. 733
Fix missing state parameter in authorization error responses. 525
Support for the none JWS algorithm.
Fix response_types strict order during dynamic client registration. 760
Implement RFC9101 The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR). 723
OIDC UserInfo endpoint support. 459
Breaking changes:
Support for acr and amr claims in id_token. 734 The OAuth2AuthorizationCodeMixin must have a migration to support the new fields.
Forbid fragments in redirect_uris. #714
Released on Apr 1, 2025
claims_cls parameter for client's parse_id_token method. #725Fix RFC9207 iss parameter. #715
Released on Feb 28, 2025
Fix token introspection auth method for clients. #662
Released on Feb 25, 2025
Fix token introspection auth method for clients. 662
Optional typ claim in JWT tokens. 696
JWT validation leeway. 689
Implement server-side RFC9207. 700 701
generate_id_token can take a kid parameter. 702
More detailed InvalidClientError. 706
OpenID Connect Dynamic Client Registration implementation. 707
Improve garbage collection on OAuth clients. #698
Released on Jan 28, 2025
Improve garbage collection on OAuth clients. 698
Fix client parameters for httpx. 694
Fix id_token decoding when kid is null. #659
Bugfixes
Breaking changes
Released on Dec 20, 2024
Fix id_token decoding when kid is null. 659
Support for Python 3.13. 682
Force login if the prompt parameter value is login. 637
Support for httpx 0.28, 695
Breaking changes:
Stop support for Python 3.8. 682
Prevent ever-growing session size for OAuth clients.
quote client id and secret.unquote basic auth header for authorization server.Released on Aug 30 2024
Prevent ever-growing session size for OAuth clients.
Revert quote client id and secret.
unquote basic auth header for authorization server.
Prevent OctKey to import ssh and PEM strings.
Prevent OctKey to import ssh and PEM strings.
Released on June 4, 2024
Prevent OctKey to import ssh and PEM strings.
Restore AuthorizationServer.create_authorization_response behavior, via #558 by @TurnrDev
Bug fixes
Breaking changes
Released on Dec 17, 2023
Restore AuthorizationServer.create_authorization_response behavior, via :PR:`558`
Include leeway in validate_iat() for JWT, via :PR:`565`
Fix encode_client_secret_basic, via :PR:`594`
Use single key in JWK if JWS does not specify kid, via :PR:`596`
Fix error when RFC9068 JWS has no scope field, via :PR:`598`
Get werkzeug version using importlib, via :PR:`591`
New features:
RFC9068 implementation, via :PR:`586`, by @azmeuk.
Breaking changes:
End support for python 3.7
Apply headers in ClientSecretJWT.sign method, via #552
ClientSecretJWT.sign method, via #552authorize_redirect for Starlette v0.26.0, via #533has_client_secret method and documentation, via #513request_invalid and token_revoked remaining occurences
and documentation. #514grant_types and response_types default values, via #509Released on Jun 25, 2023
Apply headers in ClientSecretJWT.sign method, via :PR:`552`
Allow falsy but non-None grant uri params, via :PR:`544`
Fixed authorize_redirect for Starlette v0.26.0, via :PR:`533`
Removed has_client_secret method and documentation, via :PR:`513`
Removed request_invalid and token_revoked remaining occurrences and documentation. :PR:`514`
Fixed RFC7591 grant_types and response_types default values, via :PR:`509`.
Add support for python 3.12, via :PR:`590`.
Deprecate jwk.loads and jwk.dumps
request.body to ResourceProtector, #485.flask.g instead of _app_ctx_stack, #482.headers parameter back to ClientSecretJWT, #457.realm parameter in OAuth 1 clients, #339.default_timeout for requests OAuth2Session and AssertionSession.jwk.loads and jwk.dumpsReleased on Dec 6, 2022
Not passing request.body to ResourceProtector, via 485.
Use flask.g instead of _app_ctx_stack, via 482.
Add headers parameter back to ClientSecretJWT, via 457.
Always passing realm parameter in OAuth 1 clients, via 339.
Implemented RFC7592 Dynamic Client Registration Management Protocol, via :PR:`505`.
Add default_timeout for requests OAuth2Session and AssertionSession.
Deprecate jwk.loads and jwk.dumps
This release contains breaking changes and security fixes.
This release contains breaking changes and security fixes.
claims_options to Framework OpenID Connect clients, via #446 by @Galaxy102.stream with context for HTTPX OAuth clients, via #465 by @bjoernmeierBreaking changes:
InvalidGrantError for invalid code, redirect_uri and no user errors in OAuth 2.0 server.authlib.jose.jwt would only work with JSON Web Signature algorithms, if you would like to use JWT with JWE algorithms, please pass the algorithms parameter:jwt = JsonWebToken(['A128KW', 'A128GCM', 'DEF'])
Security fixes for JOSE module
Released on Sep 13, 2022
This release contains breaking changes and security fixes.
Allow to pass claims_options to Framework OpenID Connect clients, via :PR:`446`.
Fix .stream with context for HTTPX OAuth clients, via :PR:`465`.
Fix Starlette OAuth client for cache store, via :PR:`478`.
Breaking changes:
Raise InvalidGrantError for invalid code, redirect_uri and no user errors in OAuth 2.0 server.
The default authlib.jose.jwt would only work with JSON Web Signature algorithms, if you would like to use JWT with JWE algorithms, please pass the algorithms parameter:
jwt = JsonWebToken(['A128KW', 'A128GCM', 'DEF'])
Security fixes: CVE-2022-39175 and CVE-2022-39174, both related to JOSE.
Security fix for validating essential value on blank value in JWT, via #445.
authenticate_none method, via #438.missing_token for Flask OAuth client, via #448.openid in any place of the scope, via #449.Breaking Changes: find how to solve the deprecate issues via https://git.io/JkY4f
We have dropped support for Python 2 in this release. We have removed built-in SQLAlchemy integration.
OAuth Client Changes:
The whole framework client integrations have been restructured, if you are
using the client properly, e.g. oauth.register(...), it would work as
before.
OAuth Provider Changes:
In Flask OAuth 2.0 provider, we have removed the deprecated
OAUTH2_JWT_XXX configuration, instead, developers should define
.get_jwt_config on OpenID extensions and grant types.
SQLAlchemy integrations has been removed from Authlib. Developers should define the database by themselves.
JOSE Changes
JWS has been renamed to JsonWebSignatureJWE has been renamed to JsonWebEncryptionJWK has been renamed to JsonWebKeyJWT has been renamed to JsonWebTokenThe "Key" model has been re-designed, checkout the JSON Web Key for updates.
Added ES256K algorithm for JWS and JWT.
Breaking Changes: find how to solve the deprecate issues via https://git.io/JkY4f
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Make Authlib compatible with latest httpx
alg valueSecurity fix when JWT claims is None.
Security fix when JWT claims is None.
For example, JWT payload has iss=None:
{
"iss": None,
...
}
But we need to decode it with claims:
claims_options = {
'iss': {'essential': True, 'values': ['required']}
}
jwt.decode(token, key, claims_options=claims_options)
It didn't raise an error before this fix.
Fixed .authorize_access_token for OAuth 1.0 services, via https://github.com/lepture/authlib/issues/308
Fixed .authorize_access_token for OAuth 1.0 services, via https://github.com/lepture/authlib/issues/308
Fixed httpx authentication bug via #283
Fixed httpx authentication bug via #283
Backward compitable fix for using JWKs in JWT, via #280.
Backward compitable fix for using JWKs in JWT, via #280.
This is the last release before v1.0. In this release, we added more RFCs implementations and did some refactors for JOSE:
This is the last release before v1.0. In this release, we added more RFCs implementations and did some refactors for JOSE:
We also fixed bugs for integrations:
Breaking Change:
algorithms in JsonWebSignature and JsonWebEncryption
are changed. Usually you don't have to care about it since you won't use it directly.Fix HTTPX integration via #232 and #233.
none auth method for authorization code by default.code_verifier via #216.introspect_token method on OAuth 2 Client via #224.Fix OAuth 1.0 client for starlette.
expires_at or expires_in is 0 via #227.Quick fix for legacy imports of Flask and Django clients
Fix HTTPX integrations due to HTTPX breaking changes
In this release, Authlib has introduced a new way to write framework integrations for clients.
Bug fixes and enhancements in this release:
Breaking Change: drop sync OAuth clients of HTTPX.
Deprecate Changes: find how to solve the deprecate issues via
This is the release that makes Authlib one more step close to v1.0. We did a huge refactor on our integrations. Authlib believes in monolithic design, it enables us to design the API to integrate with every framework in the best way. In this release, Authlib has re-organized the folder structure, moving every integration into the integrations folder. It makes Authlib to add more integrations easily in the future.
RFC implementations and updates in this release:
New integrations and changes in this release:
authlib.client.aiohttp has been removedBug fixes and enhancements in this release:
alg values easily for JWS and JWE.Deprecate Changes: find how to solve the deprecate issues via https://git.io/Jeclj
This is a bug fix version. Here are the fixes:
This is a bug fix version. Here are the fixes:
client.get_allowed_scope on every grant typesrequest.client before validate_requested_scopeBreaking Change: Authlib Grant system has been redesigned. If you are creating OpenID Connect providers, please read the new documentation for OpenID…
Released on Sep 3, 2019.
Breaking Change: Authlib Grant system has been redesigned. If you are creating OpenID Connect providers, please read the new documentation for OpenID Connect.
Important Update: Django OAuth 2.0 server integration is ready now. You can create OAuth 2.0 provider and OpenID Connect 1.0 with Django framework.
RFC implementations and updates in this release:
AssertionClient for the assertion frameworkIntrospectionToken for introspection token endpointRefactor and bug fixes in this release:
RefreshTokenGrant.revoke_old_credential methodauthlib.client, no breaking changesOAuth2Request, use explicit query and formrequests to optional dependencyAsyncAssertionClient for aiohttpDeprecate Changes: find how to solve the deprecate issues via https://git.io/fjPsV
Code Changes: https://github.com/lepture/authlib/compare/v0.11...v0.12
Important Changes: Authlib specs module has been split into jose, oauth1, oauth2, and oidc. Find how to solve the deprecate issues via .
BIG NEWS: Authlib has changed its open source license from AGPL to BSD.
Important Changes: Authlib specs module has been split into jose, oauth1, oauth2, and oidc. Find how to solve the deprecate issues via https://git.io/fjvpt.
RFC implementations and updates in this release:
Small changes and bug fixes in this release:
Experiment Features: There is an experiment aiohttp client for OAuth1 and OAuth2 in authlib.client.aiohttp.
Code Changes: https://github.com/lepture/authlib/compare/v0.10...v0.11
Deprecate Changes: find how to solve the deprecate issues via
The most important change in this version is grant extension system. When registering a grant, developers can pass extensions to the grant:
authorization_server.register_grant(GrantClass, [extension])
Find Flask Grant Extensions implementation.
RFC implementations and updates in this release:
Besides that, there are other improvements:
save_authorize_state method on Flask and Django clientfetch_token to Django OAuth client@require_oauth Multiple ScopesDeprecate Changes: find how to solve the deprecate issues via https://git.io/fAmW1
Code Changes: https://github.com/lepture/authlib/compare/v0.9...v0.10
Deprecated authlib.client.apps from v0.7 has been dropped.
There is no big break changes in this version. The very great improvement is adding JWE support. But the JWA parts of JWE are not finished yet, use with caution.
RFC implementations in this release:
Other Changes:
authlib.client.apps from v0.7 has been dropped.Documentation: https://docs.authlib.org/en/v0.9/
Code Changes: https://github.com/lepture/authlib/compare/v0.8...v0.9
Deprecate Changes: find how to solve the deprecate issues via
Authlib has tried to introduce Django OAuth server implementation in this version. It turns out that it is not that easy. In this version, only Django OAuth 1.0 server is provided.
As always, there are also RFC features added in this release, here is what's in version 0.8:
response_mode=form_post support for OpenID Connect.Improvement in this release:
AuthlibBaseError.authlib.flask.oauth2.sqla via issue#57.require_oauth.acquire with statement, get example on Flask OAuth 2.0 Server.Deprecate Changes: find how to solve the deprecate issues via https://git.io/vhL75
Code Changes: https://github.com/lepture/authlib/compare/v0.7...v0.8
Authlib has changed its license from LGPL to AGPL. This is not a huge release like v0.6, but it still contains some deprecate changes, the good news i…
Authlib has changed its license from LGPL to AGPL. This is not a huge release like v0.6, but it still contains some deprecate changes, the good news is they are compatible, they won’t break your project. Authlib can’t go further without these deprecate changes.
As always, Authlib is adding specification implementations. Here is what’s new in version 0.7:
AssertionSession, only works with RFC7523.JWTBearerGrant, read the guide in JWT Profile for OAuth 2.0 Client Authentication and Authorization Grants.Besides that, there are more changes:
overwrite parameter for framework integrations clients.response_mode=query for OpenID Connect implicit and hybrid flow.Deprecate Changes: find how to solve the deprecate issues via https://git.io/vpCH5
Code Changes: https://github.com/lepture/authlib/compare/v0.6...v0.7
From alpha to beta. This is a huge release with lots of deprecating changes and some breaking changes. And finally, OpenID Connect server is supported…
From alpha to beta. This is a huge release with lots of deprecating changes and some breaking changes. And finally, OpenID Connect server is supported by now, because Authlib has added these specifications:
The specifications are not completed yet, but they are ready to use. The missing RFC7516 (JWE) is going to be implemented in next version. Open ID Connect 1.0 is added with:
Besides that, there are more changes:
token_endpoint_auth_method concept defined in RFC7591.Breaking Changes:
authlib.flask.oauth2.sqla has been changed a lot. If you are using it, you need to upgrade your database.register_token_validator on ResourceProtector.authlib.client.oauth1.OAuth1 has been renamed to authlib.client.oauth1.OAuth1Auth.Deprecate Changes: find how to solve the deprecate issues via https://git.io/vAAUK
Code Changes: https://github.com/lepture/authlib/compare/v0.5.1...v0.6
Fixed OAuth2Session.request with auth.
Just a quick bug fix release.
OAuth2Session.request with auth.There are many redesigns in order to get a better stable API. It is still in Alpha stage, with these breaking changes, I hope Authlib will go into Bet…
This version breaks a lot of things. There are many redesigns in order to get a better stable API. It is still in Alpha stage, with these breaking changes, I hope Authlib will go into Beta in the next version.
register_error_uri() and its Flask integration.OAuth2Session supports more grant types.AuthorizationCodeGrant.create_authorization_code, last parameter is changed to an
OAuth2Request instance.callback_uri to redirect_uri in client.This is a quick bug fix version.
This is a quick bug fix version.
This is a feature releasing for OAuth 1 server. Things are not settled yet, there will still be breaking changes in the future. Some of the breaking c…
This version is released when people are enjoying the super blue blood moon. That's why this version is called Tsukino. The full name would be Tsukino Usagi.
This is a feature releasing for OAuth 1 server. Things are not settled yet, there will still be breaking changes in the future. Some of the breaking changes are compatible with deprecated messages, a few are not. I’ll keep the deprecated message for 2 versions. Here is the main features:
In version 0.4, there is also several bug fixes. Thanks for the early contributors.
Since this is the first release of the server implementation, you would expect that there are bugs, security vulnerabilities, and uncertainties. Try i…
This is a feature releasing for OAuth 2 server. Since this is the first release of the server implementation, you would expect that there are bugs, security vulnerabilities, and uncertainties. Try it bravely.
Your coding agent can read these notes before it upgrades. Set up the MCP server →