Metadata-Version: 2.4
Name: mlflow-oidc-auth
Version: 8.4.0
Summary: Authentication and access control for MLflow: SSO (OIDC, SAML), SCIM provisioning and per-resource permissions
Maintainer-email: Alexander Kharkevich <alex@kharkevich.org>
License-Expression: Apache-2.0
Project-URL: homepage, https://github.com/mlflow-oidc/mlflow-oidc-auth
Project-URL: issues, https://github.com/mlflow-oidc/mlflow-oidc-auth/issues
Project-URL: documentation, https://github.com/mlflow-oidc/mlflow-oidc-auth/tree/main/docs/
Project-URL: repository, https://github.com/mlflow-oidc/mlflow-oidc-auth
Keywords: mlflow,access-control,authentication,authorization,oidc,oauth2,saml,scim,sso,rbac
Classifier: Development Status :: 5 - Production/Stable
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: End Users/Desktop
Classifier: Intended Audience :: Science/Research
Classifier: Intended Audience :: Information Technology
Classifier: Topic :: Scientific/Engineering :: Artificial Intelligence
Classifier: Topic :: Software Development :: Libraries :: Python Modules
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3.10
Requires-Python: >=3.10
Description-Content-Type: text/markdown
License-File: LICENSE
Requires-Dist: mlflow<4,>=3.14.0
Requires-Dist: python-dotenv<2
Requires-Dist: requests<3,>=2.32.5
Requires-Dist: truststore>=0.10
Requires-Dist: sqlalchemy<3,>=2.0.46
Requires-Dist: flask<4
Requires-Dist: gunicorn<24; platform_system != "Windows"
Requires-Dist: alembic!=1.18.4,<2
Requires-Dist: authlib<2,>=1.8
Requires-Dist: joserfc<2,>=1.7
Requires-Dist: uvicorn>=0.41.0
Requires-Dist: fastapi>=0.132.0
Requires-Dist: asgiref>=3.11.1
Requires-Dist: httpx2>=2.0.0
Requires-Dist: cachetools>=5.5.0
Provides-Extra: dev
Requires-Dist: black<26,>=24.8.0; extra == "dev"
Requires-Dist: pytest<9,>=8.3.2; extra == "dev"
Requires-Dist: pre-commit<5; extra == "dev"
Requires-Dist: autoflake<2; extra == "dev"
Provides-Extra: test
Requires-Dist: pytest<9,>=8.3.2; extra == "test"
Requires-Dist: pytest-cov<6,>=5.0.0; extra == "test"
Requires-Dist: pytest-asyncio<2; extra == "test"
Requires-Dist: httpx2<3,>=2.0.0; extra == "test"
Provides-Extra: aws
Requires-Dist: boto3>=1.42.26; extra == "aws"
Provides-Extra: azure
Requires-Dist: azure-identity>=1.25.1; extra == "azure"
Requires-Dist: azure-keyvault-secrets>=4.10.0; extra == "azure"
Provides-Extra: vault
Requires-Dist: hvac>=2.4.0; extra == "vault"
Provides-Extra: saml
Requires-Dist: python3-saml<2,>=1.16.0; extra == "saml"
Requires-Dist: xmlsec<2,>=1.3.14; extra == "saml"
Provides-Extra: cloud
Requires-Dist: boto3>=1.42.26; extra == "cloud"
Requires-Dist: azure-identity>=1.25.1; extra == "cloud"
Requires-Dist: azure-keyvault-secrets>=4.10.0; extra == "cloud"
Requires-Dist: hvac>=2.4.0; extra == "cloud"
Provides-Extra: full
Requires-Dist: boto3>=1.42.26; extra == "full"
Requires-Dist: azure-identity>=1.25.1; extra == "full"
Requires-Dist: azure-keyvault-secrets>=4.10.0; extra == "full"
Requires-Dist: hvac>=2.4.0; extra == "full"
Requires-Dist: python3-saml<2,>=1.16.0; extra == "full"
Requires-Dist: xmlsec<2,>=1.3.14; extra == "full"
Provides-Extra: cache
Requires-Dist: redis<6,>=5.0.0; extra == "cache"
Dynamic: license-file

# MLflow Access Control (`mlflow-oidc-auth`)
[![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)
[![PyPI Downloads](https://static.pepy.tech/badge/mlflow-oidc-auth/month)](https://pepy.tech/projects/mlflow-oidc-auth)
[![Ask DeepWiki](https://deepwiki.com/badge.svg)](https://deepwiki.com/mlflow-oidc/mlflow-oidc-auth)

Authentication and access control for MLflow tracking servers: single sign-on (OIDC, SAML 2.0), SCIM user and group provisioning, service accounts, and per-resource permissions for users, groups and workspaces.

It is an MLflow server plugin, installed as `mlflow-oidc-auth` and started with `--app-name oidc-auth`. The package keeps its original name; it has long since grown beyond OIDC.

## Disclaimer

This project is not affiliated with, endorsed by, or sponsored by the MLflow Project, Databricks, the Linux Foundation, or LF Projects, LLC.
MLflow and related marks are trademarks of their respective owners.
Maintained by Kharkevich Engineering Lab.

### Features
- **Single sign-on** for the MLflow UI and API through any OpenID Connect provider (confidential or PKCE public clients) or SAML 2.0 identity provider, with several providers side by side
- **Programmatic access**: automation authenticates with short-lived workload identities — Kubernetes service-account tokens or IdP client-credentials / workload-identity tokens (JWT bearer); people using the MLflow client from a laptop or notebook use named personal access tokens (basic auth). See [Programmatic access](docs/programmatic-access.md)
- **SCIM 2.0 provisioning** of users and groups from your directory
- **Permissions** (READ, USE, EDIT, MANAGE) on experiments, registered models, prompts, scorers and AI Gateway resources, granted to users, groups or regex patterns, with deny by default
- **Workspaces** for multi-tenant isolation on a shared MLflow server
- **Admin UI** for users, groups, service accounts, permissions, workspaces, webhooks and trash
- **Operations**: server-side sessions, audit log, health probes, Redis-backed permission cache, and secrets from AWS, Azure, HashiCorp Vault or Kubernetes

### Documentation

For detailed documentation, please refer to the [docs](https://mlflow-oidc.github.io/mlflow-oidc-auth/). AI generated documentation is available at [DeepWiki](https://deepwiki.com/mlflow-oidc/mlflow-oidc-auth).

## Quick Start

To get the full version (with entire MLflow and all dependencies), run:
```bash
python3 -m venv venv
source venv/bin/activate
python3 -m pip install mlflow-oidc-auth[full]
mlflow server --app-name oidc-auth --host 0.0.0.0 --port 8080
```

## Webhook secret encryption key 🔐

Webhook secrets are stored encrypted in the database using a Fernet key. If you plan to use MLflow webhooks with secrets, set the encryption key in the environment variable `MLFLOW_WEBHOOK_SECRET_ENCRYPTION_KEY` before creating any webhooks. Generate a key with:

```bash
MLFLOW_WEBHOOK_SECRET_ENCRYPTION_KEY=$(python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())")
export MLFLOW_WEBHOOK_SECRET_ENCRYPTION_KEY
```

Important: keep this key stable across application restarts and replicas. If the key is lost or changed after webhooks are created, previously stored secrets cannot be decrypted and will cause webhook listing to fail until you restore the original key or remove/rotate the affected webhook secrets.


## Development

For development quick start, please refer to the [Development and Contribution](docs/development.md) section.
Contribution guidelines are available in [CONTRIBUTING.md](CONTRIBUTING.md).

## License

Apache 2 Licensed. For more information, please see [LICENSE](https://github.com/mlflow-oidc/mlflow-oidc-auth?tab=Apache-2.0-1-ov-file).

### Based on MLflow basic-auth plugin
https://github.com/mlflow/mlflow/tree/master/mlflow/server/auth
