Django OAuth Toolkit
3.4.0
Installation
Upgrading
Getting started
Tutorials
Part 1 - Make a Provider in a Minute
Part 2 - protect your APIs
Part 3 - OAuth2 token authentication
Part 4 - Revoking an OAuth2 Token
Part 5 - Using Celery to Automate Maintenance Chores
Part 6 - Device authorization grant flow
Part 7 - Managing applications and tokens in the Django admin
Django Rest Framework
Django Ninja
Using the views
Templates
Views code and details
Models
Advanced topics
RFC 9700 Security Best Current Practice
Security Vulnerability Response and Release Process
Principles
Roles and access
Repositories and data boundaries
Report intake and triage
Advisory and CVE management
Patch development paths
Shared security repository conventions
Required private validation
Multi-advisory release trains
Final private release gate
Public promotion and release
Failure during public cutover
Post-release work
OpenID Connect
OAuth 2.0 Authorization Server Metadata
OAuth 2.0 Protected Resource Metadata
Client ID Metadata Documents (CIMD)
Signals
Settings
Separate Resource Server
Token Audience Binding (RFC 8707)
Management commands
Glossary
Contributing
Changelog
Django OAuth Toolkit
Tutorials
View page source
Tutorials
Part 1 - Make a Provider in a Minute
Scenario
Start Your App
Create an OAuth2 Client Application
Test Your Authorization Server
Part 2 - protect your APIs
Scenario
Make your API
Testing your API
Part 3 - OAuth2 token authentication
Scenario
Setup a provider
Protect your view
Working with Rest_framework generic class based views
Part 4 - Revoking an OAuth2 Token
Scenario
Revoking a Token
Setup a Request
Part 5 - Using Celery to Automate Maintenance Chores
Scenario
Set up RabbitMQ
Add Celery
Run Celery Beat and the Worker
Configure the
clear_tokens
task
References
Part 6 - Device authorization grant flow
Scenario
Device Authorization
Device-confirm endpoint
Device polling
Part 7 - Managing applications and tokens in the Django admin
Scenario
Enabling the admin
Managing applications
Reviewing and revoking tokens