NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3584 most downloaded on PyPI
Authentication for HTTPX
Last release 2 years ago
no release in 18 months
Release timing varies
gaps range from 9 days to 11 months
Nearly every release is documented
notes for 28 of 28 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
28 releases · first in 2020
One column per quarter.
Test suite should now run even if port 5000 is used by another process. Thanks to commonism .
commonism.Bearer tokens with nested JSON string are now properly handled. Thanks to Patrick Rodrigues .
Patrick Rodrigues.httpx==0.28.*httpx_auth are now inheriting from httpx_auth.HttpxAuthException, itself inheriting from httpx.HTTPError, instead of Exception.3.13.httpx_auth.JsonTokenFileCache and httpx_auth.TokenMemoryCache get_token method does not handle kwargs anymore, the on_missing_token callable does not
httpx==0.27.*httpx_auth.JsonTokenFileCache and httpx_auth.TokenMemoryCache get_token method does not handle kwargs anymore, the on_missing_token callable does not expect any arguments anymore.Publicly expose httpx_auth.SupportMultiAuth , allowing multiple authentication support for every httpx authentication class that exists.
httpx_auth.SupportMultiAuth, allowing multiple authentication support for every httpx authentication class that exists.httpx_auth.TokenMemoryCache, allowing to create custom Oauth2 token cache based on this default implementation.success_html) and failure (failure_html) display via the new OAuth2.display shared setting. Refer to documentation for more details.redirect_uri_domain parameter on Authorization code (with and without PKCE) and Implicit flows, you can now provide the FQDN to use in the redirect_uri when localhost (the default) is not allowed.httpx_auth.testing, only direct access via httpx_auth. was considered publicly exposed. This is now explicit, as inner packages are now using private prefix (_).httpx_auth.OAuth2.display.success_display_time and failure_display_time parameters.
httpx_auth.OAuth2AuthorizationCode.httpx_auth.OktaAuthorizationCode.httpx_auth.WakaTimeAuthorizationCode.httpx_auth.OAuth2AuthorizationCodePKCE.httpx_auth.OktaAuthorizationCodePKCE.httpx_auth.OAuth2Implicit.httpx_auth.AzureActiveDirectoryImplicit.httpx_auth.AzureActiveDirectoryImplicitIdToken.httpx_auth.OktaImplicit.httpx_auth.OktaImplicitIdToken.httpx_auth.testing was modified to accommodate this change:
tab.assert_success expected_message parameter was removed.tab.assert_failure expected_message parameter should not be prefixed with Unable to properly perform authentication: anymore and \n in the message should be replaced with <br>.httpx_auth.JsonTokenFileCache does not expose tokens_path or last_save_time attributes anymore and is also allowing pathlib.Path instances as cache location.httpx_auth.TokenMemoryCache does not expose forbid_concurrent_cache_access or forbid_concurrent_missing_token_function_call attributes anymore.httpx_auth.JsonTokenFileCache and httpx_auth.TokenMemoryCache get_token method now handles a new optional parameter named on_expired_token.httpx_auth.OktaClientCredentials scope parameter is now mandatory and does not default to openid anymore.httpx_auth.OktaClientCredentials will now display a more user-friendly error message in case Okta instance is not provided.DEBUG logs will not display tokens anymore.Remove deprecation warnings due to usage of utcnow and utcfromtimestamp. Thanks to `Raphael Krupinski`.
utcnow and utcfromtimestamp. Thanks to Raphael Krupinski.httpx_auth.AWS4Auth.default_include_headers value kept growing in size every time a new httpx_auth.AWS4Auth instance was created with security_token parameter provided. Thanks to Miikka Koskinen.httpx_auth.AWS4Auth is now based almost entirely on AWS documentation, diverging from the original implementation based on requests-aws4auth and solving implementation issues in the process.
httpx_auth.AWS4Auth.default_include_headers is not available anymore, use httpx_auth.AWS4Auth include_headers parameter instead to include additional headers if the default does not fit your need (refer to documentation for an exhaustive list).httpx_auth.AWS4Auth include_headers values will not be stripped anymore, meaning that you can now include headers prefixed and/or suffixed with blank spaces.httpx_auth.AWS4Auth does not includes date header by default anymore. You will have to provide it via include_headers yourself if you need to.
httpx_auth.AWS4Auth is sending x-amz-date by default and AWS documentation states that the request date can be specified by using either the HTTP Date or the x-amz-date header. If both headers are present, x-amz-date takes precedence.httpx_auth.AWS4Auth include_headers does not needs to include host, content-type or x-amz-* anymore as those headers will always be included. It is now expected to be provided as a list of additional headers.httpx_auth.AWS4Auth will not modify the headers values spaces when computing the canonical headers, only trim leading and trailing whitespaces as per AWS documentation.Explicit support for Python 3.12
httpx==0.26.*
Python 3.8 is no longer supported.
httpx_auth.OAuth2ResourceOwnerPasswordCredentials does not send basic authentication by default.
httpx_auth.OAuth2ResourceOwnerPasswordCredentials does not send basic authentication by default.client_auth as a parameter of httpx_auth.OAuth2ResourceOwnerPasswordCredentials. Allowing to provide any kind of optional authentication.httpx_auth.OktaResourceOwnerPasswordCredentials providing Okta resource owner password credentials flow easy setup.Handle text/html; charset=utf-8 content-type in token responses. Thanks to `Marcelo Trylesinski`.
httpx==0.24.*text/html; charset=utf-8 content-type in token responses. Thanks to Marcelo Trylesinski.httpx_auth.WakaTimeAuthorizationCode handling access to the WakaTime API.Changed Requires httpx ==0.23.*
httpx==0.23.*Type information is now provided following PEP 561
mypy --strict.Python 3.6 is no longer supported.
### Changed - Requires `httpx`==0.21.\*
httpx==0.21.*OAuth2ResourceOwnerPasswordCredentials.client attribute is now set to None in case it was not provided as parameter.
httpx==0.20.*OAuth2ResourceOwnerPasswordCredentials.client attribute is now set to None in case it was not provided as parameter.OAuth2ClientCredentials.client attribute is now set to None in case it was not provided as parameter.OktaClientCredentials.client attribute is now set to None in case it was not provided as parameter.OAuth2AuthorizationCode.client attribute is now set to None in case it was not provided as parameter.OktaAuthorizationCode.client attribute is now set to None in case it was not provided as parameter.OAuth2AuthorizationCodePKCE.client attribute is now set to None in case it was not provided as parameter.OktaAuthorizationCodePKCE.client attribute is now set to None in case it was not provided as parameter.httpx.Client provided as client parameter to OAuth2ResourceOwnerPasswordCredentials is not closed anymore. You are now responsible for closing it when no more requests are expected to be issued.httpx.Client provided as client parameter to OAuth2ClientCredentials is not closed anymore. You are now responsible for closing it when no more requests are expected to be issued.httpx.Client provided as client parameter to OktaClientCredentials is not closed anymore. You are now responsible for closing it when no more requests are expected to be issued.httpx.Client provided as client parameter to OAuth2AuthorizationCode is not closed anymore. You are now responsible for closing it when no more requests are expected to be issued.httpx.Client provided as client parameter to OktaAuthorizationCode is not closed anymore. You are now responsible for closing it when no more requests are expected to be issued.httpx.Client provided as client parameter to OAuth2AuthorizationCodePKCE is not closed anymore. You are now responsible for closing it when no more requests are expected to be issued.httpx.Client provided as client parameter to OktaAuthorizationCodePKCE is not closed anymore. You are now responsible for closing it when no more requests are expected to be issued.client parameter) upon request of a new token for OAuth2ResourceOwnerPasswordCredentials flow. Re-using previously closed client was raising an issue upon token expiry.client parameter) upon request of a new token for OAuth2ClientCredentials flow. Re-using previously closed client was raising an issue upon token expiry.client parameter) upon request of a new token for OktaClientCredentials flow. Re-using previously closed client was raising an issue upon token expiry.client parameter) upon request of a new token for OAuth2AuthorizationCode flow. Re-using previously closed client was raising an issue upon token expiry.client parameter) upon request of a new token for OktaAuthorizationCode flow. Re-using previously closed client was raising an issue upon token expiry.client parameter) upon request of a new token for OAuth2AuthorizationCodePKCE flow. Re-using previously closed client was raising an issue upon token expiry.client parameter) upon request of a new token for OktaAuthorizationCodePKCE flow. Re-using previously closed client was raising an issue upon token expiry.Tild character (~) is not URL encoded anymore.
