NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2423 most downloaded on PyPI
Complete Two-Factor Authentication for Django
Last release 1 years ago
27 Sep 2025
Release timing varies
gaps range from 2 weeks to 1.1 years
Most releases are documented
notes for 28 of 45 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
48 releases · first in 2012
New translations for Azerbaijani and Serbian
Documentation for setting yubikey support forgot to inform users they would need to add our yubikey plugin to INSTALLED_APPS
INSTALLED_APPSphonenumbers is no longer a hard requirement for users who don't require it.EmailDevice.confirmed default to FalseStaticDevice can be used as backup tokens, not just those labelledINSTALLED_APPS to make sure two_factor is present andOne column per quarter.
Fixed the XML syntax of the Twilio token.xml file.
throttle_* methods (#699).pyproject.toml (noMethodNotFoundErrorlogin_not_required decorator forLoginRequiredMiddleware available with Django 5.1+.utils.class_view_decorator() in favor of Django'smethod_decorator().Upgraded minimal webauthn dependency to 2.0 (which also removes a deprecation warning) ( #634 , #701 ). Note the pydantic dependency was removed in we…
<ul> on the profile page.pydantic dependency was removed inmain_form_content template block on login template allows for easierInclude transitively replaced migrations in phonenumber migration.
Corrected migration dependency (introduced in 6150a782b6e6).
Fixes #629 .
Fixes #629.
Set default_auto_field to AutoField in apps config that have models, so no migrations are generated for projects defaulting to BigAutoField (#436).
default_auto_field to AutoField in apps config that have models,
so no migrations are generated for projects defaulting to BigAutoField (#436).public_key, which was unsupported
on MySQL (#594).Missing plugin templates ( #583 ).
two_factor app are squashed to avoid requiring phonenumber_fieldEnforcing a redirect to setup of otp device when none available for user
two_factor.utils.get_available_methods() is replaced byMethodRegistry.get_methods().The setup view got a new secret_key context variable to be able to display that key elsewhere than in the QR code.
secret_key context variable to be able to display
that key elsewhere than in the QR code.idempotent class variable to tell if the
form can validate more than once with the same input data.EmailDevice) can now be activated
and used to communicate the second factor token by email.two_factor.plugins.phonenumber
line in your INSTALLED_APPS setting. Additionally, as the two_factor
templatetags library was only containing phone-related filters, the library
was renamed to phonenumber.otp_token form field for AuthenticationTokenForm is now a Django
RegexField instead of an IntegerField.<Pause> tag.Translations for new languages: Hausa, Japanese, Vietnamese
Support Twilio Messaging Service SID
User can request that two-factor authentication be skipped the next time they log in on that particular device
re_path() to path() in URLConfDisableView now checks user has verified before disabling two-factor on
their accountNo changes in this release. Pushed new version to PyPI dropping the plaintext warning.
No changes in this release. Pushed new version to PyPI dropping the plaintext warning.
Security Fix: LoginView no longer stores credentials in plaintext in the session store.
LoginView and them needing to re-authenticate. By default this is 10
minutes.LoginView no longer re-validates a user's credentials.LoginView no longer stores credentials in plaintext in the
session store.*Nothing has been added for this version*
Nothing has been added for this version
mock dependencyextra_requires are now listed in lowercase. This is to workaround a bug in pip.trimmed option on blocktrans to avoid garbage newlines in translations.random_hex from django_otp 0.8.0 will always return a str, don't try to decode it.Optionally install full or light phonenumbers library.
1.9.0 got pushed with incorrect changelog, no other changes.
Support for QRcode library up to 6.
ValidationError with SuspiciousOperation in views.Fix: Do not list phone method if it is not supported (#225).
* Fix: Twilio client 6.0 usage (#211) * Updated translation: Russian
Fix: Fixed redirect_to after successful login
redirect_to after successful login (#204)New: Support for Django 1.11 (#188).
LOGIN_REDIRECT_URL to a URL (#192).DisableView should also take success_url parameter (#187).New: Django 1.10’s MIDDLEWARE support.
success_url overrides from urls.py.redirect_url properties to success_url to be consistent with Django.success_url overrides from urls.py.redirect_url properties to success_url to be consistent with Django.New: Support for Django 1.10 (#157).
LOGIN_URL, LOGIN_REDIRECT_URL and
LOGOUT_URL (#153).Fix: KeyError when trying to login (#102).
New feature: Added support for Django 1.9.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →