NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #5071 most downloaded on PyPI
OpenID Connect extension for Flask
Last release 1 years ago
16 Jun 2025
Ships unpredictably
gaps range from 3 weeks to 5.4 years
Some releases are documented
notes for 12 of 24 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
24 releases · first in 2014
Switch to the non-deprecated Packit job type
One column per quarter.
Added a setting to disable OIDC authentication for testing and dev
Re-add redirect_to_auth_server() for compatibility with v1.x
redirect_to_auth_server() for compatibility with v1.x (d0cac91)Add an accessor for the user's email
Add a user model to flask.g with convenience properties
Avoid redirect loops when the app is not mounted on the webserver root
Handle token expiration when there is no refresh_token or no token URL
refresh_token or no token URL (#39)OVERWRITE_REDIRECT_URI configuration option as OIDC_OVERWRITE_REDIRECT_URI.redirect_uri that is generated and sent to the ID provider is no longer forced to HTTPS, because the the OIDC spec is actually only a strong recommendation (#35). You can use OIDC_OVERWRITE_REDIRECT_URI if you want to force it to HTTPS (or any other URL).Changelog: https://github.com/fedora-infra/flask-oidc/blob/develop/docs/changelog.rst#203-2023-09-08
This is a bugfix release.
Changelog: https://github.com/fedora-infra/flask-oidc/blob/develop/docs/changelog.rst#203-2023-09-08
OIDC_CALLBACK_ROUTE with the ID provider when it is defined,
instead of the default (#21)redirect_uri that is generated and sent to the ID provider is always
HTTPS, as the OIDC spec
mandates.profile scope by default, as version 1.x used to do
(#21).Changelog: https://github.com/fedora-infra/flask-oidc/blob/develop/docs/changelog.rst#202-2023-08-23
This is a bugfix release.
Changelog: https://github.com/fedora-infra/flask-oidc/blob/develop/docs/changelog.rst#202-2023-08-23
OIDC_USERINFO_URL (and the userinfo_uri key in
client_secrets) (#15).Changelog: https://github.com/fedora-infra/flask-oidc/blob/develop/docs/changelog.rst#201-2023-08-22
This is a bugfix release.
Changelog: https://github.com/fedora-infra/flask-oidc/blob/develop/docs/changelog.rst#201-2023-08-22
This is a bugfix release.
client_secrets don't contain a userinfo_uri key (#13).This is a major release that rebases the Flask OIDC API on Authlib
This is a major release that rebases the Flask OIDC API on Authlib
Changelog: https://github.com/fedora-infra/flask-oidc/blob/develop/docs/changelog.rst#200-2023-08-21
This is a major release that rebases the Flask OIDC API on Authlib.
Custom callback with the OpenIDConnect.custom_callback() decorator
Registration has been moved to the oidc-register package
Configuration option OIDC_GOOGLE_APPS_DOMAIN
Configuration option OIDC_VALID_ISSUERS
Configuration option OIDC_REQUIRE_VERIFIED_EMAIL
Configuration option OIDC_RESOURCE_CHECK_AUD
The following parameters of the OpenIDConnect constructor have been
removed:
credentials_storehttptimeurandomConfiguration option OIDC_OPENID_REALM
Configuration option OIDC_CALLBACK_ROUTE
Configuration option OVERWRITE_REDIRECT_URI
The following configuration options have been removed because the functionality is now handled by Authlib:
OIDC_ID_TOKEN_COOKIE_NAMEOIDC_ID_TOKEN_COOKIE_PATHOIDC_ID_TOKEN_COOKIE_TTLOIDC_COOKIE_SECUREThe OpenIDConnect.user_getinfo() and OpenIDConnect.user_getfield()
methods are deprecated, you'll find all the user information in the
session: session["oidc_auth_profile"].
If you need to get the user information using a specific token, you can
do so by calling g._oidc_auth.userinfo(token=token).
The OpenIDConnect.logout() method is deprecated, just redirect to the
/logout view.
The callback route (aka "redirect URL") is not configurable with
OIDC_CALLBACK_ROUTE anymore. It is always /authorize, but a prefix can
be configured when instanciating the OpenIDConnect extension (or calling
its OpenIDConnect.init_app() method:
app = Flask(__name__)
openid = OpenIDConnect(app, prefix="/oidc")
# The OIDC redirect URL will be /oidc/authorize
This will also give you /login and /logout views, prefixed identically.
The OIDC_SCOPES configuration value should now be a string, where the
scopes are separated with spaces.
The minimum Python version is 3.8.
The OpenIDConnect.accept_token() decorator now accepts a scopes parameter,
which is a list of scopes that the provided token must include for the view to
be authorized. It is an Authlib
ResourceProtector.
The Authlib app is available in the g._oidc_auth variable. This means that
there cannot be more than one OpenIDConnect extension on a given Flask
application. If you need more, we advise you to use Authlib directly.
pre-commit installNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →