// the find
jazzband/djangorestframework-simplejwt
A JSON Web Token authentication plugin for the Django REST Framework.
The de facto JWT auth backend for Django REST Framework, handling access/refresh token issuance, verification, and rotation. It's for anyone building a DRF API that needs token auth instead of session cookies, especially SPA or mobile clients talking to a Django backend.
Ships an optional token_blacklist app with proper Django models and migrations rather than bolting revocation on as an afterthought — outstanding/blacklisted tokens are queryable and there's a management command to flush expired ones. Lives under Jazzband, so it isn't a single-maintainer bus-factor risk like a lot of auth libraries. Settings are centralized in one settings.py with sane DRF-style config overrides, and customizing token claims is a documented, supported path rather than a hack.
Revocation is not immediate by default — tokens are stateless JWTs, so if you don't install the blacklist app a compromised token is valid until it expires, and a lot of people miss this. The blacklist app itself trades that problem for a database write on every refresh, which is a real cost under load and reintroduces the statefulness JWT was supposed to avoid. There's no built-in JWKS/key-rotation endpoint, so if you need to verify tokens from multiple services or rotate signing keys without downtime, that's on you to build. Sliding tokens and rotation together have enough moving parts (refresh reuse detection, grace periods) that misconfiguration is easy and the failure mode is silent — you don't find out until someone replays a token.