如何在Authlib中关闭SSL检查?本地HTTP IDP开发场景求助
Great question—you’re absolutely right that commenting out core library code isn’t the most clean or maintainable solution. Authlib actually provides built-in, safe ways to disable SSL checks specifically for local development scenarios like yours. Here are the two recommended approaches:
1. Disable SSL Verification Per Client Instance
The most targeted way is to pass the verify parameter directly when initializing your OAuth2 client. This applies the setting only to that specific client, keeping other parts of your code secure.
For Raw OAuth2Session:
from authlib.integrations.requests_client import OAuth2Session # Initialize the session with SSL verification disabled client = OAuth2Session( client_id="your-local-client-id", client_secret="your-local-client-secret", verify=False # This skips SSL checks for this client )
For Framework Integrations (Flask/Django):
If you’re using Authlib’s framework-specific integrations, add the verify flag to the client_kwargs when registering your IDP:
# Flask example from authlib.integrations.flask_client import OAuth oauth = OAuth(app) oauth.register( name="local-idp", client_id="your-client-id", client_secret="your-client-secret", authorize_url="http://your-local-idp/authorize", access_token_url="http://your-local-idp/token", client_kwargs={"verify": False} # Disable SSL checks here )
2. Global Disable via Environment Variable (For All Clients)
If you need to disable SSL verification across all Authlib clients in your dev environment, use the official AUTHLIB_INSECURE_TRANSPORT environment variable. This is a purpose-built flag for testing with HTTP endpoints.
Set in Terminal:
export AUTHLIB_INSECURE_TRANSPORT=1
Set in Python Code:
Add this before initializing any Authlib clients (make sure this only runs in development!):
import os # Only enable this in development if os.environ.get("FLASK_ENV") == "development": os.environ["AUTHLIB_INSECURE_TRANSPORT"] = "1"
Critical Note:
Never use these settings in production environments. SSL verification is essential for securing OAuth2 transactions, and disabling it exposes your application to man-in-the-middle attacks. These methods are strictly intended for local testing with trusted, HTTP-only IDPs.
These approaches are far better than modifying Authlib’s source code because they’re explicit, maintainable, and won’t break when you update the library in the future.
内容的提问来源于stack exchange,提问作者Anakin Hao

