Reference library

Auth & security at scale

OAuth2, JWT, IAM patterns, secrets rotation, and least-privilege service auth.

8 matches
Auth & security at scale easy

Build a Mock OIDC Userinfo Endpoint in Python with Flask

Create a local mock OIDC userinfo endpoint in Flask that returns a standard JSON user payload, ideal for testing auth flows without a real identity provider.

flask oidc userinfo
Python
from flask import Flask, jsonify

app = Flask(__name__)

@app.route("/userinfo")
def userinfo():
    mock_user = {
        "sub": "1234567890",
        "name": "John Doe",
        "email": "john@example.com",
        "email_verified": True,
        "groups": ["admin", "dev"]
    }
    return jsonify(mock_user)

if __n…
13 0 Open
Auth & security at scale easy

Fetch Secrets from a Mock Secrets Manager in Python

Build a minimal in-memory secrets manager that stores and retrieves secret values, raising a KeyError for missing names.

secrets-management security mock
Python
import json

class SecretsManager:
    """Mock secrets manager that returns secrets from a local store."""
    
    def __init__(self, store=None):
        self.store = store or {
            "api_key": "mock-api-key-123",
            "db_password": "s3cret-p@ss",
            "jwt_secret": "dev-only-secret"
        }
…
16 0 Open
Auth & security at scale easy

How to Implement an HSTS Preload List Mock in Python

Implements a mock HSTS preload list in Python that supports adding, removing, checking domains with subdomain inheritance, and listing domains.

hsts security domains
Python
import json

class HSTSPreloadList:
    def __init__(self):
        self.domains = {}

    def add_domain(self, domain, include_subdomains=False, max_age=31536000):
        self.domains[domain] = {
            "include_subdomains": include_subdomains,
            "max_age": max_age
        }

    def remove_domain(sel…
15 0 Open
Auth & security at scale easy

How to Mock a Content Security Policy Header in Python

Mock a Content-Security-Policy header locally and verify it's served correctly using Python's built-in HTTP server.

csp http-server security-headers
Python
import json
from http.server import BaseHTTPRequestHandler, HTTPServer

CSP_HEADER = "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'"

class MockServer(BaseHTTPRequestHandler):
    def do_GET(self):
        if self.path == "/":
            self.send_response(200)
            self.send_header("…
15 0 Open
Auth & security at scale easy

How to Mock a Permissions Policy in Python

A lightweight Python class that simulates a browser Permissions-Policy header by tracking allowed/ denied feature permissions with get, set, reset, and bulk operations.

permissions-policy mock security
Python
class PermissionsPolicy:
    def __init__(self):
        self._features = {
            "geolocation": "self",
            "camera": "self",
            "microphone": "self",
            "payment": "self",
            "usb": "self",
        }

    def get_feature_policy(self, feature):
        return self._features.ge…
14 0 Open
Auth & security at scale easy

How to Mock a TLS Certificate Rotation Schedule in Python

Simulate a TLS certificate rotation schedule with a Python class that tracks last and next rotation dates and decides when to rotate.

tls certificates rotation
Python
import datetime
import random
import time


class CertRotator:
    def __init__(self, cert_name, rotation_days=30):
        self.cert_name = cert_name
        self.rotation_days = rotation_days
        self.last_rotated = datetime.date.today() - datetime.timedelta(days=random.randint(10, 25))
        self.next_rotatio…
16 0 Open
Auth & security at scale easy

How to Set X-Frame-Options DENY in Flask with a Mock Response

Set the X-Frame-Options header to DENY in a Flask response to prevent clickjacking, and verify it with Flask's test client.

flask security headers
Python
from flask import Flask, Response

app = Flask(__name__)

@app.route("/")
def index():
    response = Response("Hello, World!")
    response.headers["X-Frame-Options"] = "DENY"
    return response

if __name__ == "__main__":
    with app.test_client() as client:
        resp = client.get("/")
        print(resp.get_da…
12 0 Open
Auth & security at scale easy

How to mock short TTL access tokens in Python

Simulate short-lived access tokens with a TTL, issue and validate them, and watch expiry behavior.

auth tokens expiry
Python
import time
import uuid
from datetime import datetime, timedelta


class AccessTokenManager:
    def __init__(self, ttl_seconds=30):
        self.ttl_seconds = ttl_seconds
        self.tokens = {}

    def issue_token(self):
        token_id = uuid.uuid4().hex
        expiry = datetime.now() + timedelta(seconds=self.t…
15 0 Open

Browse by section

Each section groups closely related Python snippets.

Auth & security at scale — Python code examples

What you will find here

This page collects auth & security at scale snippets — short, copy-ready Python you can paste into our free online IDE and run without installing anything. Each sample includes a plain-English explanation and the full source code.

Samples vs tutorials and challenges

Samples are quick reference — one concept per page. For step-by-step teaching, use our Python tutorials. To test yourself, try quizzes or coding challenges. Clean up style with the Python formatter.