NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3229 most downloaded on PyPI
HTTP authentication for Flask routes
Last release 6 months ago
28 Mar 2026
Release timing varies
gaps range from 2 weeks to 2.9 years
Nearly every release is documented
notes for 35 of 35 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
35 releases · first in 2013
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Do not accept empty or missing tokens ( commit )
New installation section in the documentation ( commit )
Revised documentation ( commit )
Fix documentation links #163 ( commit ) (thanks Ofer Nave !)
Code modernization ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
One column per quarter.
Changes to handle breaking changes in Flask/Werkzeug 2.3 #160 ( commit )
Remove Python 3.6 and 3.7 from builds, add Python 3.11 ( commit )
Replace itsdangerous with pyjwt in examples #157 ( commit )
Better documentation for the get_user_roles callback argument #152 ( commit ) (thanks Taranjeet Singh !)
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Fallback to latin-1 encoding for credentials when utf-8 fails #151 ( commit )
Documentation updates ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Add MD5-Sess algorithm for Digest auth ( commit )
Add qop=auth option for Digest auth ( commit ) (thanks Edward !)
Add Python 3.10 and PyPy 3.8 to build ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Support for Flask 2 async views ( commit )
Do not read the request body #138 ( commit )
Remove unused flask.g import in token authentication example #137 ( commit ) (thanks Jonas Sandström !)
Fixed documentation typo #127 ( commit ) (thanks Reggie V !)
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Replace safe_str_cmp with hmac.compare_digest to avoid a deprecation warning from Werkzeug #126 ( commit ) (thanks Federico Martinez !)
Drop Python 2 support ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Support token auth with custom header in MultiAuth class #125 ( commit )
Catch UnicodeDecodeError when passing malformed data in authorization header #122 ( commit ) (thanks Bastian Raschke !)
Fixes typo #116 ( commit ) (thanks Renato Oliveira !)
Move builds to GitHub actions ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Allow error response to return a 200 status code #114 ( commit )
Add optional argument to MultiAuth class #115 ( commit ) (thanks pryankster and Michael Wright !)
Remove python 3.5 and add python 3.9 to build ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Return user object from verify callbacks ( commit )
New role authorization support ( commit ) (thanks gemerden !)
Add a custom token authorization header option ( commit ) (thanks Mohamed Feddad !)
Support an optional=True argument in login_required decorator ( commit ) (thanks Saif Almansoori !)
Pass HTTP status code to error callback ( commit )
More secure example of basic auth in the documentation ( commit )
Fix broken links in CHANGES.md and changelog template #85 ( commit ) (thanks Katie Smith !)
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Use constant time string comparisons #82 ( commit1 , commit2 ) (thanks Brendan Long !)
Edited and changed the usage of JWT, because in fact the code and documentation uses JWS tokens. #79 ( commit ) (thanks unuseless !)
Documentation fix #78 ( commit )
Documentation improvements #77 ( commit )
helper release script ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Refactored HTTPAuth login_required #74 ( commit ) (thanks nestedsoftware !)
remove incorrect references to JWT in example application #69 ( commit )
Fix typo in docs #70 ( commit ) (thanks Grey Li !)
Fix documentation #67 ( commit ) (thanks Eugene Rymarev !)
correct spelling mistake #56 ( commit ) (thanks Edward Betts !)
travis build fix for py36 ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Validate authorization header in multi auth #51 ( commit )
index.rst: Add a missing variable in a code snippet #49 ( commit ) (thanks Baptiste Fontaine !)
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
add version to package ( commit )
Add readme and license files to the built package #45 ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
pass params to view function in MultiAuth #36 ( commit ) (thanks vovanz !)
add examples to flake8 build ( commit )
Added multi auth tests ( commit )
removed dead code ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
examples ( commit )
Added support for multiple authentication methods ( commit )
Added change log ( commit )
Add additional token auth test ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Catching exception when Authorization header is empty ( commit ) (thanks Kari Hreinsson !)
Documentation fix, validate_token() -> verify_token() ( commit ) (thanks Kari Hreinsson !)
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
documentation for new token auth ( commit )
switch travis build to use tox ( commit )
token auth support, plus test reorg ( commit )
Added explicity Python 2 & 3 version classifiers to package ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Remove session dependency in authenticate_header #31 ( commit ) (thanks Paweł Stiasny !)
Add Install Notes ( commit ) (thanks Michael Washburn Jr !)
Add syntax highlighting to the README #28 ( commit ) (thanks Josh Friend !)
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Added information on how to implement digest authentication securely ( commit )
Allow for custom nonce/opaque generation #24 ( commit ) (thanks Matt Haggard !)
fixed tests to work with python 2.6 ( commit )
added travis ci badge ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
documentation changes ( commit )
documentation for stored ha1 feature ( commit )
Include notes for nginx ( commit ) (thanks Erik Stephens !)
Include notes for nginx as well ( commit ) (thanks Erik Stephens !)
Update docs with WSGI notes ( commit ) (thanks Erik Stephens !)
Update README with WSGI notes ( commit ) (thanks Erik Stephens !)
Modified documents and readme for correct import statement #19 ( commit ) (thanks Aayush Kasurde !)
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Support anonymous users in verify_password callback ( commit )
Add HA1 generation function to HTTPDigestAuth class ( commit ) (thanks Pawel Szczurko !)
Fix unit test url routes ( commit ) (thanks Pawel Szczurko !)
Add option to use ha1 combination as password instead of plain text password ( commit ) (thanks Pawel Szczurko !)
removed extra strip() calls in unit tests ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
pep8 ( commit )
Fixed problem with couple of decorator that destroy function they decorate #11 ( commit ) (thanks Nemanja Trifunovic !)
Ignore authentication headers for OPTIONS ( commit ) (thanks Henrique Carvalho Alves !)
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
#5 : correct handling of None return from get_password callback ( commit )
#5 ( commit )
Fixed problem when get_password decorator destroys function it decorates #4 ( commit ) (thanks Nemanja Trifunovic !)
custom password verification callback ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
changed auth.username to auth.username() ( commit )
2.0 documentation update ( commit )
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
See CHANGE.LOG for release notes.
Your coding agent can read these notes before it upgrades. Set up the MCP server →