NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3514 most downloaded on PyPI
Ready-to-use and customizable users management for FastAPI
Last release 6 months ago
27 Mar 2026
Release timing varies
gaps range from 2 weeks to 10 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
112 releases · first in 2019
The deprecated dependencies to retrieve current user have been removed. Use the current_user factory instead. [Documentation]
current_user factory instead. [Documentation]UserUpdate model shouldn't inherit from the base User class anymore. If you have custom fields, you should repeat them in this model. [Documentation]import statements remain unchanged.SecretStr class. Thanks @pocin 🎉One column per quarter.
Repository is now at: https://github.com/fastapi-users/fastapi-users/
## Improvements * Bump dependencies: * fastapi >=0.65.2,<0.69.0
fastapi >=0.65.2,<0.69.0Fix #646: add a python_type to the GUID column type for SQLAlchemy database backend. Thanks @mark-todd 🎉
python_type to the GUID column type for SQLAlchemy database backend. Thanks @mark-todd 🎉null in content with a 204 status code (see #650). Thanks @jnu 🎉fastapi >=0.65.2,<0.67.0Password validation feature: use your own function to validate password. It'll get called consistently at registration, password reset and user update
fastapi >=0.63.0,<0.66.0pyjwt ==2.1.0tokenUrl argument. Thanks @eddsalkield 🎉Fix #600: the Tortoise ORM integration has been heavily reworked to better handle foreign keys and nested objects. If you use Tortoise ORM, you should
Fix #561: check if e-mail not already exists when updating e-mail.
LOGIN_USER_NOT_VERIFIED error code for the /login route.Allow lifetime_seconds to be None in CookieAuthentication to allow session cookies.
lifetime_seconds to be None in CookieAuthentication to allow session cookies.tortoise-orm >=0.16.0,<0.18.0ormar >=0.9.5,<0.10.0Fix BaseUserDB typing by making email, is_active, is_superuser and is_verified non optional
BaseUserDB typing by making email, is_active, is_superuser and is_verified non optionalFix #515: remove deprecated user callables in internal codebase
py.typed to ensure mypy is type checking the library in external projectsOld dependency callables are still provided for backward-compatibility but are now deprecated and will be removed in the future.
current_user that will replace get_current_user and friends. [Documentation]
/users router to be catched by default routes.pyjwt ==2.0.1New property is_verified in User model.
is_verified in User model.
after_reset_password handler to run logic after a successful password reset. [Documentation]Fix #431: expires_at property in OAuthAccount is now optional.
expires_at property in OAuthAccount is now optional.
## Improvements * Bump dependencies: * fastapi >=0.54.0,<0.64.0
fastapi >=0.54.0,<0.64.0Fix #401: missing typing_extensions import. Thanks @roywes 🎉
typing_extensions import. Thanks @roywes 🎉Protocol from typing and fallback to typing_extensions if not available. Thanks @roywes 🎉fastapi >=0.54.0,<0.63.0Expose helper function to create a user programmatically. [Documentation]
## Improvements * Bump dependencies: * databases >=0.3.0,<0.5
databases >=0.3.0,<0.5Fix #343: missing VARCHAR parameter with MySQL database. Thanks @lill74 🎉
VARCHAR parameter with MySQL database. Thanks @lill74 🎉passlib[bcrypt]==1.7.4## Improvements * Bump dependencies * motor ==2.2.0
motor ==2.2.0## Improvements * Bump dependencies * fastapi >=0.54.0,<0.62.0
fastapi >=0.54.0,<0.62.0## Improvements * Bump dependencies * fastapi >=0.54.0,<0.61.0
fastapi >=0.54.0,<0.61.0Fix #261: safer and proper email query in MongoDB thanks to an index with case-insensitive collation. Thanks @MariusMez!
## Improvements * Bump dependencies * fastapi >=0.54.0,<0.60.0
fastapi >=0.54.0,<0.60.0Emails are now case-insensitive. Thanks @MariusMez for raising this point!
Fix #171 : Swagger documentation for /register endpoint only shows relevant fields. Thanks @martincolladofab!
