NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #127 most downloaded on PyPI
A generic, spec-compliant, thorough implementation of the OAuth request-signing logic
Last release 7 days ago
28 Sep 2026
Release timing varies
gaps range from 2 weeks to 2.7 years
Nearly every release is documented
notes for 50 of 53 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
53 releases · first in 2012
Important : this release contains 2 breaking changes. See CHANGELOG.rst for details:
The release 4.0.0 defines the foundation that enables AI contributions and will improve the maintenance of oauthlib by using AI agents, skills, code for both contributors and maintainers. It includes devcontainer, skills and cleanup of instructions.
Important: this release contains 2 breaking changes. See CHANGELOG.rst for details:
grant_type parameter is now validated before client authentication.resource to Request._params by @juannyG in #942Full Changelog: v3.3.1...v4.0.0
One column per quarter.
OAuth2.0 Provider: * Breaking: #951: Removed JSONP support from token revocation endpoint.
JSONP has been superseded by CORS for cross-origin requests. The enable_jsonp parameter has been removed from RevocationEndpoint and the callback parameter has been removed from prepare_token_revocation_request.
Breaking: #919, #920: Fixed DeviceCodeGrant.validate_token_request trying to authenticate public clients. Client authentication validation has been reorganized and is now shared across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter is validated before client authentication, so requests missing grant_type now return 400 invalid_request instead of 401 invalid_client.
#963: Improved PKCE code comparison
Misc: * #904: Stop installing examples into site-packages. * #930: Add devcontainer, Add Python3.14, Python3.14t. * #931: Fix ruff checks about unused variables. * #932: Dropped EOL Python 3.8 from CI. * #934: Pre-commit hooks autoupdate. * #938: Fix typos discovered by typos. * Add OAuthLib Maintainer agent for automated issue/PR triage and release
management.
Stop installing examples into site-packages by @mgorny in #904
examples into site-packages by @mgorny in #904Full Changelog: v3.3.0...v3.3.1
OAuth2.0 Client: * #906: fix regression of expires_in parsing when float in string.
Use proper SPDX identifier by @Shortfinga in https://github.com/oauthlib/oauthlib/pull/836
See also CHANGELOG.md
request.client_id is set during Refresh Token Grant. by @luhn in https://github.com/oauthlib/oauthlib/pull/853Full Changelog: https://github.com/oauthlib/oauthlib/compare/v3.2.2...v3.3.0
See also CHANGELOG.md
request.client_id is set during Refresh Token Grant. by @luhn in #853Full Changelog: v3.2.2...v3.3.0
OAuth2.0 Provider: * OIDC: #879 Changed in how ui_locales is parsed * RFC8628: Added OAuth2.0 Device Authorization Grant support * PKCE: #876, #893 Fixed create_code_verifier length * OIDC: Pre-configured OIDC server to use Refresh Token by default
OAuth2.0 Common: * OAuth2Error: Allow 0 to be a valid state
OAuth2.0 Client: * #745: expires_at is forced to be an int * #899: expires_at clarification
General: * Removed Python 3.5, 3.6, 3.7 support * #859, #883: Added Python 3.12, 3.13 Support * Added dependency-review GitHub Action * Updated various references of license (SPDX identifier..) * Added GitHub Action for lint, replaced bandy with ruff, removed isort... * Migrated to GitHub Actions from Travis * Added Security Policy
## OAuth2.0 Provider: * CVE-2022-36087
Improved and fixed documentation warnings.
