Django OAuth Toolkit
July 28, 2026 ยท View on GitHub
OAuth2 goodies for the Djangonauts!
.. image:: https://badge.fury.io/py/django-oauth-toolkit.svg :target: http://badge.fury.io/py/django-oauth-toolkit
.. image:: https://github.com/django-oauth/django-oauth-toolkit/workflows/Test/badge.svg :target: https://github.com/django-oauth/django-oauth-toolkit/actions :alt: GitHub Actions
.. image:: https://codecov.io/gh/django-oauth/django-oauth-toolkit/branch/master/graph/badge.svg :target: https://codecov.io/gh/django-oauth/django-oauth-toolkit :alt: Coverage
.. image:: https://img.shields.io/pypi/pyversions/django-oauth-toolkit.svg :target: https://pypi.org/project/django-oauth-toolkit/ :alt: Supported Python versions
.. image:: https://img.shields.io/pypi/djversions/django-oauth-toolkit.svg :target: https://pypi.org/project/django-oauth-toolkit/ :alt: Supported Django versions
Django OAuth Toolkit is an OAuth 2.0 authorization server for teams already running Django. It provides, out of the box, the endpoints, models, and logic to issue and manage OAuth2 tokens from your existing Django project, instead of standing up and operating a separate service.
As of 3.4.0, Django OAuth Toolkit supports the authorization server role required by the
Model Context Protocol (MCP) authorization specification: PKCE is required by default, and the
authorization server metadata (RFC 8414) and protected resource metadata (RFC 9728) discovery
endpoints are included in the default URLconf. Dynamic Client Registration (RFC 7591/7592) and
Client ID Metadata Documents can be enabled with the DCR_ENABLED and CIMD_ENABLED settings.
See the
3.4.0 release discussion <https://github.com/django-oauth/django-oauth-toolkit/discussions/1775>_
for the supported specifications and current gaps.
Django OAuth Toolkit can also act as a resource server to protect a Django or Django REST
Framework API with OAuth2. It makes extensive use of the excellent
OAuthLib <https://github.com/idan/oauthlib>, so that everything is
rfc-compliant <https://rfc-editor.org/rfc/rfc6749.html>.
Reporting security issues
Please use GitHub's private vulnerability reporting form <https://github.com/django-oauth/django-oauth-toolkit/security/advisories/new>_
and follow the repository security policy <https://github.com/django-oauth/django-oauth-toolkit/security/policy>. Do not
file a public issue or pull request for an undisclosed vulnerability. If private
reporting is unavailable, email the Django OAuth security team <mailto:django-oauth-security@googlegroups.com>.
Requirements
- Python 3.10, 3.11, 3.12, 3.13 or 3.14
- Django 4.2, 5.0, 5.1, 5.2 or 6.0
- oauthlib 3.2.2+
Installation
Install with pip::
pip install django-oauth-toolkit
Add oauth2_provider to your INSTALLED_APPS
.. code-block:: python
INSTALLED_APPS = (
...
'oauth2_provider',
)
If you need an OAuth 2.0 authorization server you'll want to add the following to your urls.py.
.. code-block:: python
from oauth2_provider import urls as oauth2_urls
urlpatterns = [
...
path('o/', include(oauth2_urls)),
]
Changelog
See CHANGELOG.md <https://github.com/django-oauth/django-oauth-toolkit/blob/master/CHANGELOG.md>_.
Documentation
The full documentation <https://django-oauth-toolkit.readthedocs.io/>_ is on Read the Docs.
License
django-oauth-toolkit is released under the terms of the BSD license. Full details in LICENSE file.
Help Wanted
We need help maintaining and enhancing django-oauth-toolkit (DOT).
Join the team
There are no barriers to participation. Anyone can open an issue, pr, or review a pull request. Please
dive in!
How you can help
See our
contributing <https://django-oauth-toolkit.readthedocs.io/en/latest/contributing.html>__
info and the open
issues <https://github.com/django-oauth/django-oauth-toolkit/issues>__ and
PRs <https://github.com/django-oauth/django-oauth-toolkit/pulls>,
especially those labeled
help-wanted <https://github.com/django-oauth/django-oauth-toolkit/labels/help-wanted>.
Discussions
Have questions or want to discuss the project?
See `the discussions <https://github.com/django-oauth/django-oauth-toolkit/discussions>`__.
Submit PRs and Perform Reviews
PR submissions and reviews are always appreciated! Since we require an independent review of any PR before it can be merged, having your second set of eyes looking at PRs is extremely valuable.
Become a Maintainer
If you are interested in stepping up to be a Maintainer, please open an issue. For maintainers we're
looking for a positive attitude, attentiveness to the specifications, strong coding and
communication skills, and a willingness to work with others. Maintainers are responsible for
merging pull requests, managing issues, creating releases, and ensuring the overall health of the
project.