NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3514 most downloaded on PyPI
Ready-to-use and customizable users management for FastAPI
Last release 6 months ago
27 Mar 2026
Release timing varies
gaps range from 2 weeks to 10 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
112 releases · first in 2019
Bump version 15.0.4 → 15.0.5 Bump dependencies: pyjwt[crypto] >=2.12.0,<3.0.0
Bump version 15.0.4 → 15.0.5
pyjwt[crypto] >=2.12.0,<3.0.0python-multipart >=0.0.22,<0.1.0"
Bump version 15.0.3 → 15.0.4
pyjwt[crypto] >=2.11.0,<3.0.0python-multipart >=0.0.22,<0.1.0"Add cookie parameters added in 15.0.1 to FastAPIUsers.get_oauth_router and FastAPIUsers.get_oauth_associate_router . Thanks @jthurner 🎉
One column per quarter.
Bump version 15.0.2 → 15.0.3
FastAPIUsers.get_oauth_router and FastAPIUsers.get_oauth_associate_router. Thanks @jthurner 🎉A CSRF vulnerability was identified in the OAuth2 flow. To mitigate this, the authorize endpoint will set a cookie in the response, and this cookie wi…
Bump version 15.0.1 → 15.0.2
A CSRF vulnerability was identified in the OAuth2 flow. To mitigate this, the authorize endpoint will set a cookie in the response, and this cookie will be expected in the callback request.
In most cases, this change should work out-of-the-box, but in certain scenarios (e.g. cross-domain setups), additional configuration may be required for the cookie to be correctly sent and received. [Read more]
Thanks to @davidbors-snyk from Snyk for his research, responisble disclosure, and assistance in fixing this issue.
python-multipart ==0.0.21pwdlib[argon2,bcrypt] ==0.3.0FastAPI Users is now in maintenance mode. While we'll continue to provide security updates and dependency maintenance, no new features will be added.
Bump version 15.0.0 → 15.0.1
FastAPI Users is now in maintenance mode.** While we'll continue to provide security updates and dependency maintenance, no new features will be added. We encourage you to explore the project and use it as-is, knowing it will remain stable and secure.
FastAPI Users is now in maintenance mode. While we'll continue to provide security updates and dependency maintenance, no new features will be added.
Bump version 14.0.2 → 15.0.0
FastAPI Users is now in maintenance mode.** While we'll continue to provide security updates and dependency maintenance, no new features will be added. We encourage you to explore the project and use it as-is, knowing it will remain stable and secure.
If you still need them, you can install v14.0.2, which was updated at the same time as this release.
This is the last release to support Python 3.9 and Pydantic v1.
Bump version 14.0.1 → 14.0.2
email-validator >=1.1.0,<2.4redis >=4.3.3,<8.0.0Bump version 14.0.0 → 14.0.1 Improvements Bump dependencies pyjwt[crypto] ==2.10.1 python-multipart ==0.0.20
Bump version 14.0.0 → 14.0.1
pyjwt[crypto] ==2.10.1python-multipart ==0.0.20Bump version 13.0.0 → 14.0.0 Breaking changes Drop Python 3.8 support Improvements Bump dependencies: python-multipart ==0.0.17 pwdlib[argon2,bcrypt]
Bump version 13.0.0 → 14.0.0
python-multipart ==0.0.17pwdlib[argon2,bcrypt] ==0.2.1pyjwt[crypto] ==2.9.0The underlying password hashing library has been changed from passlib to pwdlib . This change is breaking only if you were using a custom CryptContext
Bump version 12.1.3 → 13.0.0
The underlying password hashing library has been changed from passlib to pwdlib. This change is breaking only if you were using a custom CryptContext. Otherwise, you can upgrade without any changes.
python-multipart ==0.0.9Bump version 12.1.2 → 12.1.3 Improvements ------------ * Bump dependenciess * python-multipart ==0.0.7
Bump version 12.1.2 → 12.1.3
python-multipart ==0.0.7Fix a bug when trying to update user with a None password. Thanks @fotinakis 🎉
Bump version 12.1.1 → 12.1.2
None password. Thanks @fotinakis 🎉AccessTokenProtocol. Thanks @Nerixjk 🎉redis >=4.3.3,<6.0.0Add missing request parameter to UserManager.delete. Thanks @hgalytoby 🎉
Bump version 12.1.0 → 12.1.1
request parameter to UserManager.delete. Thanks @hgalytoby 🎉__init__ method from models protocols to fix Pylance typing error. Thanks @Nerixjk 🎉pyjwt[crypto] ==2.8.0This version brings Pydantic V2 support. Like FastAPI, it keeps backward-compatibility with Pydantic V1, so you can upgrade safely and at your own pac
Bump version 12.0.0 → 12.1.0
This version brings Pydantic V2 support. Like FastAPI, it keeps backward-compatibility with Pydantic V1, so you can upgrade safely and at your own pace.
Apart your own Pydantic schemas, no changes are needed to your FastAPI Users setup.
Thanks @AdamIsrael for the initial work and research 🎉
Bump version 11.0.0 → 12.0.0 Breaking changes ---------------- * Drop Python 3.7 support
Bump version 11.0.0 → 12.0.0
Transport classes now always build full response objects instead of using the implicit FastAPI Response object.
Bump version 10.4.2 → 11.0.0
Response object.
Response object. [Example]204 No Content response on logout, which should please OpenAPI Generators. Thanks @caniko 🎉on_after_login method now accepts response in argument, which is the Response object built by the transport. [Documentation] Thanks @sorasful 🎉/verify route returning null user ID with Beanie. Thanks @jankadel 🎉Update documentation for Beanie.
Bump version 10.4.1 → 10.4.2
Fix #1172: missing is_verified_by_default argument on get_oauth_router method
Bump version 10.4.0 → 10.4.1
is_verified_by_default argument on get_oauth_router methodpython-multipart ==0.0.6SQLAlchemy 2.0 support [Documentation]
Bump version 10.3.0 → 10.4.0
fastapi-users-db-sqlalchemy<5.0.0is_verified flag to True by default after OAuth registration [Documentation]httpx-oauth >=0.4,<0.12Ensure the reset password token can be used only once.
Bump version 10.2.1 → 10.3.0
sub claim instead of user_id.
sub claim instead of user_id.With httpx-oauth >= 0.10, the OAuth2 client may be not able to return an email address depending on the OAuth Provider. In this case, the error OAUTH_
Bump version 10.2.0 → 10.2.1
httpx-oauth >=0.4,<0.11
httpx-oauth >= 0.10, the OAuth2 client may be not able to return an email address depending on the OAuth Provider. In this case, the error OAUTH_NOT_AVAILABLE_EMAIL is raised during /callback. [Documentation]Trigger custom logic after user login with on_after_login. [Documentation] Thanks @antont 🎉
Bump version 10.1.5 → 10.2.0
on_after_login. [Documentation] Thanks @antont 🎉email-validator >=1.1.0,<1.4pyjwt[crypto] ==2.5.0## Improvements * Bump dependencies: * makefun >=1.11.2,<2.0.0 * httpx-oauth >=0.4,<0.8
makefun >=1.11.2,<2.0.0httpx-oauth >=0.4,<0.8Rollback CookieTransport changes (77d0077503d9d6b4dd206e3fc643d96bc3c5834c) to temporary fix #1048. Thanks @davidbrochart 🎉
CookieTransport changes (77d0077503d9d6b4dd206e3fc643d96bc3c5834c) to temporary fix #1048. Thanks @davidbrochart 🎉RedisStrategy: add a prefix to keys to avoid an enumeration attack. [Read more] Thanks @flipee 🎉
RedisStrategy: add a prefix to keys to avoid an enumeration attack. [Read more] Thanks @flipee 🎉Return a proper 204 empty response on successful login for CookieTransport. Thanks @caniko 🎉
CookieTransport. Thanks @caniko 🎉Fix get_oauth_associate_router import to keep OAuth dependencies optional. Thanks @schwannden 🎉
get_oauth_associate_router import to keep OAuth dependencies optional. Thanks @schwannden 🎉Account e-mail association when authenticating with OAuth is now disabled by default for security reasons. It can be re-enabled on the router using th
associate_by_email flag. [Documentation]on_before_delete and on_after_delete. [Documentation] Thanks @schwannden 🎉httpx-oauth >=0.4,<=0.7 Thanks @carloe 🎉FastAPI dependency is now unconstrained, meaning FastAPI Users will always be installable with the latest version of FastAPI. Thanks @austinorr 🎉
redis package, as async support has been merged into it. Thanks @applied-mathematician 🎉Upgrade pyjwt[crypto] ==2.4.0 to fix CVE-2022-29217. Thanks @JimScope 🎉
pyjwt[crypto] ==2.4.0 to fix CVE-2022-29217. Thanks @JimScope 🎉Fix #1000: using Beanie, id was null in API responses. Thanks @JimScope 🎉
id was null in API responses. Thanks @JimScope 🎉## Improvements * Bump dependencies: * fastapi >=0.65.2,<0.79.0
fastapi >=0.65.2,<0.79.0## Improvements * Bump dependencies: * fastapi >=0.65.2,<0.78.0 * email-validator >=1.1.0,<1.3
fastapi >=0.65.2,<0.78.0email-validator >=1.1.0,<1.3Set Pydantic orm_mode on BaseUser schema
orm_mode on BaseUser schemaFix generic typing on AuthenticationBackend class
AuthenticationBackend classVersion 10 marks important changes in how we manage User models and their ID.
Version 10 marks important changes in how we manage User models and their ID.
Before, we were relying only on Pydantic models to work with users. In particular the current_user dependency would return you an instance of UserDB, a Pydantic model. This proved to be quite problematic with some ORM if you ever needed to retrieve relationship data or make specific requests.
Now, FastAPI Users is designed to always return you a native object for your ORM model, whether it's an SQLAlchemy model or a Beanie document. Pydantic models are now only used for validation and serialization inside the API.
Before, we were forcing the use of UUID as primary key ID; a consequence of the design above. This proved to be quite problematic on some databases, like MongoDB which uses a special ObjectID format by default. Some SQL folks also prefer to use traditional auto-increment integers.
Now, FastAPI Users is designed to use generic ID type. It means that you can use any type you want for your user's ID. By default, SQLAlchemy adapter still use UUID; but you can quite easily switch to another thing, like an integer. Beanie adapter for MongoDB will use native ObjectID by default, but it also can be overriden.
Add version guards for DB adapters in prevision of v10
Fix a bug where OAuth accounts could collide if providers use the same ID. Thanks @ricfri 🎉
httpx-oauth >=0.4,<0.7Allow to use RS256/ES256 algorithms to sign JWT. [Documentation] Thanks @jtv8 🎉
## Fixes and improvements * Bump dependencies: * fastapi >=0.65.2,<0.76.0
fastapi >=0.65.2,<0.76.0Improve route names to avoid duplicates. Thanks @gaganpreet 🎉
DependencyCallable type to allow for AsyncGenerator and Generator.fastapi >=0.65.2,<0.75.0Build now generates a setup.py file to ease installation on some systems. Thanks @mekanix 🎉
setup.py file to ease installation on some systems. Thanks @mekanix 🎉## Bug fixes and improvements * Bump dependencies * fastapi >=0.65.2,<0.74.0 ## Documentation * Fix SQLAlchemy examples
fastapi >=0.65.2,<0.74.0Fix #865: fastapi_users.db module exports were not discovered correctly by IDE. Thanks @Ae-Mc 🎉
fastapi_users.db module exports were not discovered correctly by IDE. Thanks @Ae-Mc 🎉Fix #846: cookies are now correctly deleted when using custom SameSite option. Thanks @Hazedd 🎉
SameSite option. Thanks @Hazedd 🎉fastapi >=0.65.2,<0.72.0makefun >=1.11.2,<1.14The previous one is still available on fastapi-users[sqlalchemy] but is now deprecated.
pip install fastapi-users[sqlalchemy2]fastapi-users[sqlalchemy] but is now deprecated.Bump database adapters dependencies versions to work with new Database strategy. [Documentation]
Database authentication strategy: access tokens are stored in your database. [Documentation]
Fix ImportError when redis optional dependency not installed.
ImportError when redis optional dependency not installed.Version 9 changes the way authentication backends work so that they are more modular and ease the integration of new methods.
Version 9 changes the way authentication backends work so that they are more modular and ease the integration of new methods.
Please read the migration page to update your configuration.
This is a critical bug fix for v8 branch. Still, I can't commit to maintain both versions, so consider upgrading to v9 as soon as possible.
This is a critical bug fix for v8 branch. Still, I can't commit to maintain both versions, so consider upgrading to v9 as soon as possible.
Fix #823: OpenAPI error when wiring several OAuth routers. Thanks @matyasrichter 🎉
Every route is now fully documented through OpenAPI schema. Thanks @matyasrichter 🎉
When changing the e-mail address, the is_verified flag is correctly reset to False. Thanks @jakemanger 🎉
is_verified flag is correctly reset to False. Thanks @jakemanger 🎉name allowing programmatic path generation using url_for. Thanks @BrandonGoding and @ricardoorfao 🎉pyjwt ==2.3.0httpx-oauth >=0.4,<0.5Fix custom reset password token audience not being set correctly in UserManager. Thanks @maximka1221 🎉
UserManager. Thanks @maximka1221 🎉fastapi >=0.65.2,<0.71.0pyjwt ==2.2.0makefun >=1.9.2,<1.13Dynamic selection of authentication backends when using the current_user dependency. [Documentation]
current_user dependency. [Documentation]get_login_response and get_logout_response methods of authentication backends are called with a UserManager instance in argument.
Version 8 includes the biggest code changes since version 1. We reorganized lot of parts of the code to make it even more modular and integrate more i
Version 8 includes the biggest code changes since version 1. We reorganized lot of parts of the code to make it even more modular and integrate more into the dependency injection system of FastAPI.
Please read the migration page to update your configuration.
UserManager. [Documentation]UserManager. [Documentation]UserManager. [Documentation]UserManager. [Documentation]get_user_manager dependency. [Documentation]UserManager class.UPDATE_USER_EMAIL_ALREADY_EXISTS is not raised anymore. Thanks @ScrimForever 🎉Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →