NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4882 most downloaded on PyPI
Stytch python client
Last release 3 months ago
24 Jun 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
203 releases · first in 2020
One column per quarter.
# New Features * Added GetMember endpoint
Added support for B2B Passwords
Added name, trusted_metadata, & untrusted_metadata to /v1/passwords and /v1/passwords/migrate.
name, trusted_metadata, & untrusted_metadata to /v1/passwords and /v1/passwords/migrate.Add B2B endpoints by @logan-stytch in https://github.com/stytchauth/stytch-python/pull/117
Full Changelog: https://github.com/stytchauth/stytch-python/compare/v6.3.2...v6.4.0
Added new fields to the StrengthCheckResponse as part of introducing alternate configurable password strength policies. If you would like to update yo
StrengthCheckResponse as part of introducing alternate configurable password strength policies. If you would like to update your password strength policy, please reach out to support[minor] Added a convenience property for oauth.authenticate to get directly to the inner StytchSession if it exists
oauth.authenticate to get directly to the inner StytchSession if it existsAdds signup_template_id and login_template_id parameters to:
signup_template_id and login_template_id parameters to:
invite_template_id to magic link invitereset_password_template_id to reset password startAdded missing token field from magic_links.create response object
token field from magic_links.create response objectAdd missing fields from sessions/authenticate response
session_jwt: str, session_token: str, and user: Optional[User]Request arguments of Name and SearchQuery can now be given as simple dict objects instead of typed pydantic models. This reflects the behavior of the
Name and SearchQuery can now be given as simple dict objects instead of typed pydantic models. This reflects the behavior of the library prior to 6.0, so should make upgrading to stytch>=6.2 easier for those currently on stytch==5.X. If you are already using typed objects, nothing needs to change in how you use the API methods.Users Get was not returning the full User object; this has been resolved and client.users.get now returns the full User object.
client.users.get now returns the full User object.Bugfix for bad definition for response type of OAuth/authenticate. Removed AuthenticationFactor since the returned value can be a mapping from assorte
Dict[str, Any] instead of a concrete typed objectUpdated an inaccurate comment in ResponseBase
Upgrading from 6.0.1 should be seamless, with no breaking changes
…callsites for compatibility. There are two major breaking changes:
*_async variantpydantic instead of raw JSON responseclient.users.get(…) would return a stytch.models.users.GetResponse
*Response models, so the same is true for await client.users.get_async(...)StytchError (you should always use a try/except block when calling the API)StytchError
requests.JSONDecodeErrorThis is a major update to the stytch-python library, so you should carefully check all existing callsites for compatibility. There are two major breaking changes:
resp["user_id"], you may use something like resp.user_idName and SearchQuery are typed objects now and should be used with relevant API endpoints instead of manually constructing mixed-type Dict[str, Any] objects3.7Name or SearchQuery parameters, upgrade those to instead use the typed models from stytch.core.models…callsites for compatibility. There are two major breaking changes:
WARNING: This version was yanked due to a missing requirement. Please upgrade to v6.0.1.
*_async variantpydantic instead of raw JSON responseclient.users.get(…) would return a stytch.models.users.GetResponse
*Response models, so the same is true for await client.users.get_async(...)StytchError (you should always use a try/except block when calling the API)StytchError
requests.JSONDecodeErrorThis is a major update to the stytch-python library, so you should carefully check all existing callsites for compatibility. There are two major breaking changes:
resp["user_id"], you may use something like resp.user_idName and SearchQuery are typed objects now and should be used with relevant API endpoints instead of manually constructing mixed-type Dict[str, Any] objects3.7Name or SearchQuery parameters, upgrade those to instead use the typed models from stytch.core.modelsAdd support for OAuth Attach endpoint
Adds support for the optional locale parameter to the magic_links.email.send, magic_links.email.login_or_create, and magic_links.email.invite methods.
locale parameter to the magic_links.email.send, magic_links.email.login_or_create, and magic_links.email.invite methods. The locale parameter sets the email copy language that will be sent to the user.User metadata can now be added using the create and update user endpoints. User responses now include any added metadata. See docs for more details.
OAuth authenticate as well as API responses that return the full user now come with an oauth_user_registration_id that can be used to call the new del
oauth_user_registration_id that can be used to call the new delete endpoint - see docs for details.Adds user_id, session_token, and session_jwt parameters to MagicLink email send, OTP email/sms/whatsapp send endpoints to be able to attach the email/
Expand typing-extensions requirement to include v4
Restore support for Python <3.8
Added support for DeleteUserBiometricRegistration endpoint
Summarize the release, if it's useful to tl;dr it.
Summarize the release, if it's useful to tl;dr it.
locale to passwords.email.reset_startAdds various password hash formats to password migrate
Added support for our new /v1/passwords/existing_password/reset endpoint. Read more here
/v1/passwords/existing_password/reset endpoint. Read more hereWe now support the Argon2 hash type for migrating passwords
Removed login_expiration_minutes from the PasswordsEmailResetStart endpoint
login_expiration_minutes from the PasswordsEmailResetStart endpointAdding support for our Password product
Add custom claim support. Custom claims will not be visible on the session object until the product is officially released
Add custom claim support. Custom claims will not be visible on the session object until the product is officially released
Add support for PKCE to OAuth and Email Magic Link flows.
Add support for PKCE to OAuth and Email Magic Link flows.
A client can now be created with a custom URL base as the env value to allow use within Stytch's internal development environments. If your app runs o
env value to allow use within Stytch's internal development environments. If your app runs on Stytch's production environments (Live or Test) using 'live' or 'test', the correct base URL is already set for you, and you shouldn't need to use this feature.When determining the session's expiration time from a JWT, prefer the session's expires_at value over the "exp" claim.
expires_at value over the "exp" claim.client.sessions.authenticate_jwt now does remote verification in response to any JWT error.
client.sessions.authenticate_jwt now does remote verification in response to any JWT error.Nothing published for this version
add new methods search and search_all to users. search wraps the Search User endpoint and search_all is a helper method which creates a generator to i
search and search_all to users. search wraps the Search User endpoint and search_all is a helper method which creates a generator to iterate through a paginated search query.Add locale support for Email OTP endpoints
locale support for Email OTP endpointsThe API has support for IdP and Stytch sessions at the same time from the OAuthAuthenticate endpoint. The IdP session is always returned, and a Stytch
session_duration_minutes field.session_management_type field is removed from the OAuth authenticate method, and the response is has changed. The new response can be found at https://stytch.com/docs/api/oauth-authenticate.All authenticate request methods now accept session_jwt.
authenticate request methods now accept session_jwt.client.sessions.authenticate_jwt method for parsing and verifying a session JWT. It will automatically fall back to calling the Stytch API if the JWT can't be verified locally.client.sessions.jwks can fetch it on-demand.Correct some internal mypy errors.
# New Features * Add support for locale
localeAdding support for the soon to be released Crypto Wallet product. See more here.
Support sessions for TOTP recovery codes
New Features
Magic Link URLs are now optional. If not passed, your default url for that type (login, signup, or invite) will be used.
Magic Link URLs are now optional. If not passed, your default url for that type (login, signup, or invite) will be used.
- Added the new TOTP endpoints
Added the new WebAuthn endpoints
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Version 4.0.1: Note that this release has breaking changes with regards to client namespacing
Version 4.0.1: Note that this release has breaking changes with regards to client namespacing
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →