NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #71 most downloaded on PyPI
Google Authentication Library
Last release 2 days ago
30 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 59 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
10 years old
204 releases · first in 2016
Raise a helpful exception when trying to refresh credentials without a refresh token.
Added a check for the cryptography version before attempting to use it.
One column per quarter.
Added cryptography-based RSA signer and verifier.
Added google.oauth2.credentials.Credentials.from_authorized_user_file
google.oauth2.credentials.Credentials.from_authorized_user_file (#226)pyasn1-modules specify the right version. (#230)default() now checks for the project ID environment var before warning about missing project ID. (#227)has_scopes() and with_scopes(). (#228)ReadOnlyScoped. (#219)transport.requests use timeouts and retries to improve reliability. (#220)Excluded compiled Python files in source distributions.
Added google.auth.credentials.AnonymousCredentials.
google.oauth.credentials.Credentials now correctly inherits from ReadOnlyScoped instead of Scoped.
google.oauth.credentials.Credentials now correctly inherits from ReadOnlyScoped instead of Scoped. (#200)Added service_account.Credentials.project_id.
service_account.Credentials.project_id. (#187)credentials.Scoped into new interface credentials.ReadOnlyScoped. (#195, #196)compute_engine.Credentials derive from ReadOnlyScoped instead of Scoped. (#195)crypt module into a package to allow alternative implementations. (#189)GOOGLE_APPLICATION_CREDENTIALS (#188)Added documentation around the oauth2client deprecation.
Fixed a bug in the clock skew accommodation logic where expired credentials could be used for up to 5 minutes.
Milestone release for v1.0.0. No significant changes since v0.10.0
Milestone release for v1.0.0. No significant changes since v0.10.0
Added new public property id_token to oauth2.credentials.Credentials.
jwt.OnDemandCredentials. (#142)id_token to oauth2.credentials.Credentials. (#150)GCE_METADATA_ROOT and GCE_METADATA_IP environment variables. (#148)Added service_account.Credentials.with_claims.
service_account.Credentials.with_claims. (#140)google.auth.oauthlib and google.auth.flow to a new separate package google_auth_oauthlib. (#137, #139, #135, #126)InstalledAppFlow to google_auth_oauthlib. (#128)google.oauth2.credentials.Credentials public. (#124)jwt.Credentials.from_signing_credentials and removed service_account.Credentials.to_jwt_credentials. (#120)Removed one-time token behavior from jwt.Credentials, audience claim is now required and fixed.
jwt.Credentials, audience claim is now required and fixed. (#117)crypt.Signer and crypt.Verifier are now abstract base classes. The concrete implementations have been renamed to crypt.RSASigner and crypt.RSAVerifier. app_engine.Signer and iam.Signer now inherit from crypt.Signer. (#115)transport.grpc now correctly calls Credentials.before_request. (#116)Fixed issue where google.auth.app_engine.Signer erroneously returns a tuple from sign().
Added experimental integration with requests-oauthlib in google.oauth2.oauthlib and google.oauth2.flow. (#100, #105, #106)
Added crypt.Signer.from_service_account_file.
transports.grpc.secure_authorized_channel now passes kwargs to grpc.secure_channel.
Fixed an issue where an ImportError would occur if google.oauth2 was imported before google.auth.
ImportError would occur if google.oauth2 was imported before google.auth. (#88)Fixed a bug where non-padded base64 encoded strings were not accepted.
Added Google ID token verification helpers.
target and request argument order for grpc.secure_authorized_channel. (#81)service_account_email a public property on several credential classes. (#76)scope argument to google.auth.default. (#75)GCLOUD_PROJECT environment variable. (#73)Added google.auth.credentials.with_scopes_if_required helper.
google/cloud/workloadidentity/v1: add google-cloud-workloadiden…
First release with core functionality available. This version is ready for initial usage and testing.
google.auth.credentials, public interfaces for Credential types. (#8)google.oauth2.credentials, credentials that use OAuth 2.0 access and refresh tokens (#24)google.oauth2.service_account, credentials that use Service Account private keys to obtain OAuth 2.0 access tokens. (#25)google.auth.compute_engine, credentials that use the Compute Engine metadata service to obtain OAuth 2.0 access tokens. (#22)google.auth.jwt.Credentials, credentials that use a JWT as a bearer token.google.auth.app_engine, credentials that use the Google App Engine App Identity service to obtain OAuth 2.0 access tokens. (#46)google.auth.default(), an implementation of Google Application Default Credentials that supports automatic Project ID detection. (#32)google.auth.transports.urllib3.AuthorizedHttp, an HTTP client that includes authentication provided by credentials. (#19)Initial release with foundational functionality for cryptography and JWTs.
Initial release with foundational functionality for cryptography and JWTs.
google.auth.crypt for creating and verifying cryptographic signatures.google.auth.jwt for creating (encoding) and verifying (decoding) JSON Web tokens.Your coding agent can read these notes before it upgrades. Set up the MCP server →