// the find
yezz123/authx
Ready-to-use and customizable Authentications and Oauth2 management for FastAPI ✨
AuthX bolts JWT-based authentication and authorization onto FastAPI: access/refresh tokens, multiple token locations, a blocklist, and a scope/policy engine. It's aimed at FastAPI developers who want a prebuilt auth layer instead of wiring raw JWT handling and dependencies themselves.
Token handling covers the stuff most DIY JWT setups skip: freshness checks for sensitive endpoints, a revocation blocklist, and support for four token locations (headers, cookies with CSRF, query, body) rather than just bearer headers. The policy engine for scopes/attributes/environment checks is more flexible than typical hardcoded RBAC. Test layout (dedicated files for key rotation, rate limiting, websocket auth, scopes) and CI/codecov/pre-commit wiring suggest the maintainers actually exercise these paths.
The description promises 'Oauth2 management' but there's no OAuth2 provider flow in this package — it's split into the separate authx-extra repo, along with Redis sessions, caching, and metrics, so anything past bare JWT auth means trusting a second, less-maintained package. Core logic sits in underscore-prefixed internal modules (_signature.py, _session.py, _ratelimit.py) with no clear public/private boundary documented, so extending behavior means reading private internals. The README's own quickstart checks a hardcoded plaintext username/password with no mention of hashing anywhere in the main docs, which is a rough first impression for a security library.