NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4617 most downloaded on PyPI
Authentication for django rest framework
Last release 2 months ago
12 Jul 2026
Ships unpredictably
gaps range from 9 days to 2.7 years
Most releases are documented
notes for 26 of 30 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
30 releases · first in 2015
Drop support for Python 3.8 and 3.9
pyproject.toml (PEP 621); drop setup.pydjangorestframework>=3.14pyproject.tomlsetup.py is removed; build/install now relies on pyproject.toml. Most
installers (pip, uv, pipx, etc.) handle this transparently — no action
needed unless you pin via setup.py directly.
Fix for Potential n+1 query detected on AuthToken.user
One column per quarter.
Implement AUTO_REFRESH_MAX_TTL to limit total token lifetime when AUTO_REFRESH = True
Fix migration when not overriding AuthToken model
TOKEN_MODEL from knox_settings instead of Django settings.This is the first Jazzband release of django-rest-knox, and it comes with an extensive list of fixes and improvements from the last version. Thanks to
This is the first Jazzband release of django-rest-knox, and it comes with an extensive list of fixes and improvements from the last version.
Thanks to everyone in the community that contributed to help get this through! :rocket:
cryptography in favor of hashlibsix libraryself.authenticate_header() in authenticate() method to get auth header prefixcompatibility with Python up to 3.10 and Django up to 4.0
Expiry format now defaults to whatever is used Django REST framework
Fix for tox config to build Django 2.2 on python 3.6
Fix for tox config to build Django 2.2 on python 3.6
BREAKING This is a major release version because it breaks the existing API. Changes have been made to the create() method on the AuthToken model. It
BREAKING This is a major release version because it breaks the existing API. Changes have been made to the create() method on the AuthToken model. It now returns the model instance and the raw token instead of just the token to allow the expiry field to be included in the success response.
Model field of AuthToken has been renamed from expires to expiry to remain consistent across the code base.
This patch requires you to run a migration and depending on your usage you might also have to adjust your code.
BREAKING This is a major release version because it
breaks the existing API.
Changes have been made to the create() method on the AuthToken model.
It now returns the model instance and the raw token instead
of just the token to allow the expiry field to be included in the
success response.
Model field of AuthToken has been renamed from expires to expiry
to remain consistent across the code base. This patch requires you
to run a migration.
Depending on your usage you might have to adjust your code to fit these new changes.
AuthToken model field has been changed from expires to expiryexpiry field for when the token expiresThe user serializer for each LoginViewis now dynamic
LoginViewis now dynamicThe context, token TTL and tokens per user settings in LoginView are now dynamic
The context, token TTL and tokens per user settings in LoginView are now dynamic
*Our release cycle was broken since 3.1.5, hence you can not find the previous releases on pypi. We now fixed the problem.*
Our release cycle was broken since 3.1.5, hence you can not find the previous releases on pypi. We now fixed the problem.
Our release cycle was broken since 3.1.5, hence you can not find the previous releases on pypi. We now fixed the problem.
extended docs for using only token auth
Fix compability with django-rest-swagger (bad inheritance)
Fix compability with django-rest-swagger (bad inheritance)
Avoid 500 error response for invalid-length token requests
Avoid 500 error response for invalid-length token requests
the hmac.compare_digest method is not available before Python 2.7.7 this restores a simple a==b if it is not available
the hmac.compare_digest method is not available before Python 2.7.7 this restores a simple a==b if it is not available
use hmac.compare_digest instead of == for comparing hashes for more security as reported by @fengsi
use hmac.compare_digest instead of == for comparing hashes for more security as reported by @fengsi
drop Django 1.8 support as djangorestframework did so too in v.3.7.0
make rest-knox compatible with OpenSSL 17.3.0 https://pyopenssl.org/en/stable/changelog.html#id1
make rest-knox compatible with OpenSSL 17.3.0 https://pyopenssl.org/en/stable/changelog.html#id1
Please be aware: updating to this version requires applying a database migration. All clients will need to reauthenticate.
Please be aware: updating to this version requires applying a database migration. All clients will need to reauthenticate.
Nothing published for this version
Bugfix: invalid token length does no longer trigger a server error
Please be aware: updating to his version requires applying a database migration
v. 2.2.1
Please be aware: updating to his version requires applying a database migration
Please be aware: updating to his version requires applying a database migration
Introducing token_key to avoid loop over all tokens on login-requests
Signals are sent on login/logout
Test for invalid token length
Cleanup in code and documentation
Bugfix: invalid token length does no longer trigger a server error
Extending documentation
- Change to support python 2.7
Nothing published for this version
Nothing published for this version
Nothing published for this version
Hashing of tokens on the server introduced.
LoginView changed to respect DEFAULT_AUTHENTICATION_CLASSES
LoginView changed to respect DEFAULT_AUTHENTICATION_CLASSES- Initial release
Your coding agent can read these notes before it upgrades. Set up the MCP server →