Documentation

FastAPI

FastAPI authentication and bypass

Combine Access402 payments with application authentication and trusted internal bypass rules.
Last reviewed August 9, 2026

Separate responsibilities

Access402 decides whether a matching resource requires payment and whether that payment or grant is valid. Your application still owns user authentication, tenant authorization, roles, and business permissions.

Trusted bypass callback

Pass a callback when authenticated internal users should bypass payment:

async def trusted_internal_request(scope):
    user = scope.get("state", {}).get("user")
    return bool(user and user.is_admin)

Access402.from_env(bypass=trusted_internal_request).install(app)

The callback receives the ASGI scope and must base its decision on authentication state your application has already verified.

Middleware order

If the callback reads state populated by authentication middleware, ensure authentication runs before the Access402 bypass decision. Test middleware order with an authenticated internal request and an unauthenticated external request.

Unsafe bypass patterns

Never bypass based only on a client-supplied header, query parameter, cookie value that has not been verified, source IP without trusted-proxy handling, or a claimed administrator email in the request.