TinySesam

TinySesam

The login layer for your self-built apps.
Super-light auth for FastAPI where you use
only what you need
Hang one class in front of your app and get login pages, sessions and route guards. It grows with you.

Secures your own apps and consumes existing identity providers (OIDC, SAML, LDAP / AD). It is not an identity provider itself — not a Keycloak / Authentik / PocketID replacement.

MIT · Python 3.12+ · every feature optional, front end fully replaceable

Use only what you need

  • ✓Just gate one page behind a PIN?
    — a shared PIN or passphrase, no user account required.
  • ✓Forward-auth in front of other apps, like TinyAuth?
    — yes, via /auth/forward or a ready-made OIDC gateway.
  • ✓Want an admin panel?
    — built in. Prefer it inside your own? — use just the JSON API.
  • ✓From “a password is enough” to “OIDC → password → TOTP”?
    — it grows with you; every piece optional, on/off by config.
  • ✓Your own look & language?
    — the whole front end is replaceable (set_template), texts in English or German.

Ways to sign in

🔐 Password🔢 PIN🔑 Passkey / WebAuthn🌐 OIDC · Entra🪪 SAML 2.0🗂️ LDAP / Active Directory✉️ Magic-link📱 TOTP + recovery codes

See every sign-in flow as a diagram →

And more

Factor chainsordered combinations like OIDC → password, per route or global
Step-up MFAre-confirm before sensitive routes — with a PIN, TOTP or the password
Register & inviteself-signup, email verification, invitation links
Sign in with what you wantusername, email or both — login_identifier
Shared resource secretprotect an area with a PIN/passphrase, no account
Forward-authguard other apps via Caddy / nginx / Traefik
Admin panel & API keysusers, sessions, service accounts, audit log
Hardenedargon2, CSRF, brute-force lockout, Redis rate-limit, i18n

Install

pip install "tinysesam[all] @ git+https://github.com/Ollornog/TinySesam.git@v0.24.2"

[all] pulls every optional dependency. Take only what you need:

  • [argon2]stronger hashing
  • [oidc]OIDC login
  • [saml]SAML 2.0
  • [ldap]LDAP/AD
  • [passkey]WebAuthn
  • [qr]TOTP QR code
  • [redis]rate limit across workers
  • [gateway]forward-auth gateway (OIDC + server)

Combine them: [oidc,argon2]. Without any extra you still get password + TOTP (stdlib scrypt).

Use

auth = TinySesam(TinySesamConfig(db_path="app.db")) app.include_router(auth.router()) # /auth/* + login UI @app.get("/") def home(user = Depends(auth.require_user)): # protected return {"hi": user["username"]}

Want just SSO in front of existing apps? Run it as an OIDC forward-auth gateway.

TinySesam

TinySesam

Der Login-Mechanismus für deine selbstgebauten Apps.
Super-leichtes Auth für FastAPI, bei dem du
nur nutzt, was du brauchst
Eine Klasse davorhängen — Login-Seite, Sessions und Route-Guards inklusive. Es wächst mit dir.

Sichert deine eigenen Apps und nutzt vorhandene IdProvider (OIDC, SAML, LDAP / AD). Es ist selbst kein Identity Provider — kein Ersatz für Keycloak / Authentik / PocketID.

MIT · Python 3.12+ · jedes Feature optional, Frontend komplett austauschbar

Nutze nur, was du brauchst

  • ✓Nur eine Seite hinter einer PIN sichern?
    — eine geteilte PIN oder Passphrase, ganz ohne Benutzerkonto.
  • ✓Forward-Auth vor fremde Apps hängen, wie TinyAuth?
    — ja, über /auth/forward oder ein fertiges OIDC-Gateway.
  • ✓Ein Admin-Panel?
    — eingebaut. Lieber in dein eigenes einbauen? — dann nur die JSON-API.
  • ✓Von „Passwort reicht“ bis „OIDC → Passwort → TOTP“?
    — wächst mit — jedes Stück optional, an/aus per Config.
  • ✓Eigenes Look & Feel, eigene Sprache?
    — das komplette Frontend ist austauschbar (set_template), Texte auf Deutsch oder Englisch.

Wege sich anzumelden

🔐 Passwort🔢 PIN🔑 Passkey / WebAuthn🌐 OIDC · Entra🪪 SAML 2.0🗂️ LDAP / Active Directory✉️ Magic-Link📱 TOTP + Recovery-Codes

Alle Login-Wege als Diagramm ansehen →

Und mehr

Faktor-Kettengeordnete Kombinationen wie OIDC → Passwort, pro Route oder global
Step-up-MFAvor sensiblen Routen erneut bestätigen — per PIN, TOTP oder Passwort
Registrierung & EinladungSelbst-Registrierung, E-Mail-Bestätigung, Einladungslinks
Anmelden womit du willstBenutzername, E-Mail oder beides — login_identifier
Geteiltes Ressourcen-Geheimniseinen Bereich per PIN/Passphrase schützen, ohne Konto
Forward-Authfremde Apps über Caddy / nginx / Traefik absichern
Admin-Panel & API-KeysBenutzer, Sitzungen, Service-Accounts, Audit-Log
Gehärtetargon2, CSRF, Brute-Force-Lockout, Redis-Rate-Limit, i18n

Installation

pip install "tinysesam[all] @ git+https://github.com/Ollornog/TinySesam.git@v0.24.2"

[all] zieht alle optionalen Abhängigkeiten. Nimm nur, was du brauchst:

  • [argon2]stärkeres Hashing
  • [oidc]OIDC-Login
  • [saml]SAML 2.0
  • [ldap]LDAP/AD
  • [passkey]WebAuthn
  • [qr]TOTP-QR-Code
  • [redis]Rate-Limit über mehrere Worker
  • [gateway]Forward-Auth-Gateway (OIDC + Server)

Kombinierbar: [oidc,argon2]. Ganz ohne Extra bleiben Passwort + TOTP (stdlib-scrypt).

Benutzung

auth = TinySesam(TinySesamConfig(db_path="app.db")) app.include_router(auth.router()) # /auth/* + Login-UI @app.get("/") def home(user = Depends(auth.require_user)): # geschützt return {"hi": user["username"]}

Nur SSO vor bestehende Apps? Dann als OIDC-Forward-Auth-Gateway betreiben.