NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2628 most downloaded on PyPI
Declarative parsing and validation of HTTP request objects, with built-in support for popular web frameworks, including Flask, Django, Bottle, Tornado, Pyramid, Falcon, and aiohttp.
Last release 10 months ago
29 Oct 2025
Ships fairly regularly
a new release about every 6 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
104 releases · first in 2014
Fix parsing multiple arguments in AIOHTTParser (165). Thanks ariddell for reporting and thanks zaro for reporting.
Bug fixes:
Fix parsing multiple arguments in AIOHTTParser (165). Thanks ariddell for reporting and thanks zaro for reporting.
Fix form parsing in aiohttp>=2.0.0. Thanks DmitriyS for the PR.
Bug fixes:
Fix form parsing in aiohttp>=2.0.0. Thanks DmitriyS for the PR.
One column per quarter.
Fix compatibility with marshmallow 3.x.
Bug fixes:
Fix compatibility with marshmallow 3.x.
Other changes:
Drop support for Python 2.6 and 3.3.
Support marshmallow>=2.7.0.
Port fix from release 1.5.2 to AsyncParser. This fixes 146 for AIOHTTPParser.
Bug fixes:
Port fix from release 1.5.2 to AsyncParser. This fixes 146 for AIOHTTPParser.
Handle invalid types passed to DelimitedList (149). Thanks psconnect-dev for reporting.
Don't add marshmallow.missing to original_data when using marshmallow.validates_schema(pass_original=True) (146). Thanks lafrech for reporting and for
Bug fixes:
Don't add marshmallow.missing to original_data when using marshmallow.validates_schema(pass_original=True) (146). Thanks lafrech for reporting and for the fix.
Other changes:
Test against Python 3.6.
Fix handling missing nested args when many=True (120, 145). Thanks chavz and Bangertm for reporting.
Bug fixes:
Fix handling missing nested args when many=True (120, 145). Thanks chavz and Bangertm for reporting.
Fix behavior of load_from in AIOHTTPParser.
The use_args and use_kwargs decorators add a reference to the undecorated function via the __wrapped__ attribute. This is useful for unit-testing purp
Features:
The use_args and use_kwargs decorators add a reference to the undecorated function via the __wrapped__ attribute. This is useful for unit-testing purposes (144). Thanks EFF for the PR.
Bug fixes:
If load_from is specified on a field, first check the field name before checking load_from (118). Thanks jasonab for reporting.
when using Flask-RESTful) (122). Thanks frol for the catch and patch. NOTE: Though this is a bugfix, this is a potentially breaking change for code th…
Bug fixes:
Prevent error when rendering validation errors to JSON in Flask (e.g. when using Flask-RESTful) (122). Thanks frol for the catch and patch. NOTE: Though this is a bugfix, this is a potentially breaking change for code that needs to access the original ValidationError object.
# Before
@app.errorhandler(422)
def handle_validation_error(err):
return jsonify({"errors": err.messages}), 422
# After
@app.errorhandler(422)
def handle_validation_error(err):
# The marshmallow.ValidationError is available on err.exc
return jsonify({"errors": err.exc.messages}), 422
Fix bug in parsing form in Falcon>=1.0.
Bug fixes:
Fix bug in parsing form in Falcon>=1.0.
Fix behavior for nullable List fields (107). Thanks shaicantor for reporting.
Bug fixes:
Fix behavior for nullable List fields (107). Thanks shaicantor for reporting.
Fix passing a schema factory to use_kwargs (103). Thanks ksesong for reporting.
Bug fixes:
Fix passing a schema factory to use_kwargs (103). Thanks ksesong for reporting.
Fix memory leak when calling parser.parse with a dict in a view (101). Thanks frankslaughter for reporting.
Bug fixes:
Fix memory leak when calling parser.parse with a dict in a view (101). Thanks frankslaughter for reporting.
aiohttpparser: Fix bug in handling bulk-type arguments.
Support:
Massive refactor of tests (98).
Docs: Fix incorrect use_args example in Tornado section (100). Thanks frankslaughter for reporting.
Docs: Add "Mixing Locations" section (90). Thanks tuukkamustonen.
Add bulk-type arguments support for JSON parsing by passing many=True to a Schema (81). Thanks frol.
Features:
Add bulk-type arguments support for JSON parsing by passing many=True to a Schema (81). Thanks frol.
Bug fixes:
Fix JSON parsing in Flask<=0.9.0. Thanks brettdh for the PR.
Fix behavior of status_code argument to ValidationError (85). This requires marshmallow>=2.7.0. Thanks ParthGandhi for reporting.
Support:
Docs: Add "Custom Fields" section with example of using a Function field (94). Thanks brettdh for the suggestion.
Add view_args request location to FlaskParser (82). Thanks oreza for the suggestion.
Features:
Add view_args request location to FlaskParser (82). Thanks oreza for the suggestion.
Bug fixes:
Use the value of load_from as the key for error messages when it is provided (83). Thanks immerrr for the catch and patch.
aiohttpparser: Fix bug that raised a JSONDecodeError raised when parsing non-JSON requests using default locations (80). Thanks leonidumanskiy for rep
Bug fixes:
aiohttpparser: Fix bug that raised a JSONDecodeError raised when parsing non-JSON requests using default locations (80). Thanks leonidumanskiy for reporting.
Fix parsing JSON requests that have a vendor media type, e.g. application/vnd.api+json.
Parser.parse, Parser.use_args and Parser.use_kwargs can take a Schema factory as the first argument (73). Thanks DamianHeard for the suggestion and th
Features:
Parser.parse, Parser.use_args and Parser.use_kwargs can take a Schema factory as the first argument (73). Thanks DamianHeard for the suggestion and the PR.
Support:
Docs: Add "Custom Parsers" section with example of parsing nested querystring arguments (74). Thanks dwieeb.
Docs: Add "Advanced Usage" page.
Add webargs.async module with AsyncParser.
Features:
Add AIOHTTPParser (71).
Add webargs.async module with AsyncParser.
Bug fixes:
If an empty list is passed to a List argument, it will be parsed as an empty list rather than being excluded from the parsed arguments dict (70). Thanks mTatcher for catching this.
Other changes:
Backwards-incompatible: When decorating resource methods with FalconParser.use_args, the parsed arguments dictionary will be positioned after the request and response arguments.
Backwards-incompatible: When decorating views with DjangoParser.use_args, the parsed arguments dictionary will be positioned after the request argument.
Backwards-incompatible: Parser.get_request_from_view_args gets passed a view function as its first argument.
Backwards-incompatible: Remove logging from default error handlers.
Add fields.DelimitedList (66). Thanks jmcarp.
Features:
Add FalconParser (63).
Add fields.DelimitedList (66). Thanks jmcarp.
TornadoParser will parse json with simplejson if it is installed.
BottleParser caches parsed json per-request for improved performance.
No breaking changes. Yay!
*Backwards-compatible*: webargs.core.get_value takes a Field as its last argument. Note: this is technically a breaking change, but this won't affect…
Features:
TornadoParser returns unicode strings rather than bytestrings (41). Thanks thomasboyt for the suggestion.
Add Parser.get_default_request and Parser.get_request_from_view_args hooks to simplify Parser implementations.
Backwards-compatible: webargs.core.get_value takes a Field as its last argument. Note: this is technically a breaking change, but this won't affect most users since get_value is only used internally by Parser classes.
Support:
Add examples/annotations_example.py (demonstrates using Python 3 function annotations to define request arguments).
Fix examples. Thanks hyunchel for catching an error in the Flask error handling docs.
Bug fixes:
Correctly pass validate and force_all params to PyramidParser.use_args.
The major change in this release is that webargs now depends on marshmallow _ for defining arguments and validation.
The major change in this release is that webargs now depends on marshmallow for defining arguments and validation.
Your code will need to be updated to use Fields rather than Args.
# Old API
from webargs import Arg
args = {
"name": Arg(str, required=True),
"password": Arg(str, validate=lambda p: len(p) >= 6),
"display_per_page": Arg(int, default=10),
"nickname": Arg(multiple=True),
"Content-Type": Arg(dest="content_type", location="headers"),
"location": Arg({"city": Arg(str), "state": Arg(str)}),
"meta": Arg(dict),
}
# New API
from webargs import fields
args = {
"name": fields.Str(required=True),
"password": fields.Str(validate=lambda p: len(p) >= 6),
"display_per_page": fields.Int(load_default=10),
"nickname": fields.List(fields.Str()),
"content_type": fields.Str(load_from="Content-Type"),
"location": fields.Nested({"city": fields.Str(), "state": fields.Str()}),
"meta": fields.Dict(),
}
Features:
Error messages for all arguments are "bundled" (58).
Changes:
Backwards-incompatible: Replace Args with marshmallow fields (61).
Backwards-incompatible: When using use_kwargs, missing arguments will have the special value missing rather than None.
TornadoParser raises a custom HTTPError with a messages attribute when validation fails.
Bug fixes:
Fix required validation of nested arguments (39, 51). These are fixed by virtue of using marshmallow's Nested field. Thanks ewang and chavz for reporting.
Support:
Updated docs.
Add examples/schema_example.py.
Tested against Python 3.5.
If a parsed argument is None, the type conversion function is not called 54. Thanks marcellarius.
Changes:
If a parsed argument is None, the type conversion function is not called 54. Thanks marcellarius.
Bug fixes:
Fix parsing nested Args when the argument is missing from the input (52). Thanks stas.
Add parsing of matchdict to PyramidParser. Thanks hartror.
Features:
Add parsing of matchdict to PyramidParser. Thanks hartror.
Bug fixes:
Fix PyramidParser's use_kwargs method (42). Thanks hartror for the catch and patch.
Correctly use locations passed to Parser's constructor when using use_args (44). Thanks jacebrowning for the catch and patch.
Fix behavior of default and dest argument on nested Args (40 and 46). Thanks stas.
Changes:
A 422 response is returned to the client when a ValidationError is raised by a parser (38).
Support for webapp2 via the webargs.webapp2parser module. Thanks Trii.
Features:
Support for webapp2 via the webargs.webapp2parser module. Thanks Trii.
Store argument name on RequiredArgMissingError. Thanks stas.
Allow error messages for required validation to be overriden. Thanks again stas.
Removals:
Remove source parameter from Arg.
Store argument name on ValidationError (32). Thanks alexmic for the suggestion. Thanks stas for the patch.
Features:
Store argument name on ValidationError (32). Thanks alexmic for the suggestion. Thanks stas for the patch.
Allow nesting of dict subtypes.
The source parameter is deprecated in favor of the dest parameter.
Changes:
Add dest parameter to Arg constructor which determines the key to be added to the parsed arguments dictionary (32).
Backwards-incompatible: Rename targets parameter to locations in Parser constructor, Parser#parse_arg, Parser#parse, Parser#use_args, and Parser#use_kwargs.
Backwards-incompatible: Rename Parser#target_handler to Parser#location_handler.
Deprecation:
The source parameter is deprecated in favor of the dest parameter.
Bug fixes:
Fix validate parameter of DjangoParser#use_args.
When parsing a nested Arg, filter out extra arguments that are not part of the Arg's nested dict (28). Thanks Derrick Gilland for the suggestion.
When parsing a nested Arg, filter out extra arguments that are not part of the Arg's nested dict (28). Thanks Derrick Gilland for the suggestion.
Fix bug in parsing Args with both type coercion and multiple=True (30). Thanks Steven Manuatu for reporting.
Raise RequiredArgMissingError when a required argument is missing on a request.
Fix behavior of multiple=True when nesting Args (29). Thanks Derrick Gilland for reporting.
Fix behavior of multiple=True when nesting Args (29). Thanks Derrick Gilland for reporting.
Pyramid support thanks to @philtay.
Pyramid support thanks to @philtay.
User-friendly error messages when Arg type conversion/validation fails. Thanks Andriy Yurchuk.
Allow use argument to be a list of functions.
Allow Args to be nested within each other, e.g. for nested dict validation. Thanks @saritasa for the suggestion.
Backwards-incompatible: Parser will only pass ValidationErrors to its error handler function, rather than catching all generic Exceptions.
Backwards-incompatible: Rename Parser.TARGET_MAP to Parser.__target_map__.
Add a short-lived cache to the Parser class that can be used to store processed request data for reuse.
Docs: Add example usage with Flask-RESTful.
Fix bug in TornadoParser that raised an error when request body is not a string (e.g when it is a Future). Thanks Josh Carp.
Fix bug in TornadoParser that raised an error when request body is not a string (e.g when it is a Future). Thanks Josh Carp.
Fix Parser.use_kwargs behavior when an Arg is allowed missing. The allow_missing attribute is ignored when use_kwargs is called.
Fix Parser.use_kwargs behavior when an Arg is allowed missing. The allow_missing attribute is ignored when use_kwargs is called.
default may be a callable.
Allow ValidationError to specify a HTTP status code for the error response.
Improved error logging.
Add 'query' as a valid target name.
Allow a list of validators to be passed to an Arg or Parser.parse.
A more useful __repr__ for Arg.
Add examples and updated docs.
Add source parameter to Arg constructor. Allows renaming of keys in the parsed arguments dictionary. Thanks Josh Carp.
Add source parameter to Arg constructor. Allows renaming of keys in the parsed arguments dictionary. Thanks Josh Carp.
FlaskParser's handle_error method attaches the string representation of validation errors on err.data['message']. The raised exception is stored on err.data['exc'].
Additional keyword arguments passed to Arg are stored as metadata.
Fix bug in TornadoParser's handle_error method. Thanks Josh Carp.
Fix bug in TornadoParser's handle_error method. Thanks Josh Carp.
Add error parameter to Parser constructor that allows a custom error message to be used if schema-level validation fails.
Fix bug that raised a UnicodeEncodeError on Python 2 when an Arg's validator function received non-ASCII input.
Fix regression with parsing an Arg with both default and target set (see issue #11).
Fix regression with parsing an Arg with both default and target set (see issue #11).
Add validate parameter to Parser.parse and Parser.use_args. Allows validation of the full parsed output.
Add validate parameter to Parser.parse and Parser.use_args. Allows validation of the full parsed output.
If allow_missing is True on an Arg for which None is explicitly passed, the value will still be present in the parsed arguments dictionary.
Backwards-incompatible: Parser's parse_* methods return webargs.core.Missing if the value cannot be found on the request. NOTE: webargs.core.Missing will not show up in the final output of Parser.parse.
Fix bug with parsing empty request bodies with TornadoParser.
Fix behavior of Arg's allow_missing parameter when multiple=True.
Fix behavior of Arg's allow_missing parameter when multiple=True.
Fix bug in tornadoparser that caused parsing JSON arguments to fail.
Fix JSON parsing in Flask parser when Content-Type header contains more than just application/json. Thanks Samir Uppaluru for reporting.
Fix JSON parsing in Flask parser when Content-Type header contains more than just application/json. Thanks Samir Uppaluru for reporting.
Backwards-incompatible: The use parameter to Arg is called before type conversion occurs. Thanks Eric Wang for the suggestion.
Tested on Tornado>=4.0.
Custom target handlers can be defined using the Parser.target_handler decorator.
Custom target handlers can be defined using the Parser.target_handler decorator.
Error handler can be specified using the Parser.error_handler decorator.
Args can define their request target by passing in a target argument.
Backwards-incompatible: DEFAULT_TARGETS is now a class member of Parser. This allows subclasses to override it.
Fix bug that caused use_args to fail on class-based views in Flask.
Fix bug that caused use_args to fail on class-based views in Flask.
Add allow_missing parameter to Arg.
Awesome contributions from the open-source community!
Awesome contributions from the open-source community!
Add use_kwargs decorator. Thanks @venuatu.
Tornado support thanks to @jvrsantacruz.
Tested on Python 3.4.
Fix bug with parsing JSON in Flask and Bottle.
Fix bug with parsing JSON in Flask and Bottle.
Remove print statements in core.py. Oops.
Remove print statements in core.py. Oops.
Add support for repeated parameters (#1).
Add support for repeated parameters (#1).
Backwards-incompatible: All parse_* methods take arg as their fourth argument.
Add error_handler param to Parser.
Add targets param to Parser. Allows setting default targets.
Bottle support.
Add targets param to Parser. Allows setting default targets.
Add files target.
Parses JSON, querystring, forms, headers, and cookies.
First release.
Parses JSON, querystring, forms, headers, and cookies.
Support for Flask and Django.
Your coding agent can read these notes before it upgrades. Set up the MCP server →