authkits

Search Authkits

Search pages, documentation, and resources.

Django edition available

Authentication you can actually ship fast.

Production-ready authentication, MFA, session and device security, social auth, headless APIs, abuse controls, audit history, and overrideable templates without rebuilding the stack for every project.

Included out of the box

MFA + recovery codes
Sessions + trusted devices
Persistent abuse controls
Social authentication
Headless + DRF APIs
Audit + offline licensing

Authkits Django

v0.1.0a2

authkits django

Security-first authentication for serious Django applications

Django 5.2 + 6.0

Self-hosted authentication with security controls built in

View docsGet Authkits

First available kit

The auth work every product needs, already handled.

The Django Authentication kit gives you the security-critical flows and defaults you would otherwise rebuild, review, and maintain for every new product.

Multi-factor auth

TOTP, email OTP, SMS OTP, backup codes, and secure recovery.

Rate limits

Protect sign-in, registration, password reset, and verification endpoints from abuse.

Audit logs

See sign-ins, failed attempts, password resets, and sensitive admin actions.

Email flows

Ship verification, password reset, magic links, and account recovery without rebuilding the plumbing.

Admin protection

Harden admin access with protected routes, enforced 2FA, and role checks.

API ready

Use clean auth endpoints across dashboards, mobile apps, and SaaS products.

Security by default

The safeguards auth needs before production.

Protection, recovery, visibility, and admin controls are built in from the start instead of being bolted on after launch.

Login protection

Rate limits, lockouts, suspicious IP checks, and session controls from day one.

Multi-factor auth

TOTP, email OTP, SMS OTP, backup codes, and trusted-device flows.

Account recovery

Password reset, email verification, recovery events, and sensible expiry windows.

Admin hardening

Protected admin paths, enforced 2FA, audit trails, and role-aware access checks.

Audit visibility

Track sign-ins, failed attempts, security events, and sensitive account actions.

Built to be yours

Start with working auth. Keep full control.

Install the entitled Django wheel, enable the account-security boundaries your product needs, and override the templates when you want the UI to feel completely native to your app.

python -m pip install ./authkits_django-<version>-py3-none-any.whl
your-project/settings.py
settings.py
$python -m pip install ./authkits_django-<version>-py3-none-any.whl
1INSTALLED_APPS = [
2    # ...
3    "authkits",
4    "allauth",
5    "allauth.account",
6    "allauth.socialaccount",
7    "allauth.socialaccount.providers.github",
8    "allauth.socialaccount.providers.google",
9]
10
11AUTHENTICATION_BACKENDS = [
12    "allauth.account.auth_backends.AuthenticationBackend",
13]
14
15MIDDLEWARE = [
16    # ...
17    "django.contrib.auth.middleware.AuthenticationMiddleware",
18    "allauth.account.middleware.AccountMiddleware",
19    "authkits.security.middleware.SessionSecurityMiddleware",
20]
21
22SOCIALACCOUNT_ADAPTER = "authkits.integrations.social.AuthkitsSocialAccountAdapter"
23SOCIALACCOUNT_QUERY_EMAIL = True
24SOCIALACCOUNT_EMAIL_AUTHENTICATION = False
25
26AUTHKITS = {
27    "ACCOUNTS": {
28        "REQUIRE_EMAIL_VERIFICATION": True,
29        "REQUIRE_TERMS": True,
30        "SIGNUP_ENABLED": True,
31    },
32    "SECURITY": {
33        "SESSION_TRACKING": True,
34        "TRUSTED_DEVICES": True,
35    },
36    "MFA": {
37        "TOTP_ENABLED": True,
38        "ALLOWED_METHODS": ["totp", "email"],
39        "ENCRYPTION_KEYS": [env("AUTHKITS_MFA_KEY")],
40    },
41    "SOCIAL": {
42        "ENABLED": True,
43        "MODE": "managed",
44        "PROVIDERS": {
45            "github": {
46                "CLIENT_ID": env("GITHUB_CLIENT_ID"),
47                "CLIENT_SECRET": env("GITHUB_CLIENT_SECRET"),
48            },
49            "google": {
50                "CLIENT_ID": env("GOOGLE_CLIENT_ID"),
51                "CLIENT_SECRET": env("GOOGLE_CLIENT_SECRET"),
52            },
53        },
54    },
55    "API": {
56        "ENABLED": True,
57        "CREDENTIAL_TTL": 604800,
58        "CREDENTIAL_MAX_ACTIVE": 10,
59    },
60    "UI": {
61        "LOGIN_REDIRECT": "/dashboard/",
62        "LOGOUT_REDIRECT": "/auth/login/",
63    },
64    "LICENSING": {
65        "ENTITLEMENT_FILE": "/run/secrets/authkits-entitlement.jws",
66    },
67}

Authentication kit roadmap

Django first. More stacks next.

Django is the first edition of the Authentication kit. Future editions can bring the same self-hosted approach to Next.js, FastAPI, and other popular stacks.

Available

Django

Production-ready authentication for Django applications.

Planned

Next.js

Self-hosted authentication for modern React products.

Planned

FastAPI

API-first authentication for Python backends and services.

Later

Laravel

A production auth foundation for Laravel applications.

One-time license

Pay once. Keep the code.

Get a production-ready Django authentication foundation you can own, customize, and ship without a recurring auth subscription.

Authkits Django License

$49one-time payment

Own the authentication foundation, run it in your infrastructure, and adapt it to your product.

Production-ready Django auth
Multi-factor authentication
Email verification
Password reset flows
Audit logs
Rate limiting
Admin protection
Future updates

FAQ

Know exactly what you are buying.

The important details about ownership, framework support, security, and how Authkits fits into your application.

Ship authentication. Build the product.

Start with a secure Django auth foundation, keep control of the code and infrastructure, and spend your time on what makes your product different.

One-time license. Self-hosted. Built to be extended.