// the find
mitsuhiko/flask-oauth
OAuth Support for Flask
flask-oauth is a small single-file library that lets a Flask app authenticate against external OAuth providers like Google, Facebook, and Twitter. It's for consuming OAuth, not implementing an OAuth provider yourself, and it's aimed at classic OAuth1/OAuth2 flows from the pre-OAuth2-standardization era.
The implementation is tiny (a single flask_oauth.py file) so there's nothing hidden and it's trivial to read end to end in a few minutes. It ships working example apps for Facebook, Google, and Twitter that show the actual request/callback flow instead of just documenting it abstractly.
The README leads with 'Unmaintained' and points you straight at Flask-Dance instead — the maintainer is telling you not to use this. Last push was 2022, well before OAuth2 PKCE and modern provider requirements became standard, so provider configs will likely need patching to work at all. It only handles consuming third-party OAuth, so it's useless if you need to act as a provider. With 575 stars against 203 forks, a large chunk of the user base already had to fork it to fix or extend something.