finds.dev← search

// the find

jazzband/djangorestframework-simplejwt

★ 4,330 · Python · MIT · updated Sep 2026

A JSON Web Token authentication plugin for the Django REST Framework.

The de facto JWT auth backend for Django REST Framework, handling access/refresh token issuance, verification, and rotation. It's for anyone building a DRF API that needs token auth instead of session cookies, especially SPA or mobile clients talking to a Django backend.

Ships an optional token_blacklist app with proper Django models and migrations rather than bolting revocation on as an afterthought — outstanding/blacklisted tokens are queryable and there's a management command to flush expired ones. Lives under Jazzband, so it isn't a single-maintainer bus-factor risk like a lot of auth libraries. Settings are centralized in one settings.py with sane DRF-style config overrides, and customizing token claims is a documented, supported path rather than a hack.

Revocation is not immediate by default — tokens are stateless JWTs, so if you don't install the blacklist app a compromised token is valid until it expires, and a lot of people miss this. The blacklist app itself trades that problem for a database write on every refresh, which is a real cost under load and reintroduces the statefulness JWT was supposed to avoid. There's no built-in JWKS/key-rotation endpoint, so if you need to verify tokens from multiple services or rotate signing keys without downtime, that's on you to build. Sliding tokens and rotation together have enough moving parts (refresh reuse detection, grace periods) that misconfiguration is easy and the failure mode is silent — you don't find out until someone replays a token.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →