Home
Softono

Dj Rest Auth

Open source MIT Python
1.9K
Stars
345
Forks
255
Issues
17
Watchers
2 months
Last Commit

 About Dj Rest Auth

Authentication for Django Rest Framework

Platforms

Web Self-hosted

Languages

Python

Need Help Installing Dj Rest Auth?

We provide expert installation service for this software. Our team will install, configure, and secure Dj Rest Auth on your server. plans start at just $30.

Dj Rest Auth

View on GitHub

dj-rest-auth

CI Security PyPI Python Django

Secure drop-in authentication endpoints for Django REST Framework. Works seamlessly with SPAs and mobile apps.

Documentation | PyPI

Features

  • Login, logout, password change, password reset
  • User registration with email verification
  • Built-in MFA/2FA support (TOTP + recovery codes)
  • Passkey / WebAuthn passwordless authentication
  • JWT authentication with HTTP-only cookies
  • Social auth (Google, GitHub, Facebook) via django-allauth
  • Fully customizable serializers

Architecture

flowchart LR
    Client[Client<br/>React / Vue / Mobile]
    
    subgraph Django
        subgraph dj-rest-auth
            Auth[Login / Logout]
            Reg[Registration]
            PW[Password Reset]
            PK[Passkeys]
        end
        
        DRF[Django REST Framework]
        DJAuth[django.contrib.auth]
        AA[django-allauth]
        JWT[simplejwt]
    end
    
    Client <--> dj-rest-auth
    
    Auth --> DRF
    Auth --> DJAuth
    Auth -.-> JWT
    Reg -.-> AA
    PW --> DJAuth

Quick Start

pip install dj-rest-auth
# settings.py
INSTALLED_APPS = [
    ...
    'rest_framework',
    'rest_framework.authtoken',
    'dj_rest_auth',
]
# urls.py
urlpatterns = [
    path('auth/', include('dj_rest_auth.urls')),
]

You now have:

Endpoint Method Description
/auth/login/ POST Obtain auth token
/auth/logout/ POST Revoke token
/auth/user/ GET, PUT User details
/auth/password/change/ POST Change password
/auth/password/reset/ POST Request reset email
/auth/password/reset/confirm/ POST Confirm reset

JWT with HTTP-only Cookies

pip install dj-rest-auth djangorestframework-simplejwt
# settings.py
REST_FRAMEWORK = {
    'DEFAULT_AUTHENTICATION_CLASSES': [
        'dj_rest_auth.jwt_auth.JWTCookieAuthentication',
    ],
}

REST_AUTH = {
    'USE_JWT': True,
    'JWT_AUTH_COOKIE': 'access',
    'JWT_AUTH_REFRESH_COOKIE': 'refresh',
    'JWT_AUTH_HTTPONLY': True,
}

Registration

pip install 'dj-rest-auth[with-social]'
# settings.py
INSTALLED_APPS = [
    ...
    'django.contrib.sites',
    'allauth',
    'allauth.account',
    'dj_rest_auth.registration',
]

SITE_ID = 1
# urls.py
urlpatterns = [
    path('auth/', include('dj_rest_auth.urls')),
    path('auth/registration/', include('dj_rest_auth.registration.urls')),
]

MFA / 2FA

pip install 'dj-rest-auth[with-mfa]'

MFA ships as an opt-in sub-package (dj_rest_auth.mfa) with:

  • TOTP login challenge flow
  • Recovery codes
  • Security-focused defaults (short-lived MFA tokens, activation confirmation)

See the guide for setup and endpoint details: MFA Guide

Passkeys (WebAuthn)

pip install 'dj-rest-auth[with-passkeys]'

Passkeys provide passwordless authentication using the FIDO2/WebAuthn standard:

  • Touch ID, Windows Hello, hardware security keys
  • Two-step challenge-response registration and login
  • Credential management (list, rename, delete)

See the guide for setup and endpoint details: Passkeys Guide

Documentation

Full documentation at dj-rest-auth.readthedocs.io

Contributing

pip install -r dj_rest_auth/tests/requirements.txt
python runtests.py

See Contributing Guide for details.

License

MIT