---
title: Charmhub | Deploy Hydra using Charmhub - The Open Operator Collection
description: Deploy the latest version of Hydra as a Kubernetes Operator on any cloud.
url: https://charmhub.io/hydra/libraries/oauth
---

# Hydra

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

Platform:

stable 396

```
juju deploy hydra
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/hydra/libraries/oauth#drawer)

## charms.hydra.v0.oauth

* [*Docstrings*Docstrings](https://charmhub.io/hydra/libraries/oauth)
  [*Code*Source code](https://charmhub.io/hydra/libraries/oauth/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.hydra.v0.oauth
    ```

    [Download oauth.py](https://charmhub.io/hydra/libraries/oauth/download)
  + *Last updated* 14 Sep 2026
  + *Revision* Library version 0.14

#### Oauth Library.

> **DEPRECATED**
> This charm library is deprecated in favor of the `charmlibs-interfaces-oauth` PyPI package.
> Please install `charmlibs-interfaces-oauth` and import from `charmlibs.interfaces.oauth`.

This library is designed to enable applications to register OAuth2/OIDC
clients with an OIDC Provider through the `oauth` interface.

##### Getting started

To get started using this library you just need to fetch the library using `charmcraft`. **Note
that you also need to add `jsonschema` to your charm's `requirements.txt`.**

```
cd some-charm
charmcraft fetch-lib charms.hydra.v0.oauth
EOF
```

Then, to initialize the library:

```
# ...
from charms.hydra.v0.oauth import ClientConfig, OAuthRequirer

OAUTH = "oauth"
OAUTH_SCOPES = "openid email"
OAUTH_GRANT_TYPES = ["authorization_code"]

class SomeCharm(CharmBase):
  def __init__(self, *args):
    # ...
    self.oauth = OAuthRequirer(self, client_config, relation_name=OAUTH)

    self.framework.observe(self.oauth.on.oauth_info_changed, self._configure_application)
    # ...

    def _on_ingress_ready(self, event):
        self.external_url = "https://example.com"
        self._set_client_config()