### Changed - Requires `httpx`==0.18.\*
httpx==0.18.*### Changed - Requires `httpx`==0.17.\*
httpx==0.17.*Do not expose httpx_auth.oauth2_tokens.decode_base64 function anymore as it supposed to be used internally only.
httpx_auth.oauth2_tokens.decode_base64 function anymore as it supposed to be used internally only.add_bearer_token token cache method anymore as it supposed to be used internally only.add_access_token token cache method anymore as it supposed to be used internally only.get_token cache method now requires on_missing_token function args to be provided as kwargs instead of args.get_token cache method now requires on_missing_token parameter to be provided as a non positional argument.get_token cache method now expose early_expiry parameter, defaulting to 30 seconds.httpx_auth.OAuth2ResourceOwnerPasswordCredentials contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OAuth2ClientCredentials contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OktaClientCredentials contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OAuth2AuthorizationCode contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OktaAuthorizationCode contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OAuth2AuthorizationCodePKCE contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OktaAuthorizationCodePKCE contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OAuth2Implicit contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.AzureActiveDirectoryImplicit contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.AzureActiveDirectoryImplicitIdToken contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OktaImplicit contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.httpx_auth.OktaImplicitIdToken contains a new early_expiry parameter allowing to tweak the number of seconds before actual token expiry where the token will be considered as already expired. Default to 30s.Explicit support for Python 3.9
httpx_auth.AWS4Auth authentication class.httpx==0.16.*black==20.8b1 formatting instead of the git master version.### Changed - Requires `httpx`==0.15.*
httpx==0.15.*Thanks to `Michael E. Martinka`. This class is still considered as under development and subject to breaking changes without notice.
AWSAuth authentication class now handles empty path. Thanks to Michael E. Martinka. This class is still considered as under development and subject to breaking changes without notice.AWSAuth are now private. They were never meant to be exposed anyway.Allow to provide an httpx.Client instance for *AuthorizationCode flows (even PKCE), *ClientCredentials and *ResourceOwnerPasswordCredentials flows.
httpx.Client instance for *AuthorizationCode flows (even PKCE), *ClientCredentials and *ResourceOwnerPasswordCredentials flows.Still under development, subject to breaking changes without notice: AWS4Auth authentication class for AWS. Ported from `requests-aws4auth` by `Michae…
httpx_auth.testing.token_cache_mock. Getting rid of pyjwt default dependency for testing.httpx==0.14.*AWS4Auth authentication class for AWS. Ported from requests-aws4auth by Michael E. Martinka.
Note that a few changes were made:
amz_date attribute has been removed.AWSSigningKey instance, use explicit parameters instead.date. It will default to now.raise_invalid_date parameter anymore as the date will always be valid.include_hdrs parameter was renamed into include_headershost is not considered as a specific Amazon service anymore (no test specific code).session_token was renamed into security_token for consistency with the underlying name at Amazon.### Changed - Requires `httpx`==0.13.*
httpx==0.13.*Deprecated httpx_auth.Auths class has been removed.
httpx_auth.Auths class has been removed.### Changed - Requires `httpx`==0.12.*
httpx==0.12.*Port of requests_auth 5.0.2 for httpx
Placeholder for port of requests_auth to httpx
Your coding agent can read these notes before it upgrades. Set up the MCP server →