Secure FastAPI Application with Oauth2 JWT

In this tutorial, we will learn how to sign up, login for token, and secure FastAPI application with Oauth2 JWT. We will use MongoDB database to persist users data.

FastAPI provides several tools for implementing security easily without a big amount of effort and code.

FastAPI is based on OpenAPI. OpenAPI was previously known as Swagger. Swagger was orginally designed to generate interactive documentation interfaces.

FastAPI defines several security schemes. Some are as follows:

  • apiKey: This is an application specific key which can come from a header, cookie or a query parameter.
  • http: A standard http authentication system that includes the following:
    • bearer : A header Authorization value with a token. It is inherited from OAuth2.
    • HTTP basic authentication
    • HTTP Digest
  • Oauth2: Includes all the OAuth2 process of handling security flows:
    • The implicit, clientCredentials, and authorizationCode flows are appropriate for creating authentication providers like Google, Facebook, etc.
    • The password flow can be used for handling authentication in the same application directly.
  • openIdConnect: This provides a way to discover Oauth2 authentication data automatically. The automatic discovery is defined in the OpenID connect specification.

Follow the steps below to complete this tutorial:

  1. Create a Python project with the following file structure:
    ├── app
    │   │── env
    │   ├──
    │   ├──
    │   └── src
    │   │   ├──
    │   │   ├── user
    │   │   │    ├──
    │   │   │    └──

    The user folder has a file for user APIs.

    There is one file in every directory or subdirectory. This presence of files allows importing code from one file into another.

  3. Install the following dependencies for FastAPI, Uvicorn, passlib, python-jose[cryptography], python-multipart, mongoengine:
    pip install fastapi
    pip install uvicorn
    pip install passlib
    pip install python-jose[cryptography]
    pip install python-multipart
    pip install mongoengine
  5. Create src/ file and add User class for saving user data in MongoDB:
    from mongoengine import Document, StringField, DateTimeField, IntField, BooleanField
    import datetime
    class User(Document):
        _id = IntField()
        username = StringField(max_length=250, required=True)
        password = StringField(max_length=250, required=True)
        disabled = BooleanField(default=False)
        date_created = DateTimeField(default=datetime.datetime.utcnow)
        date_modified = DateTimeField(default=datetime.datetime.utcnow)
  7. Create user related APIs in the src/user/ file:
    from datetime import datetime, timedelta
    from fastapi import APIRouter, Depends, HTTPException, Query, status
    from pydantic import BaseModel, Field
    from typing import Optional
    from src.models import User
    from passlib.context import CryptContext
    from import OAuth2PasswordBearer, OAuth2PasswordRequestForm
    import json
    from jose import jwt, JWTError
    router = APIRouter(
        responses={404: {"description": "Not found"}}
    class NewUser(BaseModel):
        username: str
        password: str
    crypt_context = CryptContext(schemes=["sha256_crypt", "md5_crypt"])
    def get_password_hash(password):
        return crypt_context.hash(password)
    oauth2_scheme = OAuth2PasswordBearer(tokenUrl="token")"/signup")
    async def sign_up(newUser: NewUser):
        user = User(username=newUser.username,
        return {"message": "Created user successfully!"}
    # run the following on terminal to generate a secret key
    # openssl rand -hex 32
    SECRET_KEY = "3e8a3f31aab886f8793176988f8298c9265f84b8388c9fef93635b08951f379b"
    ALGORITHM = "HS256"
    def create_access_token(data: dict, expires_delta: timedelta):
        to_encode = data.copy()
        expire = datetime.utcnow() + expires_delta
        to_encode.update({"exp": expire})
        encoded_jwt = jwt.encode(to_encode, SECRET_KEY, algorithm=ALGORITHM)
        return encoded_jwt
    def verify_password(plain_password, hashed_password):
        return crypt_context.verify(plain_password, hashed_password)
    def authenticate(username, password):
            user = get_user(username)
            password_check = verify_password(password, user['password'])
            return password_check
        except User.DoesNotExist:
            return False
    class Token(BaseModel):
        access_token: str
        token_type: str"/token" , response_model=Token)
    async def login(form_data: OAuth2PasswordRequestForm = Depends()):
        username = form_data.username
        password = form_data.password
        if authenticate(username, password):
            access_token = create_access_token(
                data={"sub": username}, expires_delta=timedelta(minutes=ACCESS_TOKEN_EXPIRE_MINUTES))
            return {"access_token": access_token, "token_type": "bearer"}
            raise HTTPException(
                status_code=400, detail="Incorrect username or password")
    class TokenData(BaseModel):
        username: Optional[str] = None
    def get_user(username: str):
            user = json.loads(User.objects.get(username=username).to_json())
            return user
        except User.DoesNotExist:
            return None
    async def get_current_user(token: str = Depends(oauth2_scheme)):
        credentials_exception = HTTPException(
            detail="Could not validate credentials",
            headers={"WWW-Authenticate": "Bearer"},
            payload = jwt.decode(token, SECRET_KEY, algorithms=[ALGORITHM])
            username: str = payload.get("sub")
            if username is None:
                raise credentials_exception
            token_data = TokenData(username=username)
        except JWTError:
            raise credentials_exception
        user = get_user(username=token_data.username)
        if user is None:
            raise credentials_exception
        return user
    async def user_detail(current_user: User = Depends(get_current_user)):
        return {"name": "Danny", "email": "[email protected]"}
  9. On the app/ file add the code as shown in the example below:
    import uvicorn
    from fastapi import FastAPI
    from src.user import main as user_main
    from mongoengine import connect, disconnect
    app = FastAPI()
    connect('my_db_fast_api', host='', port=27107)
    if __name__ == '__main__':, host='', port=8005)
  11. Run your application and open on your web browser.
  12. Sign up a user with /users/signup POST API and use /users/token POST API to retrieve access token. Use this access token to access /users/detail GET API which is protected.