OAuth2.0 Provider:
OAuth1.0:
General:
Full Changelog: https://github.com/oauthlib/oauthlib/compare/v3.2.0...v3.2.1
OAuth2.0 Provider:
OAuth1.0:
General:
Full Changelog: v3.2.0...v3.2.1
@kazkansouh made their first contribution in https://github.com/oauthlib/oauthlib/pull/771
OAuth2.0 Client:
OAuth2.0 Provider:
OAuth2.0 Provider - OIDC:
refresh_id_tokentoken, token_handler, request).General:
Full Changelog: https://github.com/oauthlib/oauthlib/compare/v3.1.1...v3.2.0
OAuth2.0 Client:
OAuth2.0 Provider:
OAuth2.0 Provider - OIDC:
refresh_id_tokentoken, token_handler, request).General:
Full Changelog: v3.1.1...v3.2.0
OAuth2.0 Provider - Bugfixes * #753: Fix acceptance of valid IPv6 addresses in URI validation OAuth2.0 Client - Bugfixes * #730: Base OAuth2 Client no
OAuth2.0 Provider - Bugfixes
OAuth2.0 Client - Bugfixes
scope: it consistently
relies on the scope provided in the constructor if any, except if overridden temporarily
in a method call. Note that in particular providing a non-None scope in
prepare_authorization_request or prepare_refresh_token does not override anymore
self.scope forever, it is just used temporarily.scope provided in
constructor.scope provided in constructorOAuth2.0 Provider - Bugfixes
General
Deprecated RequestValidator.get_id_token method
3.1.0 is an feature release including improvement to OIDC and security enhancements. Check-it out !
OAuth2.0 Provider - Features
OAuth2.0 Provider - Security
OAuth2.0 Provider - Bugfixes
OAuth2.0 Client - Bugfixes
OAuth1.0 Client
OAuth2.0 Provider - Features
- #660: OIDC add support of nonce, c_hash, at_hash fields
New RequestValidator.fill_id_token method
Deprecated RequestValidator.get_id_token method
#677: OIDC add UserInfo endpoint - New RequestValidator.get_userinfo_claims method
OAuth2.0 Provider - Security
- #665: Enhance data leak to logs
New default to not expose request content in logs
New function oauthlib.set_debug(True)
#666: Disabling query parameters for POST requests
OAuth2.0 Provider - Bugfixes
#670: Fix validate_authorization_request to return the new PKCE fields
#674: Fix token_type to be case-insensitive (bearer and Bearer)
OAuth2.0 Client - Bugfixes
#290: Fix Authorization Code's errors processing
#603: BackendApplicationClient.prepare_request_body use the scope argument as intended.
#672: Fix edge case when expires_in=Null
OAuth1.0 Client
#669: Add case-insensitive headers to oauth1 BaseEndpoint
OAuth1.0
#722: Added support for HMAC-SHA512, RSA-SHA256 and RSA-SHA512 signature methods.
Bug fix release - #650: OAuth1: Fixed space encoding in base string URI used in the signature base string. - #654: OAuth2: Doc: The value state must n
Bug fix release
#650: Fixed space encoding in base string URI used in the signature base string.
#652: Fixed OIDC /token response which wrongly returned "&state=None"
#654: Doc: The value state must not be stored by the AS, only returned in /authorize response.
#656: Fixed OIDC "nonce" checks: raise errors when it's mandatory
Fix regression introduced in 3.0.0
Fix regression introduced in 3.0.0
Fix regression introduced in 3.0.0
Fixed OAuth2.0 regression introduced in 3.0.0: Revocation with Basic auth no longer possible #644
This is a major release containing API Breaking changes, and new major features. See the full list below:
This is a major release containing API Breaking changes, and new major features. See the full list below:
OAuth2.0 Provider - outstanding Features
OAuth2.0 Provider - API/Breaking Changes
OAuth2.0 Provider - Bugfixes
OAuth2.0 Client - Bugfixes / Changes:
prepare_token_request supports sending an empty string for client_id (#585)WebApplicationClient.prepare_request_body was refactored to better
support sending or omitting the client_id via a new include_client_id kwarg.
By default this is included. The method will also emit a DeprecationWarning if
a client_id parameter is submitted; the already configured self.client_id
is the preferred option. (#585)OAuth1.0 Client:
General fixes:
This minor release includes the following changes:
This minor release includes the following changes:
:tada: First oauthlib community release. :tada:
:tada: First oauthlib community release. :tada:
Fix-up release, since 2.0.5 contained breaking changes.
Fix-up release, since 2.0.5 contained breaking changes.
This was a bad release; don't use.
This was a bad release; don't use.
Fixed typo that caused OAuthlib to crash because of the fix in "Address missing OIDC errors and fix a typo in the AccountSelectionRequired exception".
Address missing OIDC errors and fix a typo in the AccountSelectionRequired exception.
Dropped support for Python 2.6, 3.2 & 3.3.
OpenIDConnector will no longer raise an AttributeError when calling openid_authorization_validator() twice.(FIX) Normalize handling of request.scopes list
Documentation improvements and fixes.
(Fix) Query strings should be able to include colons.
(Enhancement) Better sanitisation of Request objects __repr__.
__repr__.(Fix) '(', ')', '/' and '?' are now safe characters in url encoded strings.
__slots__ for smaller memory footprint.(Fix) Changed the documented return type of the invalidate_request_token() method from the RSA key to None since nobody is using the return type.
invalidate_request_token() method from the RSA key to None since nobody is using the return type.(Fix) Allow client secret to be null for public applications that do not mandate it's specification in the query parameters.
(Fix) Added token_type_hint to the list of default Request parameters.
(Breaking Change) Replace pycrypto with cryptography from https://cryptography.io
(Quick fix) Unpushed locally modified files got included in the PyPI 0.7.1 release. Doing a new clean release to address this. Please upgrade quickly
(Quick fix) Add oauthlib.common.log object back in for libraries using it.
(Change) OAuth2 clients will not raise a Warning on scope change if the environment variable OAUTHLIB_RELAX_TOKEN_SCOPE is set. The token will now be
OAUTHLIB_RELAX_TOKEN_SCOPE is set. The token
will now be available as an attribute on the error, error.token.
Token changes will now also be announced using blinker.oauthlib.(Quick fix) OAuth 1 client repr in 0.6.2 overwrote secrets when scrubbing for print.
Numerous OAuth2 provider errors now suggest a status code of 401 instead of 400 (#247).
Draft revocation endpoint features and numerous fixes including:
Draft revocation endpoint features and numerous fixes including:
OAuth 1 & 2 provider API refactor with breaking changes:
OAuth 1 & 2 provider API refactor with breaking changes:
headers, body, status code where the initial redirect_uri
has been relocated to its rightful place inside headers as Location.invalidate_request_token.oob callbacks.OAuth 1 provider fix for incorrect token param in nonce validation.
OAuth 1 provider refactor. OAuth 2 refresh token validation fix.
OAuth 1 provider refactor. OAuth 2 refresh token validation fix.
OAuth 2 draft to RFC. Removed OAuth 2 framework decorators.
OAuth 2 draft to RFC. Removed OAuth 2 framework decorators.
Documentation corrections and various small code fixes.
Documentation corrections and various small code fixes.
OAuth 2 Provider support (experimental).
OAuth 2 Provider support (experimental).
OAuth 2 Client now uses custom errors and raise on expire.
OAuth 2 Client now uses custom errors and raise on expire.
OAuth 1 optional encoding of Client.sign return values.
OAuth 1 optional encoding of Client.sign return values.
Revert default urlencoding.
Revert default urlencoding.
Default unicode conversion (utf-8) and urlencoding of input.
Default unicode conversion (utf-8) and urlencoding of input.
A number of small features and bug fixes.
A number of small features and bug fixes.
OAuth 1 Provider verify now return useful params.
OAuth 1 Provider verify now return useful params.
Fixed #62, all Python 3 tests pass.
Fixed #62, all Python 3 tests pass.
Initial OAuth 2 client support.
Initial OAuth 2 client support.
Use python-rsa instead of pycrypto.
Use python-rsa instead of pycrypto.
Fix installation of pycrypto dependency.
Fix installation of pycrypto dependency.
Nothing published for this version
OAuth 1 client functionality seems to be working. Hooray!
OAuth 1 client functionality seems to be working. Hooray!
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →