NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1656 most downloaded on PyPI
Python social authentication made simple.
Last release 4 days ago
30 Sep 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 56 of 56 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
56 releases · first in 2016
Added a CESID AAI OpenID Connect backend.
user argument to do_auth() and a BaseAuth.prepare_auth()FACEBOOK_COMPLETE_URI when submitting the callback.One column per quarter.
VK app authentication now fetches user profiles directly from VK and verifies that the profile ID matches the signed viewer ID, preventing forged call
AuthReauthenticationRequired, a subclass of AuthTokenError, foropenid, profile, and email scopes andAuthTokenError when the token response lacks an ID token.Added a Helmholtz AAI OpenID Connect backend.
ALLOWED_REDIRECT_SCHEMES setting.AuthForbidden.LINE backend now validates callback state before exchanging authorization codes, preventing login CSRF.
Externally resumable partial request links now require confirmation even in the browser session that created the partial, preventing validation links
LoginRadius backend now validates callback state to prevent login CSRF.
five_hundred_px), legacy Google App Engine bundled Usersgae), Jawbone, Moves, Mozilla Persona, Readability Parser API, and Wunderlist.google-plus / GooglePlusAuth).GitHub backend now handles scoped email fetching deterministically.
QueryDict values.This release might contain breaking changes. Review the removed backends and stricter OAuth, OpenID Connect, and Azure AD validation before upgrading.
This release might contain breaking changes. Review the removed backends and
stricter OAuth, OpenID Connect, and Azure AD validation before upgrading.
AUTH_EXTRA_ARGUMENTS values are no longer overridden by request data unlessAUTH_EXTRA_ARGUMENTS_OVERRIDE_ALLOWLIST.sub does notOpenID Connect backends can now opt in to PKCE support
Require PyJWT >= 2.12.0 to address CVE-2026-32597
storage.UserProtocol now supports read-only attributes for better type-checker compatibilitysanitize_redirect() now handles invalid redirect values that raise ValueErrorPyJWT >= 2.12.0 to address CVE-2026-32597Fixed partial pipeline handling for unauthenticated users
This project welcomes donations to make the development sustainable. The following platforms are available for funding Python Social Auth:
Improved error handling in SAML
This project welcomes donations to make the development sustainable. The following platforms are available for funding Python Social Auth:
Added registry to configure default strategy
This project welcomes donations to make the development sustainable. The following platforms are available for funding Python Social Auth:
The timeout parameter can be again configured
ID_KEY is now configurableThis project welcomes donations to make the development sustainable. The following platforms are available for funding Python Social Auth:
Fixed extra_data() invocation from refresh_token()
extra_data() invocation from refresh_token()Fixed Gitea backend API authentication headers
RelayState and attributes handling in the SAML backend
AuthMissingParameter errorid_token when not present in the responseat_hash validation in OIDCAuthTokenErrorextra_data method of backends now receives pipeline arguments as pipeline_kwargsALLOW_INACTIVE_USERS_LOGINFixed getting user info in LinkedIn authentication.
This project welcomes donations to make the development sustainable, you can fund Python Social Auth on the following platforms:
Fixed crash in partial pipelines for some backends
This project welcomes donations to make the development sustainable, you can fund Python Social Auth on following platforms:
OAuth2 backends now default to POST method
This project welcomes donations to make the development sustainable, you can fund Python Social Auth on following platforms:
fix: revert API changes from #986 by @nijel in https://github.com/python-social-auth/social-core/pull/1020
Full Changelog: https://github.com/python-social-auth/social-core/compare/4.5.5...4.5.6
chore: drop 10 years deprecated interface by @nijel in https://github.com/python-social-auth/social-core/pull/1002
HTTPError response text by @dases in https://github.com/python-social-auth/social-core/pull/1008Full Changelog: https://github.com/python-social-auth/social-core/compare/4.5.4...4.5.5
family-name with ORCIDSOCIAL_AUTH_FORCE_EMAIL_LOWERCASE.tokens alias for access_token on UserMixin which has been deprecated for 10 years now.LinkedIn supports refresh token
uid is automatically converted to string in the pipelineuid is automatically converted to string in the pipeline### Added - OpenStreetMap OAuth2 ### Changed - Etsy backend fixes
Updated Facebook API version to 18.0
OpenID Connect skips at_hash validation when missing
at_hash validation when missingredirect_name is now passed to backend on do_completenext is preserved through SAML RelayStateID_KEY is no longer configurable (it never worked)Add backend for LinkedIn OpenID Connect
Fixed Azure AD Tenant authentication with custom signing keys
ID_KEY configurableMoved Facebook Limited Login to a separate module to avoid extra dependency
Removed OpenStackDevOpenId backend
user_data method in StripeOAuth2 to return email in get_user_detailslxmlAdd backend for Hashicorp Vault OIDC backend
Add fields that populate on create but not update SOCIAL_AUTH_IMMUTABLE_USER_FIELDS
SOCIAL_AUTH_IMMUTABLE_USER_FIELDSInstagram Legacy API has been replaced with Instagram Basic Display API since the first one was deprecated, see.
Changes:
self.dataexpires_in for Zoom backendget and delete class methods for NonceMixinself.dataexpires_in for Zoom backend### Changed - Updated PyJWT version to 2.0.0 - Remove six dependency
PyJWT version to 2.0.0six dependencyFixes to Github-action release mechanism
Directly use access_token in Azure Tenant backend
access_token in Azure Tenant backendUpdated list of default user protected fields to include admin flags and password
Updated package upload method to use twine
twineReverted PR #388 due to dependency license incompatibility
Allow ignoring of default protected user fields with option SOCIAL_AUTH_NO_DEFAULT_PROTECTED_USER_FIELDS
SOCIAL_AUTH_NO_DEFAULT_PROTECTED_USER_FIELDSunidecode to cleanup usernames from unicode characterspytest version for Python2 and Python3user_details in user pipeline to allow model attributes to be updatedReplace deprecated Google+ API usage in GoogleOpenIdConnect
hmac.compare_digest for constant time comparisonsaml_config.json is included by addint it to MANIFEST.inemail_verified as part of user details on Auth0 backendversion parameter on Shopify session setupSOCIAL_AUTH_SHOPIFY_API_VERSION setting to override default API versionid attribute existence before using itlast_name from family_name in Cognito backendAuth0.com authentication backend
user_data method in AzureADOAuth2 to return access_token if
id_token is not present in responseReplace deprecated Google+ API usage with
get_user_details to return more detailsTelegram authentication backend
state parameter instead of redirect_stateuserPrincipalName to set username and email accordinglyunitest2 with Python 3unicode_literals on Slack backendsanitize_redirect to invalidate redirects like ///evil.comurlencode from sixid_tokenUpdate EvenOnline token expiration key
httpsAuthorization headerextra_data update to use the alias as key toosigned_request optional in Facebook App OAuth2 backendparams sending on GET access-token retrieval caseextras_requrie to specify python specific version dependenciesFix coinbase backend to use api v2
REDIRECT_STATE to False in FacebookOAuth2 backend.oauth_token as request headerFix using the entire SAML2 nameid string
Fix path in import BaseOAuth2 for Monzo
redirect_state usage on Disqus backendGET_ALL_EXTRA_DATA boolean flag.Use extra_data method when refreshing an access_token, ensure that auth-time is updated then
access_token, ensure that
auth-time is updated thenget_access_token method that will refresh if expiredauthenticate methodextra_dataid_token in GooglePlusAuth's AuthMissingParameterLimit Slack by team through SOCIAL_AUTH_SLACK_TEAM setting
SOCIAL_AUTH_SLACK_TEAM settingexpires to expires_in for Facebook OAuth2 backendid fetch to default to user id if not present in responseStrategy method to let implementation cleanup arguments passed to the authenticate method
Fixed broken dependencies while building the package
Store partial pipeline data in an storage class
auth_time with the last time authentication took place, use
auth_time to determine if access token expiredtestkey.pem is distributedsave_status_to_session to partialize a pipeline runDefined extras for SAML, and "all" that will install SAML and OpenIdConnect
extras for SAML, and "all" that will install SAML and OpenIdConnectauth_time in extra data by default to store the time that the authentication took placeextras requirements defined in the setup.py scriptReorganize requirements, make OpenIdConnect optional
social-core[openidconnect]Update Google+ Auth tokeninfo API version, drop support for deprecated API scopes. Refs #791.
expires_in as expires for LinkedIn OAuth2. Refs #666SOCIAL_AUTH_USER_AGENT setting to override the default User-Agent header.
Refs #752make docker-tox)callback_uri and oauth_verifier parameters on authenticated API calls.
Refs #871Split from the monolitic python-social-auth codebase
Your coding agent can read these notes before it upgrades. Set up the MCP server →