NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3426 most downloaded on PyPI
The ultra-reliable, fast ASGI+WSGI framework for building data plane APIs at scale.
Last release 4 days ago
30 Sep 2026
Release timing varies
gaps range from 8 days to 13 months
Some releases are documented
notes for 22 of 38 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
104 releases · first in 2013
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Support for both CPython 2.6 and Jython 2.7 is now deprecated and will be discontinued in Falcon 2.0.
(None)
CPython 3.6 is now fully supported.
Falcon appears to work well on PyPy3.5, but we are waiting until that platform is out of beta before officially supporting it.
Support for both CPython 2.6 and Jython 2.7 is now deprecated and will be discontinued in Falcon 2.0.
We added built-in resource representation serialization and deserialization, including input validation based on JSON Schema. (See also: Media)
URI template field converters are now supported. We expect to expand this feature over time. (See also: Field Converters)
A new method, ~falcon.Request.get_param_as_datetime, was added to ~falcon.Request.
A number of attributes were added to ~falcon.Request to make proxy information easier to consume. These include the ~falcon.Request.forwarded, ~falcon.Request.forwarded_uri, ~falcon.Request.forwarded_scheme, ~falcon.Request.forwarded_host, and ~falcon.Request.forwarded_prefix attributes. The ~falcon.Request.prefix attribute was also added as part of this work.
A ~falcon.Request.referer attribute was added to ~falcon.Request.
We implemented __repr__() for ~falcon.Request, ~falcon.Response, and ~.HTTPError to aid in debugging.
A number of Internet media type constants were defined to make it easier to check and set content type headers. (See also: Media Type Constants)
Several new 5xx error classes were implemented. (See also: Error Handling)
If even a single cookie in the request to the server is malformed, none of the cookies will be parsed (all-or-nothing). Change the parser to simply skip bad cookies (best-effort).
~.API instances are not pickleable. Modify the default router to fix this.
Nothing published for this version
Nothing published for this version
Nothing published for this version
port, netloc and scheme properties were added to the falcon.Request class. The protocol property is now deprecated and will be removed in a future rel…
(None)
A new default kwarg was added to ~falcon.Request.get_header.
A ~falcon.Response.delete_header method was added to falcon.Response.
Several new HTTP status codes and error classes were added, such as falcon.HTTPFailedDependency.
If ujson is installed it will be used in lieu of json to speed up error serialization and query string parsing under CPython. PyPy users should continue to use json.
The independent_middleware kwarg was added to falcon.API to enable the execution of process_response() middleware methods, even when process_request() raises an error.
Single-character field names are now allowed in URL templates when specifying a route.
A detailed error message is now returned when an attempt is made to add a route that conflicts with one that has already been added.
The HTTP protocol version can now be specified when simulating requests with the testing framework.
The falcon.ResponseOptions class was added, along with a secure_cookies_by_default option to control the default value of the "secure" attribute when setting cookies. This can make testing easier by providing a way to toggle whether or not HTTPS is required.
port, netloc and scheme properties were added to the falcon.Request class. The protocol property is now deprecated and will be removed in a future release.
The strip_url_path_trailing_slash was added to falcon.RequestOptions to control whether or not to retain the trailing slash in the URL path, if one is present. When this option is enabled (the default), the URL path is normalized by stripping the trailing slash character. This lets the application define a single route to a resource for a path that may or may not end in a forward slash. However, this behavior can be problematic in certain cases, such as when working with authentication schemes that employ URL-based signatures. Therefore, the strip_url_path_trailing_slash option was introduced to make this behavior configurable.
Improved the documentation for falcon.HTTPError, particularly around customizing error serialization.
Misc. improvements to the look and feel of Falcon's documentation.
The tutorial in the docs was revamped, and now includes guidance on testing Falcon applications.
Certain non-alphanumeric characters, such as parenthesis, are not handled properly in complex URI template path segments that are comprised of both literal text and field definitions.
When the WSGI server does not provide a wsgi.file_wrapper object, Falcon wraps Response.stream in a simple iterator object that does not implement close(). The iterator should be modified to implement a close() method that calls the underlying stream's close() to free system resources.
The testing framework does not correctly parse cookies under Jython.
Whitespace is not stripped when parsing cookies in the testing framework.
The Vary header is not always set by the default error serializer.
While not specified in PEP-3333 that the status returned to the WSGI server must be of type str, setting the status on the response to a unicode string under Python 2.6 or 2.7 can cause WSGI servers to raise an error. Therefore, the status string must first be converted if it is of the wrong type.
The default OPTIONS responder returns 204, when it should return 200. RFC 7231 specifically states that Content-Length should be zero in the response to an OPTIONS request, which implies a status code of 200 since RFC 7230 states that Content-Length must not be set in any response with a status code of 204.
Nothing published for this version
A new bounded_stream property was added to falcon.Request that can be used in place of the stream property to mitigate the blocking behavior of input
(None)
A new bounded_stream property was added to falcon.Request that can be used in place of the stream property to mitigate the blocking behavior of input objects used by some WSGI servers.
A new uri_template property was added to ~falcon.Request to expose the template for the route corresponding to the path requested by the user agent.
A context property was added to ~falcon.Response to mirror the same property that is already available for ~falcon.Request.
JSON-encoded query parameter values can now be retrieved and decoded in a single step via ~falcon.Request.get_param_as_dict.
CSV-style parsing of query parameter values can now be disabled.
~falcon.Request.get_param_as_bool now recognizes "on" and "off" in support of IE's default checkbox values.
An accept_ranges property was added to ~falcon.Response to facilitate setting the Accept-Ranges header.
Added the ~falcon.HTTPUriTooLong and ~falcon.HTTPGone error classes.
When a title is not specified for ~falcon.HTTPError, it now defaults to the HTTP status text.
All parameters are now optional for most error classes.
Cookie-related documentation has been clarified and expanded
The falcon.testing.Cookie class was added to represent a cookie returned by a simulated request. falcon.testing.Result now exposes a cookies attribute for examining returned cookies.
pytest support was added to Falcon's testing framework. Apps can now choose to either write unittest- or pytest-style tests.
The test runner for Falcon's own tests was switched from nose to pytest.
When simulating a request using Falcon's testing framework, query string parameters can now be specified as a dict, as an alternative to passing a raw query string.
A flag is now passed to the process_request middleware method to signal whether or not an exception was raised while processing the request. A shim was added to avoid breaking existing middleware methods that do not yet accept this new parameter.
A new CLI utility, falcon-print-routes, was added that takes in a module:callable, introspects the routes, and prints the results to stdout. This utility is automatically installed along with the framework:
$ falcon-print-routes commissaire:api
-> /api/v0/status
-> /api/v0/cluster/{name}
-> /api/v0/cluster/{name}/hosts
-> /api/v0/cluster/{name}/hosts/{address}
Custom attributes can now be attached to instances of ~falcon.Request and ~falcon.Response. This can be used as an alternative to adding values to the context property, or implementing custom subclasses.
~falcon.get_http_status was implemented to provide a way to look up a full HTTP status line, given just a status code.
When auto_parse_form_urlencoded is set to True, the framework now checks the HTTP method before attempting to consume and parse the body.
Before attempting to read the body of a form-encoded request, the framework now checks the Content-Length header to ensure that a non-empty body is expected. This helps prevent bad requests from causing a blocking read when running behind certain WSGI servers.
When the requested method is not implemented for the target resource, the framework now raises ~falcon.HTTPMethodNotAllowed, rather than modifying the ~falcon.Request object directly. This improves visibility for custom error handlers and for middleware methods.
Error class docstrings have been updated to reflect the latest RFCs.
When an error is raised by a resource method or a hook, the error will now always be processed (including setting the appropriate properties of the ~falcon.Response object) before middleware methods are called.
A case was fixed in which middleware processing did not continue when an instance of ~falcon.HTTPError or ~falcon.HTTPStatus was raised.
The ~falcon.uri.encode method will now attempt to detect whether the specified string has already been encoded, and return it unchanged if that is the case.
The default OPTIONS responder now explicitly sets Content-Length to zero in the response.
falcon.testing.Result now assumes that the response body is encoded as UTF-8 when the character set is not specified, rather than raising an error when attempting to decode the response body.
When simulating requests, Falcon's testing framework now properly tunnels Unicode characters through the WSGI interface.
import falcon.uri now works, in addition to from falcon import uri.
URI template fields are now validated up front, when the route is added, to ensure they are valid Python identifiers. This prevents cryptic errors from being raised later on when requests are routed.
When running under Python 3, inspect.signature() is used instead of inspect.getargspec() to provide compatibility with annotated functions.
Nothing published for this version
Nothing published for this version
Implementing this required passing the ~falcon.Response object to the serializer, which would normally be a breaking change. However, the framework wa…
The deprecated global hooks feature has been removed. ~falcon.API no longer accepts before and after kwargs. Applications can work around this by migrating any logic contained in global hooks to reside in middleware components instead.
The middleware method process_resource must now accept an additional params argument. This gives the middleware method an opportunity to interact with the values for any fields defined in a route's URI template.
The middleware method process_resource is now skipped when no route is found for the incoming request. This avoids having to include an if resource is not None check when implementing this method. A sink may be used instead to execute logic in the case that no route is found.
An option was added to toggle automatic parsing of form params. Falcon will no longer automatically parse, by default, requests that have the content type "application/x-www-form-urlencoded". This was done to avoid unintended side-effects that may arise from consuming the request stream. It also makes it more straightforward for applications to customize and extend the handling of form submissions. Applications that require this functionality must re-enable it explicitly, by setting a new request option that was added for that purpose, per the example below:
app = falcon.API() app.req_options.auto_parse_form_urlencoded = True
The ~falcon.HTTPUnauthorized initializer now requires an additional argument, challenges. Per RFC 7235, a server returning a 401 must include a WWW-Authenticate header field containing at least one challenge.
The performance of composing the response body was improved. As part of this work, the Response.body_encoded attribute was removed. This property was only intended to be used by the framework itself, but any dependent code can be migrated per the example below:
# Before
body = resp.body_encoded
# After
if resp.body:
body = resp.body.encode('utf-8')
else:
body = b''
A code of conduct was added to solidify our community's commitment to sustaining a welcoming, respectful culture.
CPython 3.5 is now fully supported.
The constants HTTP_422, HTTP_428, HTTP_429, HTTP_431, HTTP_451, and HTTP_511 were added.
The ~falcon.HTTPUnprocessableEntity, ~falcon.HTTPTooManyRequests, and ~falcon.HTTPUnavailableForLegalReasons error classes were added.
The HTTPStatus class is now available directly under the falcon module, and has been properly documented.
Support for HTTP redirections was added via a set of HTTPStatus subclasses. This should avoid the problem of hooks and responder methods possibly overriding the redirect. Raising an instance of one of these new redirection classes will short-circuit request processing, similar to raising an instance of ~falcon.HTTPError.
The default 404 responder now raises an instance of ~falcon.HTTPError instead of manipulating the response object directly. This makes it possible to customize the response body using a custom error handler or serializer.
A new method, ~falcon.Response.get_header, was added to ~falcon.Response. Previously there was no way to check if a header had been set. The new ~falcon.Response.get_header method facilitates this and other use cases.
falcon.Request.client_accepts_msgpack now recognizes "application/msgpack", in addition to "application/x-msgpack".
New ~falcon.Request.access_route and ~falcon.Request.remote_addr properties were added to ~falcon.Request for getting upstream IP addresses.
~falcon.Request and ~falcon.Response now support range units other than bytes.
The ~falcon.API and ~falcon.testing.StartResponseMock class types can now be customized by inheriting from ~falcon.testing.TestBase and overriding the api_class and srmock_class class attributes.
Path segments with multiple field expressions may now be defined at the same level as path segments having only a single field expression. For example:
api.add_route('/files/{file_id}', resource_1)
api.add_route('/files/{file_id}.{ext}', resource_2)
Support was added to API.add_route() for passing through additional args and kwargs to custom routers.
Digits and the underscore character are now allowed in the falcon.routing.compile_uri_template helper, for use in custom router implementations.
A new testing framework was added that should be more intuitive to use than the old one. Several of Falcon's own tests were ported to use the new framework (the remainder to be ported in a subsequent release.) The new testing framework performs wsgiref validation on all requests.
The performance of setting Response.content_range was improved by ~50%.
A new param, obs_date, was added to falcon.Request.get_header_as_datetime, and defaults to False. This improves the method's performance when obsolete date formats do not need to be supported.
Field expressions at a given level in the routing tree no longer mask alternative branches. When a single segment in a requested path can match more than one node at that branch in the routing tree, and the first branch taken happens to be the wrong one (i.e., the subsequent nodes do not match, but they would have under a different branch), the other branches that could result in a successful resolution of the requested path will now be subsequently tried, whereas previously the framework would behave as if no route could be found.
The user agent is now instructed to expire the cookie when it is cleared via ~falcon.Response.unset_cookie.
Support was added for hooks that have been defined via functools.partial.
Tunneled UTF-8 characters in the request path are now properly decoded, and a placeholder character is substituted for any invalid code points.
The instantiation of ~falcon.Request.context_type is now delayed until after all other properties of the ~falcon.Request class have been initialized, in case the context type's own initialization depends on any of ~falcon.Request's properties.
A case was fixed in which reading from ~falcon.Request.stream could hang when using wsgiref to host the app.
The default error serializer now sets the Vary header in responses. Implementing this required passing the ~falcon.Response object to the serializer, which would normally be a breaking change. However, the framework was modified to detect old-style error serializers and wrap them with a shim to make them compatible with the new interface.
A query string containing malformed percent-encoding no longer causes the framework to raise an error.
Additional tests were added for a few lines of code that were previously not covered, due to deficiencies in code coverage reporting that have since been corrected.
The Cython note is no longer displayed when installing under Jython.
Several errors and ambiguities in the documentation were corrected.
Nothing published for this version
Nothing published for this version
Date headers are now returned as datetime.datetime objects instead of strings.
Date headers are now returned as datetime.datetime objects instead of strings.
The expected signature for the add_route() method of custom routers no longer includes a method_map parameter. Custom routers should, instead, call the falcon.routing.util.map_http_methods function directly from their add_route() method if they require this mapping.
This release includes a new router architecture for improved performance and flexibility.
A custom router can now be specified when instantiating the API class.
URI templates can now include multiple parameterized fields within a single path segment.
Falcon now supports reading and writing cookies.
Falcon now supports Jython 2.7.
A method for getting a query param as a date was added to the Request class.
Date headers are now returned as datetime.datetime objects.
A default value can now be specified when calling Request.get_param. This provides an alternative to using the pattern:
value = req.get_param(name) or default_value
Friendly constants for status codes were added (e.g., falcon.HTTP_NO_CONTENT vs. falcon.HTTP_204.)
Several minor performance optimizations were made to the code base.
The query string parser was modified to improve handling of percent-encoded data.
Several errors in the documentation were corrected.
The six package was pinned to 1.4.0 or better. six.PY2 is required by Falcon, but that wasn't added to six until version 1.4.0.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →