NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2159 most downloaded on PyPI
A pluggable framework for adding two-factor authentication to Django using one-time passwords.
Last release 11 days ago
06 Sep 2026
Release timing varies
gaps range from 2 weeks to 8 months
Nearly every release is documented
notes for 57 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
88 releases · first in 2012
Generate HOTP and TOTP otpauth URLs and corresponding QR Codes. To enable this feature, install django-otp[qrcode] or just install the qrcode_ package
Generate HOTP and TOTP otpauth URLs and corresponding QR Codes. To enable this feature, install django-otp[qrcode] or just install the qrcode package.
Support for Python 2.6 and Django 1.4 were dropped in this version (long overdue).
Nothing published for this version
Nothing published for this version
One column per quarter.
Treat ~django.contrib.auth.models.User.is_authenticated and ~django.contrib.auth.models.User.is_anonymous as properties in Django 1.10 and later.
Treat ~django.contrib.auth.models.User.is_authenticated and ~django.contrib.auth.models.User.is_anonymous as properties in Django 1.10 and later.
Add explict on_delete behavior for all foreign keys.
Added a convenience API for verifying TOTP tokens: django_otp.oath.TOTP.verify.
Added a convenience API for verifying TOTP tokens: django_otp.oath.TOTP.verify.
Don't break the laziness of request.user.
Don't break the laziness of request.user.
Improved error message for invalid tokens.
Support the new middleware API in Django 1.10.
The default (random) key for a new TOTP device is now forced to a unicode string.
The default (random) key for a new TOTP device is now forced to a unicode string.
All modules include all four Python 3 __future__ imports for consistency.
All modules include all four Python 3 __future__ imports for consistency.
Migrations no longer have byte strings in them.
Fix the addstatictoken management command under Django 1.9.
Fix the addstatictoken management command under Django 1.9.
Stop importing models into the root of the package.
Stop importing models into the root of the package.
Use ModelAdmin.raw_id_fields for foreign keys to users.
General cleanup and compatibility with Django 1.9a1.
Add support for the new app registry, when available.
Add support for the new app registry, when available.
Add Django 1.8 to the test matrix and fix a few test bugs.
All plugins now have both Django and South migrations. Please see the upgrade notes_ for details on upgrading from previous versions.
All plugins now have both Django and South migrations. Please see the upgrade notes for details on upgrading from previous versions.
Updated the otp_totp South migrations to support custom user models. Thanks to https://bitbucket.org/robirichter.
Updated the otp_totp South migrations to support custom user models. Thanks to https://bitbucket.org/robirichter.
Removed South-generated unicode string literals.
Removed South-generated unicode string literals.
Nothing published for this version
Per the RFC, ~django_otp.plugins.otp_totp.models.TOTPDevice will no longer verify the same token twice.
Per the RFC, ~django_otp.plugins.otp_totp.models.TOTPDevice will no longer verify the same token twice.
Cosmetic fixes to the admin login form on Django 1.6.
Warning
This includes a model change in TOTPDevice. If you are upgrading and your project uses South, you should first convert it to South with manage migrate otp_totp 0001 --fake. If you're not using South, you will need to generate and run the appropriate SQL manually.
OTPMiddleware no longer interferes with pickling request.user.
OTPMiddleware no longer interferes with pickling request.user.
Update Django requirement to 1.4.2, the first version with django.utils.six.
Update Django requirement to 1.4.2, the first version with django.utils.six.
Fix unicode representation of devices in some exotic scenarios.
Fix unicode representation of devices in some exotic scenarios.
Now supports Django 1.4 to 1.6 on Python 2.6, 2.7, 3.2, and 3.3. This is the first release for Python 3.
Now supports Django 1.4 to 1.6 on Python 2.6, 2.7, 3.2, and 3.3. This is the first release for Python 3.
Add django_otp.user_has_device to detect whether a user has any devices configured. This change supports a fix in django-otp-agents 0.1.4.
Add django_otp.user_has_device to detect whether a user has any devices configured. This change supports a fix in django-otp-agents 0.1.4.
Add if_configured argument to ~django_otp.decorators.otp_required.
Add if_configured argument to ~django_otp.decorators.otp_required.
Major unit test cleanup. Tests should pass or be skipped under all supported versions of Django, with or without custom users and timzeone support.
Major unit test cleanup. Tests should pass or be skipped under all supported versions of Django, with or without custom users and timzeone support.
OTPAdminSite now selects an apporpriate login template automatically, based on the current Django version. Django versions 1.3 to 1.5 are currently su
OTPAdminSite now selects an apporpriate login template automatically, based on the current Django version. Django versions 1.3 to 1.5 are currently supported.
Unit test cleanup.
Add support for custom user models in Django 1.5.
Add support for custom user models in Django 1.5.
Stop using Device.objects: Django doesn't allow access to an abstract model's manager any more.
Fix an exception when an empty login form is submitted.
Fix an exception when an empty login form is submitted.
Nothing published for this version
Initial release.
Initial release.
Your coding agent can read these notes before it upgrades. Set up the MCP server →