Scalekit provides auth and actions on behalf of users, with 500+ connectors and 20,000+ tools. Build secure AI products faster with authentication for humans (SSO, passwordless, full-stack auth) and agents (MCP/APIs, delegated actions), all unified on one platform. This Python SDK enables both traditional B2B authentication and cutting-edge agentic workflows.
- 🔐 Agent Identity: Agents as first-class actors with human ownership and org context
- 🎯 MCP-Native OAuth 2.1: Purpose-built for Model Context Protocol with DCR/PKCE support
- ⏰ Ephemeral Credentials: Time-bound, task-based authorization (minutes, not days)
- 🔒 Token Vault: Per-user, per-tool token storage with rotation and progressive consent
- 👥 Human-in-the-Loop: Step-up authentication when risk crosses thresholds
- 📊 Immutable Audit: Track which user initiated, which agent acted, what resource was accessed
- 🔐 Enterprise SSO: Support for SAML and OIDC protocols
- 👥 SCIM Provisioning: Automated user provisioning and deprovisioning
- 🚀 Passwordless Authentication: Magic links, OTP, and modern auth flows
- 🏢 Multi-tenant Architecture: Organization-level authentication policies
- 📱 Social Logins: Support for popular social identity providers
- 🛡️ Full-Stack Auth: Complete IdP-of-record solution for B2B SaaS
- 🐍 Pythonic API: Clean, intuitive interface following Python conventions
- Sign up for a Scalekit account.
- Get your
env_url,client_idandclient_secretfrom the Scalekit dashboard.
Install Scalekit SDK using your preferred package manager.
pip install scalekit-sdk-python
from scalekit import ScalekitClient
sc = ScalekitClient(
env_url,
client_id,
client_secret
)
# Use the sc object to interact with the Scalekit API
auth_url = sc.get_authorization_url(
"https://acme-corp.com/redirect-uri",
state="state",
connection_id="con_123456789"
)To use the Scalekit Python SDK, you must have the following:
| Component | Version |
|---|---|
| Python | 3.8+ |
Tip: Although Python 3.8 meets the minimum requirement, using a more recent version (such as Python 3.9 or later) is advisable.
Below is a simple code sample that showcases how to implement Single Sign-on using Scalekit SDK
from fastapi import FastAPI, Request, Response
from scalekit import ScalekitClient
import uvicorn
app = FastAPI()
sc = ScalekitClient(
env_url,
client_id,
client_secret
)
redirect_uri = "http://localhost:8000/auth/callback"
@app.get("/auth/login")
async def auth_login(request: Request):
auth_url = sc.get_authorization_url(
redirect_uri,
state="state",
connection_id="con_123456789"
)
return Response(status_code=302, headers={"Location": auth_url})
@app.get("/auth/callback")
async def auth_callback(request: Request):
code = request.query_params.get("code")
token = sc.authenticate_with_code(
code,
redirect_uri
)
response = JSONResponse(content=token)
response.set_cookie("access_token", token["access_token"])
return response
if __name__ == "__main__":
uvicorn.run(app, port=8080)Explore fully functional sample applications built with popular Python frameworks and the Scalekit SDK:
| Framework | Repository | Description |
|---|---|---|
| FastAPI | scalekit-fastapi-example | Modern async Python API framework |
The example above is for Modular SSO: Scalekit brokers the OAuth exchange with your customer's own IdP via a connection_id, and your app owns its own session however it likes.
If instead Scalekit hosts your login UI and you want it to also manage the session lifecycle for you (Full Stack Auth), scalekit-sdk-python ships optional Flask, FastAPI, and Django extras that handle the encrypted session cookie, transparent token refresh, CSRF-safe login/callback, and full logout for you — no hand-rolled cookies, no manual refresh timing.
Register these under Dashboard → Authentication → Redirects before testing:
- Redirect URI — your
redirect_uri(the/callbackpath). Scalekit rejects the exchange if this doesn't match exactly. - Post Logout Redirect URI — where users land after full logout. A relative path gets auto-absolutized against the request host, but the resulting absolute URL must still be registered.
- Initiate Login URL — your
/loginpath. Scalekit redirects here (not/callback) for a bookmarked login page, an IdP portal tile, or an invite/magic link — the login view already handles this correctly, including theidp_initiated_logincase, with no extra code required.
pip install "scalekit-sdk-python[flask]" # or "scalekit-sdk-python[fastapi]" or "scalekit-sdk-python[django]"
# Flask
import os
from flask import Flask
from scalekit.frameworks.flask import ScalekitAuth
app = Flask(__name__)
auth = ScalekitAuth(
app,
env_url=os.environ["SCALEKIT_ENV_URL"],
client_id=os.environ["SCALEKIT_CLIENT_ID"],
client_secret=os.environ["SCALEKIT_CLIENT_SECRET"],
redirect_uri="https://myapp.com/callback",
cookie_encryption_secret=os.environ["COOKIE_ENCRYPTION_SECRET"], # openssl rand -base64 32
) # registers /login, /callback, /logout
@app.route("/account")
@auth.requires_auth
def account():
return {"email": auth.current_user["email"]}# FastAPI -- protect routes with Depends(), FastAPI's idiomatic mechanism
import os
from fastapi import Depends, FastAPI
from scalekit.frameworks.fastapi import ScalekitAuth
app = FastAPI()
auth = ScalekitAuth(
env_url=os.environ["SCALEKIT_ENV_URL"],
client_id=os.environ["SCALEKIT_CLIENT_ID"],
client_secret=os.environ["SCALEKIT_CLIENT_SECRET"],
redirect_uri="https://myapp.com/callback",
cookie_encryption_secret=os.environ["COOKIE_ENCRYPTION_SECRET"],
)
auth.install(app) # registers /login, /callback, /logout
@app.get("/account")
async def account(user: dict = Depends(auth.requires_auth)):
return {"email": user["email"]}# Django -- settings.py
import os
MIDDLEWARE = [..., "scalekit.frameworks.django.ScalekitAuthMiddleware"]
SCALEKIT_ENV_URL = os.environ["SCALEKIT_ENV_URL"]
SCALEKIT_CLIENT_ID = os.environ["SCALEKIT_CLIENT_ID"]
SCALEKIT_CLIENT_SECRET = os.environ["SCALEKIT_CLIENT_SECRET"]
SCALEKIT_REDIRECT_URI = "https://myapp.com/callback"
SCALEKIT_COOKIE_ENCRYPTION_SECRET = os.environ["COOKIE_ENCRYPTION_SECRET"]
# urls.py
from django.urls import include, path
urlpatterns = [path("", include("scalekit.frameworks.django")), ...] # /login, /callback, /logout
# views.py
from django.http import JsonResponse
from scalekit.frameworks.django import login_required
@login_required
def account(request):
return JsonResponse(request.scalekit_user)See examples/flask, examples/fastapi, and examples/django for complete, runnable versions. For a fuller production-oriented sample app, see the framework repos above.
- SSO Integration - Implement enterprise Single Sign-on
- Full Stack Auth - Complete authentication solution
- Passwordless Auth - Modern authentication flows
- Social Logins - Popular social identity providers
- Machine-to-Machine - API authentication
- API Reference - Complete API documentation
- Developer Kit - Tools and utilities
- API Authentication Guide - Secure API access
- Setup Guide - Initial platform configuration
- Code Examples - Ready-to-use code snippets
- Admin Portal Guide - Administrative interface
- Launch Checklist - Pre-production checklist
This project is licensed under the MIT license. See the LICENSE file for more information.