Skip to content

Add pydantic-jwt to security libraries list - #334

Open
dmi03 wants to merge 1 commit into
mjhea0:mainfrom
dmi03:add-pydantic-jwt
Open

dmi03 wants to merge 1 commit into
mjhea0:mainfrom
dmi03:add-pydantic-jwt

Conversation

@dmi03

@dmi03 dmi03 commented Aug 29, 2026 •

Copy link
Copy Markdown

Project Information

  1. Project Name: pydantic-jwt
  2. Project URL: https://github.com/dmi03/pydantic-jwt
  3. Description:
    JWT tokens as Pydantic models. The claims are declared as fields on a model,
    and that one class both issues tokens and validates incoming ones — parsing,
    claim checks and signature verification. Failures surface as regular
    ValidationErrors. It has no FastAPI dependency, but is designed to be used
    through a FastAPI dependency; the docs ship a complete example application.

Criteria

  1. Is the project new?

    • Yes
    • No
  2. How long has the project been maintained?
    Under a year

  3. How many releases has it had if it's a library or package?
    3 — https://github.com/dmi03/pydantic-jwt/releases

  4. Are you the author, or are you submitting the project on behalf of a company?

    • I am the author
    • I am submitting on behalf of a company
    • Other (please specify)
  5. What makes it awesome?
    Every other entry in the Auth section wraps FastAPI. This one moves the token
    into the type system instead: the endpoint receives a typed object rather
    than dict[str, Any], the claim set is written down once, and expired,
    forged and malformed tokens all fail through Pydantic's normal error path, so
    a single except in the dependency covers them. The algorithm is taken from
    configuration and never from the token header, which rules out algorithm
    confusion by construction.


AI Disclosure

  • Yes, this pull request was generated or assisted by AI.
  • No, this pull request was authored entirely by a human.

Additional Information

Full documentation at https://pydantic-jwt.dmi03.com, including a
security notes page covering
the library's sharp edges and what it deliberately leaves to the caller, and a
FastAPI guide with a
complete application — bearer dependency, refresh token rotation, scopes and
tests. Test coverage is 100% (statements and branches), the package ships
py.typed and is checked under mypy --strict.

I am aware the project does not meet the age and stars guidance in this
template. Submitting anyway in case the maintainer considers it a fit; happy to
resubmit later if not.

Added a new security library for JWT token management.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant