NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3371 most downloaded on PyPI
A high performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar.
Last release 5 days ago
29 Sep 2026
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 38 of 38 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
38 releases · first in 2022
One column per quarter.
apply per-request min_wait_in_ms to wait, not max_retry ( #320 ) ( c190a4f ), closes #319
Full Changelog: v0.10.4...v0.10.5
add support for Python 3.13 and 3.14
Full Changelog: v0.10.3...v0.10.4
add token expiry buffer to prevent expired token usage and lock concurrent refreshes
Full Changelog: v0.10.2...v0.10.3
oauth2 scopes for authentication
Full Changelog: v0.10.1...v0.10.2
stop destroying connection pool after every sync request
Full Changelog: v0.10.0...v0.10.1
feat: add execute_api_request and execute_streamed_api_request methods to OpenFgaClient and OpenFgaApi for making arbitrary HTTP requests to any OpenF
execute_api_request and execute_streamed_api_request methods to OpenFgaClient and OpenFgaApi for making arbitrary HTTP requests to any OpenFGA API endpoint with full auth, retry, and telemetry support (#252) - thanks @kcbiradar_return_http_data_only, _preload_content, _request_auth, async_req, and _request_timeout kwargs have been removed from all OpenFgaApi and SyncOpenFgaApi endpoint methods. These were internal implementation details not intended for external use. _return_http_data_only is now hardcoded to True; all endpoint methods return the deserialized response object directly. Users relying on _with_http_info methods returning a (data, status, headers) tuple should use execute_api_request instead.Full Changelog: v0.9.9...v0.10.0
feat: improve error messaging by @SoulPancake in #245
Full Changelog: v0.9.8...v0.9.9
feat: add support for conflict options for Write operations: ( #235 ) The client now supports setting ConflictOptions on ClientWriteOptions to control
ConflictOptions on ClientWriteOptions to control behavior when writing duplicate tuples or deleting non-existent tuples. This feature requires OpenFGA server v1.10.0 or later.on_duplicate for handling duplicate tuple writes (ERROR or IGNORE)on_missing for handling deletes of non-existent tuples (ERROR or IGNORE)Full Changelog: v0.9.7...v0.9.8
feat: headers configuration property
Full Changelog: v0.9.6...v0.9.7
fix: reuse ssl context in the sync client ( #222 ) - thanks @wadells !
Full Changelog: v0.9.5...v0.9.6
fix: aiohttp.ClientResponse.data should be awaited (#197) - thanks @cmbernard333
feat: support List Stores name filter
Retry-After) returned by the server and will retry the request after the specified time.
If the header is not sent or on network errors, it will fall back to exponential backoff.fix: urllib3 compatibility < v2
fix(telemetry): fixes for telemetry attributes and metrics tracking
stream request (#172)feat: add /streamed-list-objects endpoint support
/streamed-list-objects endpoint support (#163)contextual_tuples support for /expand endpoint requests (#164)feat: remove client-side validation - thanks @GMorris-professional
start_time parameter in ReadChanges endpoint (#156) - Note, this feature requires v1.8.0 of OpenFGA or newerBatchCheck API (#154) - Note, this feature requires v1.8.2 of OpenFGA or newerBREAKING CHANGE:
Usage of the existing batch_check should now use client_batch_check instead, additionally the existing BatchCheckResponse has been renamed to ClientBatchCheckClientResponse.
Please see (#154)(https://github.com/openfga/python-sdk/pull/154) for more details on this change.
feat: allow specifying a request timeout (#151) - thanks @Oscmage!
feat: allow configuring the token endpoint
retry_params (#144)read_latest_authorization_model (#147)This release includes improvements to the OpenTelemetry configuration API introduced in the previous releases
This release includes improvements to the OpenTelemetry configuration API introduced in the previous releases
This release also includes fixes for several bugs identified in previous releases:
This release includes fixes for several bugs identified in the previous release related to OpenTelemetry metrics reporting:
This release includes fixes for several bugs identified in the previous release related to OpenTelemetry metrics reporting: (#124)
http_client_request_duration being reported in seconds rather than the intended millisecondsqueryDuration() and requestDuration()queryDuration() and requestDuration() may not have updated their histograms reliably when attr_http_client_request_duration or attr_http_server_request_duration (respectively) were not enabled (which is the default)Please note that if you use third-party OpenTelemetry tooling to visualize the attributes mentioned above, you may need to update your queries to account for these changes.
Note this introduces some breaking changes to our metrics:
Note this introduces some breaking changes to our metrics:
fga-client.request.method is now in TitleCase to match the naming conventions in the Protos, e.g. Check, ListObjects, etc..fga-client.userhttp.client.request.durationhttp.server.request.duration
We added configuration options to allow you to set which specific metrics and attributes you care about in case the defaults don't work for your use-casefeat: add support for specifying consistency when evaluating or reading (#129) Note: To use this feature, you need to be running OpenFGA v1.5.7+ with
feat: add support for specifying consistency when evaluating or reading (#129)
Note: To use this feature, you need to be running OpenFGA v1.5.7+ with the experimental flag
enable-consistency-params enabled. See the v1.5.7 release notes for details.
feat: add OpenTelemetry metrics reporting
feat: add OpenTelemetry metrics reporting
fix: ClientTuple condition property type
- feat: support for list users ## v0.4.2
feat: support for modular models metadata
api_scheme, min_wait_in_ms and disabled_client_side_validations validation issuesfeat: support api_url configuration option and deprecate api_scheme and api_host
api_url configuration option and deprecate api_scheme and api_hostBREAKING CHANGES: Note: This release comes with substantial breaking changes, especially to the interfaces due to the protobuf changes in the last rel…
BREAKING CHANGES: Note: This release comes with substantial breaking changes, especially to the interfaces due to the protobuf changes in the last release.
While the http interfaces did not break (you can still use v0.3.3 SDK with a v1.3.8+ server),
the grpc interface did and this caused a few changes in the interfaces of the SDK.
If you are using OpenFgaClient, the changes required should be smaller, if you are using OpenFgaApi a bit more changes will be needed.
You will have to modify some parts of your code, but we hope this will be to the better as a lot of the parameters are now correctly marked as required, and so the Pointer-to-String conversion is no longer needed.
Some of the changes to expect:
CheckRequest: the TupleKey field is now of interface CheckRequestTupleKey, you can also now pass in ContextExpandRequest: the TupleKey field is now of interface ExpandRequestTupleKeyReadRequest: the TupleKey field is now of interface ReadRequestTupleKeyWriteRequest: now takes WriteRequestWrites and WriteRequestDeletes, the latter of which accepts TupleKeyWithoutConditionCreateStoreResponseGetStoreResponseListStoresResponseListObjectsResponseReadChangesResponseReadResponseAuthorizationModelTake a look at the changes in models in https://github.com/openfga/python-sdk/commit/9ed1f70d64db71451de2eb26e330bbd511625c5c and https://github.com/openfga/python-sdk/pull/59/files for more.
Note: v0.3.4 has been re-released as v0.4.0 due to breaking changes
Note: v0.3.4 has been re-released as v0.4.0 due to breaking changes
fix: correct type hints for list_relations
feat: allow passing ssl certs to client configuration
chore(deps): reduce min urllib3 to 1.25.11, add dependabot & bump deps
feat(client): introduce synchronous OpenFgaClient
fix(client): fix a crash when calling check with contextual tuples
[BREAKING] feat!: schema_version is now required when calling write_authorization_model
Changes:
schema_version is now required when calling write_authorization_modelv0.1.1 docs for the OpenFgaApi docsbatch_check to check multiple tuples in parallellist_relations to check in one call whether a user has multiple relations to an objectswrite15chore(deps): upgrade dependencies
Updated to include support for OpenFGA 0.3.0
Updated to include support for OpenFGA 0.3.0
Changes:
{"object_ids":["roadmap"]}, will now be {"objects":["document:0192ab2a-d83f-756d-9397-c5ed9f3cb69a"]}Fixes:
Initial OpenFGA Python SDK release
Initial OpenFGA Python SDK release
Your coding agent can read these notes before it upgrades. Set up the MCP server →