litestar-security
Installation
SKILL.md
Litestar Security
litestar-security 0.6.0 is a declarative authentication and authorization framework for Litestar. It provides credential slots and mechanisms, unified session management, local accounts, MFA, WebAuthn passkeys, OAuth/OIDC, API keys, workload JWTs, and browser hardening.
Two separate axes, wired through two separate Litestar keywords:
- Authentication — who is calling — is a policy on
auth=(oropt={"auth": ...}). - Authorization — what they may do — is a predicate in Litestar's native
guards=[...].
Do not conflate them: the policy helpers (public, required, any_of, all_of, at_least, optional, exclude, mechanism) take mechanism names, while the guard combinators (requires_any_of, requires_all_of, requires_at_least, requires_one_of) take predicates.