    def _set_client_config(self):
        client_config = ClientConfig(
            urljoin(self.external_url, "/oauth/callback"),
            OAUTH_SCOPES,
            OAUTH_GRANT_TYPES,
        )
        self.oauth.update_client_config(client_config)
```

##### Provider

Besides the `client_created`/`client_changed` events, a provider can read a requirer's
published configuration at any time with `OAuthProvider.get_client_config(relation)`. It
returns `None` when the requirer has published nothing yet and raises `DataValidationError`
when what it published does not match the requirer schema. Use it to reconcile registered
clients holistically rather than relying on an event having been delivered.

Note that `client_created`/`client_changed` are not emitted when the requirer's data fails
validation; the failure is logged and the relation is skipped rather than erroring the hook.

---

Index

* [class ClientConfigError](https://charmhub.io/hydra/libraries/oauth#clientconfigerror)
* [class DataValidationError](https://charmhub.io/hydra/libraries/oauth#datavalidationerror)
* [def strtobool(
  val
  )](https://charmhub.io/hydra/libraries/oauth#strtobool)
* [class OAuthRelation](https://charmhub.io/hydra/libraries/oauth#oauthrelation)
* [class ClientConfig](https://charmhub.io/hydra/libraries/oauth#clientconfig)
* + [def validate(
    self)](https://charmhub.io/hydra/libraries/oauth#clientconfig-validate)
* + [def to\_dict(
    self)](https://charmhub.io/hydra/libraries/oauth#clientconfig-to_dict)
* [class OauthProviderConfig](https://charmhub.io/hydra/libraries/oauth#oauthproviderconfig)
* + [def from\_dict(
    cls,
    dic)](https://charmhub.io/hydra/libraries/oauth#oauthproviderconfig-from_dict)
* [class OAuthInfoChangedEvent](https://charmhub.io/hydra/libraries/oauth#oauthinfochangedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    client\_id,
    client\_secret\_id)](https://charmhub.io/hydra/libraries/oauth#oauthinfochangedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/hydra/libraries/oauth#oauthinfochangedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/hydra/libraries/oauth#oauthinfochangedevent-restore)
* [class InvalidClientConfigEvent](https://charmhub.io/hydra/libraries/oauth#invalidclientconfigevent)
* + [def \_\_init\_\_(
    self,
    handle,
    error)](https://charmhub.io/hydra/libraries/oauth#invalidclientconfigevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/hydra/libraries/oauth#invalidclientconfigevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/hydra/libraries/oauth#invalidclientconfigevent-restore)
* [class OAuthInfoRemovedEvent](https://charmhub.io/hydra/libraries/oauth#oauthinforemovedevent)
* + [def snapshot(
    self)](https://charmhub.io/hydra/libraries/oauth#oauthinforemovedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/hydra/libraries/oauth#oauthinforemovedevent-restore)
* [class OAuthRequirerEvents](https://charmhub.io/hydra/libraries/oauth#oauthrequirerevents)
* [class OAuthRequirer](https://charmhub.io/hydra/libraries/oauth#oauthrequirer)
* + [def \_\_init\_\_(
    self,
    charm,
    client\_config,
    relation\_name)](https://charmhub.io/hydra/libraries/oauth#oauthrequirer-__init__)
* + [def is\_client\_created(
    self,
    relation\_id)](https://charmhub.io/hydra/libraries/oauth#oauthrequirer-is_client_created)
* + [def get\_provider\_info(
    self,
    relation\_id)](https://charmhub.io/hydra/libraries/oauth#oauthrequirer-get_provider_info)
* + [def get\_client\_secret(
    self,
    client\_secret\_id)](https://charmhub.io/hydra/libraries/oauth#oauthrequirer-get_client_secret)
* + [def update\_client\_config(
    self,
    client\_config,
    relation\_id)](https://charmhub.io/hydra/libraries/oauth#oauthrequirer-update_client_config)
* [class ClientCreatedEvent](https://charmhub.io/hydra/libraries/oauth#clientcreatedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    redirect\_uri,
    scope,
    grant\_types,
    audience,
    token\_endpoint\_auth\_method,
    relation\_id)](https://charmhub.io/hydra/libraries/oauth#clientcreatedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/hydra/libraries/oauth#clientcreatedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/hydra/libraries/oauth#clientcreatedevent-restore)
* + [def to\_client\_config(
    self)](https://charmhub.io/hydra/libraries/oauth#clientcreatedevent-to_client_config)
* [class ClientChangedEvent](https://charmhub.io/hydra/libraries/oauth#clientchangedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    redirect\_uri,
    scope,
    grant\_types,
    audience,
    token\_endpoint\_auth\_method,
    relation\_id,
    client\_id)](https://charmhub.io/hydra/libraries/oauth#clientchangedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/hydra/libraries/oauth#clientchangedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/hydra/libraries/oauth#clientchangedevent-restore)
* + [def to\_client\_config(
    self)](https://charmhub.io/hydra/libraries/oauth#clientchangedevent-to_client_config)
* [class ClientDeletedEvent](https://charmhub.io/hydra/libraries/oauth#clientdeletedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    relation\_id)](https://charmhub.io/hydra/libraries/oauth#clientdeletedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/hydra/libraries/oauth#clientdeletedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/hydra/libraries/oauth#clientdeletedevent-restore)
* [class OAuthProviderEvents](https://charmhub.io/hydra/libraries/oauth#oauthproviderevents)
* [class OAuthProvider](https://charmhub.io/hydra/libraries/oauth#oauthprovider)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name)](https://charmhub.io/hydra/libraries/oauth#oauthprovider-__init__)
* + [def remove\_secret(
    self,
    relation)](https://charmhub.io/hydra/libraries/oauth#oauthprovider-remove_secret)
* + [def get\_client\_secret(
    self,
    relation)](https://charmhub.io/hydra/libraries/oauth#oauthprovider-get_client_secret)
* + [def get\_client\_config(
    self,
    relation)](https://charmhub.io/hydra/libraries/oauth#oauthprovider-get_client_config)
* + [def set\_provider\_info\_in\_relation\_data(
    self,
    issuer\_url,
    authorization\_endpoint,
    token\_endpoint,
    introspection\_endpoint,
    userinfo\_endpoint,
    jwks\_endpoint,
    scope,
    groups,
    ca\_chain,
    jwt\_access\_token)](https://charmhub.io/hydra/libraries/oauth#oauthprovider-set_provider_info_in_relation_data)
* + [def set\_client\_credentials\_in\_relation\_data(
    self,
    relation\_id,
    client\_id,
    client\_secret)](https://charmhub.io/hydra/libraries/oauth#oauthprovider-set_client_credentials_in_relation_data)

#### class ClientConfigError

Description

Emitted when invalid client config is provided. None

#### class DataValidationError

Description

Raised when data validation fails on relation data. None

#### def strtobool(val: str)

Convert a string representation of truth to true (1) or false (0).

Description

True values are 'y', 'yes', 't', 'true', 'on', and '1'; false values
are 'n', 'no', 'f', 'false', 'off', and '0'. Raises ValueError if
'val' is anything else.

#### class OAuthRelation

Description

A class containing helper methods for oauth relation. None

Methods

#### class ClientConfig

Description

Helper class containing a client's configuration. None

Methods

ClientConfig.
validate(

*self*
)

Description

Validate the client configuration. None

ClientConfig.
to\_dict(

*self*
)

Description

Convert object to dict. None

#### class OauthProviderConfig

Description

Helper class containing provider's configuration. None

Methods

OauthProviderConfig.
from\_dict(

cls

,
dic: Dict
)

Description

Generate OauthProviderConfig instance from dict. None

#### class OAuthInfoChangedEvent

Description

Event to notify the charm that the information in the databag changed. None

Methods

OAuthInfoChangedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
client\_id: str

,
client\_secret\_id: str
)

OAuthInfoChangedEvent.
snapshot(

*self*
)

Description

Save event. None

OAuthInfoChangedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class InvalidClientConfigEvent

Description

Event to notify the charm that the client configuration is invalid. None

Methods

InvalidClientConfigEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
error: str
)

InvalidClientConfigEvent.
snapshot(

*self*
)

Description

Save event. None

InvalidClientConfigEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class OAuthInfoRemovedEvent

Description

Event to notify the charm that the provider data was removed. None

Methods

OAuthInfoRemovedEvent.
snapshot(

*self*
)

Description

Save event. None

OAuthInfoRemovedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class OAuthRequirerEvents

Description

Event descriptor for events raised by `OAuthRequirerEvents`. None

#### class OAuthRequirer

Description

Register an oauth client. None

Methods

OAuthRequirer.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
client\_config

,
relation\_name: str
)

OAuthRequirer.
is\_client\_created(

*self*

,
relation\_id
)

Description

Check if the client has been created. None

OAuthRequirer.
get\_provider\_info(

*self*

,
relation\_id
)

Description

Get the provider information from the databag. None

OAuthRequirer.
get\_client\_secret(

*self*

,
client\_secret\_id: str
)

Description

Get the client\_secret. None

OAuthRequirer.
update\_client\_config(

*self*

,
client\_config: ClientConfig

,
relation\_id
)

Description

Update the client config stored in the object. None

#### class ClientCreatedEvent

Description

Event to notify the Provider charm to create a new client. None

Methods

ClientCreatedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
redirect\_uri: str

,
scope: str

,
grant\_types

,
audience: List

,
token\_endpoint\_auth\_method: str

,
relation\_id: int
)

ClientCreatedEvent.
snapshot(

*self*
)

Description

Save event. None

ClientCreatedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

ClientCreatedEvent.
to\_client\_config(

*self*
)

Description

Convert the event information to a ClientConfig object. None

#### class ClientChangedEvent

Description

Event to notify the Provider charm that the client config changed. None

Methods

ClientChangedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
redirect\_uri: str

,
scope: str

,
grant\_types: List

,
audience: List

,
token\_endpoint\_auth\_method: str

,
relation\_id: int

,
client\_id: str
)

ClientChangedEvent.
snapshot(

*self*
)

Description

Save event. None

ClientChangedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

ClientChangedEvent.
to\_client\_config(

*self*
)

Description

Convert the event information to a ClientConfig object. None

#### class ClientDeletedEvent

Description

Event to notify the Provider charm that the client was deleted. None

Methods

ClientDeletedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
relation\_id: int
)

ClientDeletedEvent.
snapshot(

*self*
)

Description

Save event. None

ClientDeletedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class OAuthProviderEvents

Description

Event descriptor for events raised by `OAuthProviderEvents`. None

#### class OAuthProvider

Description

A provider object for OIDC Providers. None

Methods

OAuthProvider.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str
)

OAuthProvider.
remove\_secret(

*self*

,
relation: Relation
)

OAuthProvider.
get\_client\_secret(

*self*

,
relation: Relation
)

Return the client secret currently shared with the requirer, if there is one.

Description

Re-registering a client with this value keeps the requirer working: writing a
different secret would cut a new revision that the requirer does not track.

OAuthProvider.
get\_client\_config(

*self*

,
relation: Relation
)

Read the requirer's client configuration from the integration databag.

Description

Returns None when the requirer has not published its configuration yet.

OAuthProvider.
set\_provider\_info\_in\_relation\_data(

*self*

,
issuer\_url: str

,
authorization\_endpoint: str

,
token\_endpoint: str

,
introspection\_endpoint: str

,
userinfo\_endpoint: str

,
jwks\_endpoint: str

,
scope: str

,
groups

,
ca\_chain

,
jwt\_access\_token
)

Description

Put the provider information in the databag. None

OAuthProvider.
set\_client\_credentials\_in\_relation\_data(

*self*

,
relation\_id: int

,
client\_id: str

,
client\_secret: str
)

Description

Put the client credentials in the databag. None
