pyevp

Relying-party verification for the Email Verification Protocol (EVP).

With EVP, the browser obtains a token from the user’s email provider proving that the user controls an address, and puts it in your sign-up or sign-in form. This library verifies that token on your server, so no confirmation email round-trip is needed.

Warning

Alpha. The protocol (draft-hardt-email-verification, WICG Email Verification API) and browser support (Chrome origin trial) are still changing. Every moving part is isolated in a versioned profile, so the library can follow along without silent behaviour changes.

  • Typed: frozen dataclasses, protocols and stable error codes.

  • Sync and async from one core: the verification logic does no I/O itself; thin drivers serve Django and FastAPI alike.

  • Testable: pyevp.testing ships a fake issuer and a fake browser, so your application’s tests need no network access.

  • Small: the only required dependencies are joserfc and idna; DNS and HTTP are pluggable.