NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1638 most downloaded on PyPI
FastAPI plugin to enable SSO to most common providers (such as Facebook login, Google login and login via Microsoft Office 365 Account)
Last release 13 days ago
21 Sep 2026
Release timing varies
gaps range from 2 weeks to 9 months
Most releases are documented
notes for 39 of 49 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
49 releases · first in 2021
One column per quarter.
docs: route vulnerability reports through private advisories by @autonomous-bot-agent-tomasvotava[bot] in #310
Full Changelog: 0.22.0...0.23.0
⚠️ Security fix and breaking change
This release fixes an OAuth login CSRF vulnerability
(GHSA-wgrh-7h2j-rg46,
CWE-352), reported by @mohammedix88 (cystack.ps redteam).
SSOBase.requires_state defaulted to False, so the state validation added in 0.19.0 never ran
unless you opted in. Any application on the default configuration accepted a callback with nothing
bound to the caller's session. Upgrading is recommended for all users.
requires_state now defaults to True. A login flow that does not carry the sso_state cookie
back to your callback will now fail with 401 State cookie not found. This affects you if:
async with sso:), so no state is generatedget_login_url, which returns a URL and sets no cookie.SecurityWarning at login time, so you will see it before your users doIf you cannot carry the cookie, you can opt out per instance and keep the old behaviour, at the cost
of losing CSRF protection:
sso = GoogleSSO(client_id, client_secret, redirect_uri)
sso.requires_state = FalseThe sso_state cookie is now also set HttpOnly, SameSite=lax, and Secure unless
allow_insecure_http is enabled.
Full Changelog: 0.21.1...0.22.0
chore(deps): bump vulnerable transitive deps (pillow, cairosvg, urllib3) by @tomasvotava in #293
Dependencies-only release
Full Changelog: 0.21.0...0.21.1
feat: remove python 3.9 support, add python 3.14 support by @tomasvotava in #274
Full Changelog: 0.20.0...0.21.0
chore(deps): bump the all group across 1 directory with 3 updates by @dependabot [bot] in #270
Full Changelog: 0.19.0...0.20.0
️ ⚠️ A critical OAuth login CSRF vulnerability caused by missing state validation was reported by @davidbors-snyk (Snyk Security Labs) in #266 and has…
️⚠️ A critical OAuth login CSRF vulnerability caused by missing state validation was
reported by @davidbors-snyk (Snyk Security Labs)
in #266 and has been resolved
in version 0.19.0.
Starting with fastapi-sso==1.0.0, OAuth state will be backed by a pluggable server-side store
(in-memory by default, with support for external stores such as Redis).
Full Changelog: 0.18.0...0.19.0
chore: add Python 3.13 to testing and linting workflows by @tomasvotava in #226
Removed support for python 3.8
Full Changelog: 0.17.0...0.18.0
docs: update guide on return urls by @tomasvotava in #206
Full Changelog: 0.16.0...0.17.0
Thanks @afi-dev for the contribution!
Please see the security notice before upgrading.
Please see the security notice before upgrading.
Full Changelog: 0.15.0...0.16.0
chore(deps): bump the all group across 1 directory with 10 updates by @dependabot in #158
"" was invalid and should be None by @tomasvotava in #166Full Changelog: 0.14.2...0.15.0
[hotfix] add naver email, nickname fields(optinal). by @dalbodeule in #153
Full Changelog: 0.14.1...0.14.2
chore(deps): bump the all group with 3 updates by @dependabot in #149
Full Changelog: 0.14.0...0.14.1
feat: added Yandex SSO provider by @akimrx in https://github.com/tomasvotava/fastapi-sso/pull/146
Full Changelog: https://github.com/tomasvotava/fastapi-sso/compare/0.13.1...0.14.0
chore(deps): bump the all group with 3 updates by @dependabot in https://github.com/tomasvotava/fastapi-sso/pull/140
Full Changelog: https://github.com/tomasvotava/fastapi-sso/compare/0.13.0...0.13.1
feat: add TwitterSSO to support Twitter (X) login by @tomasvotava in https://github.com/tomasvotava/fastapi-sso/pull/139
Full Changelog: https://github.com/tomasvotava/fastapi-sso/compare/0.12.2...0.13.0
chore(deps): bump the all group with 12 updates by @dependabot in https://github.com/tomasvotava/fastapi-sso/pull/135
Full Changelog: https://github.com/tomasvotava/fastapi-sso/compare/0.12.1...0.12.2
remove pylint from runtime dependencies
Full Changelog: https://github.com/tomasvotava/fastapi-sso/compare/0.12.0...0.12.1
feat: add id_token property to enhance support for OpenID responses
id_token property to enhance support for OpenID responsesFull Changelog: https://github.com/tomasvotava/fastapi-sso/compare/0.11.0...0.12.0
chore(deps): bump the all group with 2 updates by @dependabot in https://github.com/tomasvotava/fastapi-sso/pull/116
Full Changelog: https://github.com/tomasvotava/fastapi-sso/compare/0.10.0...0.11.0
fix: use additional_headers for user endpoint
additional_headers for user endpointonly allow valid e-mail addresses in OpenID's email field
email fieldContributed by @parfeniukink
obtain github users' email even if private
openid_from_responseadd email to default MicrosoftSSO scopes
add email to default MicrosoftSSO scopes
do not fail if Microsoft API does not return mail in its response
starlette is now an indirect dependency
added support for Python 3.12
- PEP 561 compliance credits to @parfeniukink
credits to @parfeniukink
import paths can now be shorter
from fastapi_sso.sso.base import OpenID is now available as from fastapi_sso import OpenIDfix: add User.Read to MicrosoftSSO's scope
User.Read to MicrosoftSSO's scopefixed Github OpenID validation errors (contributed by @MP-StefanKraus)
🔒 add security warning for versions < 0.7.0 due to shared state vulnerability
with statement- deprecate use_state parameter
use_state parameteradded additional_headers parameter
additional_headers parameterredirect_uri can be set during the primal requestgeneric SSO provider class factory
Nothing published for this version
Added support for login using Fitbit.
Added support for login using Fitbit.
kakao support (contributed by Jae-Baek Song - thdwoqor)
params argument (allows to specify access_type: offline etc.
params argument (allows to specify access_type: offline etc.scope argument for SSOBase constructorexamples/Allow specifying redirect_uri on request time.
Allow specifying redirect_uri on request time.
do not force body on GET request
do not force body on GET request
Use httpx instead of aiohttp
Use httpx instead of aiohttp
Nothing published for this version
optional state parameter usage
optional state parameter usage
allow HTTP for testing (see this issue)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →