Conversation
Added a new security library for JWT token management.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Project Information
JWT tokens as Pydantic models. The claims are declared as fields on a model,
and that one class both issues tokens and validates incoming ones — parsing,
claim checks and signature verification. Failures surface as regular
ValidationErrors. It has no FastAPI dependency, but is designed to be usedthrough a FastAPI dependency; the docs ship a complete example application.
Criteria
Is the project new?
How long has the project been maintained?
Under a year
How many releases has it had if it's a library or package?
3 — https://github.com/dmi03/pydantic-jwt/releases
Are you the author, or are you submitting the project on behalf of a company?
What makes it awesome?
Every other entry in the Auth section wraps FastAPI. This one moves the token
into the type system instead: the endpoint receives a typed object rather
than
dict[str, Any], the claim set is written down once, and expired,forged and malformed tokens all fail through Pydantic's normal error path, so
a single
exceptin the dependency covers them. The algorithm is taken fromconfiguration and never from the token header, which rules out algorithm
confusion by construction.
AI Disclosure
Additional Information
Full documentation at https://pydantic-jwt.dmi03.com, including a
security notes page covering
the library's sharp edges and what it deliberately leaves to the caller, and a
FastAPI guide with a
complete application — bearer dependency, refresh token rotation, scopes and
tests. Test coverage is 100% (statements and branches), the package ships
py.typedand is checked undermypy --strict.I am aware the project does not meet the age and stars guidance in this
template. Submitting anyway in case the maintainer considers it a fit; happy to
resubmit later if not.