/register endpoint only shows relevant fields. Thanks @martincolladofab!
UserRegister model inherit from the User model. This way, you can fine tune the fields you want for registration.JWT authentication backend now outputs token in access_token property rather than token.
access_token property rather than token.fastapi>=0.54.0,<0.59.0## Improvements * Bump dependencies: * fastapi >=0.54.0,<0.56.0
fastapi >=0.54.0,<0.56.0Add get_optional_user_* dependency callables to optionally retrieve an authenticated user without raising an HTTP error. [Documentation]
get_optional_user_* dependency callables to optionally retrieve an authenticated user without raising an HTTP error. [Documentation]FastAPIUsers in its constructor.This is a major release with lot of changes under the hood. Please review the Migration documentation carefully.
This is a major release with lot of changes under the hood. Please review the Migration documentation carefully.
## Improvements * Bump dependencies: * email-validator ==1.1.0
email-validator ==1.1.0Remove the list users endpoint. It seemed to me that it was too opinionated ; and I prefer end-developer to implement it its own way with pagination,
databases >=0.3.0,<0.4## Improvements * Bump dependencies * fastapi >=0.54.0,<0.55.0 * httpx-oauth >=0.2.2,<0.3
fastapi >=0.54.0,<0.55.0httpx-oauth >=0.2.2,<0.3## Improvements * Bump dependencies * fastapi>=0.53.0,<0.54.0
fastapi>=0.53.0,<0.54.0## Improvements * Bump dependencies: * fastapi>=0.52.0,<0.53.0 * tortoise-orm>=0.15.18,<0.16.0
fastapi>=0.52.0,<0.53.0tortoise-orm>=0.15.18,<0.16.0## Improvements * Bump dependencies: * fastapi>=0.50.0,<0.51.0 * tortoise-orm==0.15.17
fastapi>=0.50.0,<0.51.0tortoise-orm==0.15.17## Improvements * Bump dependencies: * httpx-oauth >0.2,<0.3
httpx-oauth >0.2,<0.3Fix Tortoise import issue. Thanks @rnd42!
fastapi==0.48.0passlib==1.7.2 Thanks @rnd42!Add a /logout route. [Documentation]
/logout route. [Documentation]on_after_update event handler. [Documentation]sqlalchemy==1.3.13Fix on_after_register handler not being passed Request with OAuth.
on_after_register handler not being passed Request with OAuth.Event handlers have now access to the Request as parameter. [Documentation]
Request as parameter. [Documentation]fastapi==0.47.1tortoise-orm==0.15.7Arbitrary redirect URL were not used when generating the authorize URL in OAuth2 flow.
OAuth2 flow based on HTTPX OAuth. [Documentation]
Expose more options to tune the generated cookie with Cookie authentication. [Documentation]
fastapi==0.46.0Fix #83: custom fields where not output in API responses. Thanks @MariusMez!
FastAPIUsers object. [Documentation] [Documentation]abstract model and is now named TortoiseBaseUserModel. [Documentation]Fix #77: with Tortoise ORM, use a CharField as primary key instead of a TextField. Thanks @grigi!
CharField as primary key instead of a TextField. Thanks @grigi!fastapi==0.45.0tortoise==0.15.5motor==2.1.0sqlalchemy==1.3.12Multiple authentication backends. [Documentation]
fastapi==0.44.0Fix #36: fix token url in auto doc
databases==0.2.5sqlalchemy==1.3.11fastapi==0.43.0Fix #35: import error when trying to import fastapi_users.db when optional mongodb/sqlalchemy depencies are not installed. Thanks @erkandem!
fastapi_users.db when optional mongodb/sqlalchemy depencies are not installed. Thanks @erkandem!MongoDB database adapter. [Documentation]
pip install fastapi-users[sqlalchemy]. [Documentation]Define several handlers per event thanks to decorators. [Documentation]
on_after_forgot_password event handler is now declared using a decorator. [Documentation][X] Ready-to-use register, login, forgot and reset password routes.
First working version 🎉
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →