Install & Compatibility
Where this runs
tested against v0.5.0 · pip install
no network on importno background threads
Install × environment matrix
Each cell = how many times install + import succeeded across repeated harness runs. Partial = flaky.
glibc = Debian/Ubuntu slim · musl = Alpine Linux
muslpy 3.10–3.920 runs
installs and imports cleanly · install 0.0s · import 0.000s · 27.8MB
glibcpy 3.10–3.920 runs
installs and imports cleanly · install 4.1s · import 0.000s · 30MB
27MB installed
● package 27MB
Code
Verified usage
Verified import paths — ran on the pinned version, not inferred.
JwtVerifier
✓ from okta_jwt_verifier import JwtVerifier
✗ from okta_jwt_verifier import JwtVerifier
This quickstart demonstrates how to initialize the `JwtVerifier` and verify an Okta Access Token. Remember to replace the placeholder environment variables (or directly set the values) with your actual Okta Org URL, API Audience, and a real JWT token for successful verification. The `verify_access_token` method is asynchronous and must be awaited.
import os
import asyncio
from okta_jwt_verifier import JwtVerifier
from okta_jwt_verifier.exceptions import InvalidTokenException, MissingIssuerException, MissingAudienceException
# --- Configuration (replace with your actual Okta values) ---
# Your Okta Org URL, e.g., 'https://dev-12345678.okta.com'
OKTA_ORG_URL = os.environ.get('OKTA_ORG_URL', 'https://dev-12345678.okta.com')
# The audience identifier for your API, e.g., 'api://default' or a specific Client ID
OKTA_AUDIENCE = os.environ.get('OKTA_AUDIENCE', 'api://default')
# An example JWT token. FOR SUCCESSFUL VERIFICATION, replace this with a real Okta Access Token.
# This placeholder token is designed to match the default issuer/audience but will have an invalid signature.
EXAMPLE_JWT_TOKEN = os.environ.get('EXAMPLE_JWT_TOKEN', 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyLCJleHAiOjQ4MjE5MzkyMDAsImF1ZCI6ImFwaTovL2RlZmFhdWx0IiwiaXNzIjoiaHR0cHM6Ly9kZXYtMTIzNDU2NzguT2t0YS5jb20ifQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c')
async def verify_token_example():
if 'dev-12345678.okta.com' in OKTA_ORG_URL or OKTA_AUDIENCE == 'api://default':
print("WARNING: Using placeholder values. For successful verification, set real OKTA_ORG_URL and OKTA_AUDIENCE environment variables.")
if EXAMPLE_JWT_TOKEN == 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyLCJleHAiOjQ4MjE5MzkyMDAsImF1ZCI6ImFwaTovL2RlZmFhdWx0IiwiaXNzIjoiaHR0cHM6Ly9kZXYtMTIzNDU2NzguT2t0YS5jb20ifQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c':
print("WARNING: Using a dummy JWT token. Verification will likely fail with 'Invalid signature' or similar errors. Set EXAMPLE_JWT_TOKEN environment variable.")
print(f"\nAttempting to verify token with:\n Issuer: {OKTA_ORG_URL}\n Audience: {OKTA_AUDIENCE}")
try:
# Initialize the verifier with your Okta issuer and expected audience
jwt_verifier = JwtVerifier(
issuer=OKTA_ORG_URL,
audience=OKTA_AUDIENCE
)
# Use verify_access_token for access tokens or verify_id_token for ID tokens
verified_claims = await jwt_verifier.verify_access_token(EXAMPLE_JWT_TOKEN)
print("\nJWT Token successfully verified!")
print(f"Claims: {verified_claims}")
except (InvalidTokenException, MissingIssuerException, MissingAudienceException) as e:
print(f"\nJWT Token verification failed: {e}")
print("Please ensure your OKTA_ORG_URL, OKTA_AUDIENCE, and EXAMPLE_JWT_TOKEN are correctly configured and valid.")
except Exception as e:
print(f"\nAn unexpected error occurred during verification: {e}")
if __name__ == "__main__":
asyncio.run(verify_token_example())
Upgrade
Version history
0.5.0latest on PyPI · released May 12, 2026
Audit
Dependencies
PyJWTrequiredCore dependency for JWT parsing and validation.
requestsrequiredUsed for fetching JWKS (JSON Web Key Set) from the Okta issuer.
cryptographyrequiredProvides cryptographic primitives for JWT signature verification.