ZCore LogoZCore
Api reference

Security Services

API reference for the Security class providing Argon2id password hashing, JWT lifecycle, and cryptographic utilities.

The Security class is a unified coordinator for cryptographic and authentication operations. It provides memory-hard password hashing (Argon2id), JSON Web Token (JWT) encoding/decoding, secure hexadecimal generation, and SHA-256 digests.

Class Definition

from zcore import Security
# or: from zcore.security import Security

class Security:
    ...

Password Hashing Methods (Argon2id)

ZCore configures argon2-cffi with dynamic hardware parameter tuning (memory_cost, time_cost, parallelism) from the active Settings.

hash_password

Generates a secure Argon2id hash from a plain-text password.

@staticmethod
def hash_password(password: str) -> str: ...

Prop

Type

verify_password

Verifies a plain-text password against a stored Argon2id hash.

@staticmethod
def verify_password(plain_password: str, hashed_password: str) -> bool: ...

Prop

Type


JWT Methods

create_jwt

Creates a signed JWT access token.

@classmethod
def create_jwt(
    cls, 
    data: dict, 
    expires_delta: Optional[timedelta] = None
) -> str: ...

Prop

Type

decode_jwt

Decodes, validates the signature, and checks the expiration of a signed JWT string.

@classmethod
def decode_jwt(cls, token: str) -> dict: ...

Prop

Type

is_token_expired

Checks if a Unix timestamp expiration claim has expired against UTC current time.

@staticmethod
def is_token_expired(token_exp: int) -> bool: ...

Prop

Type

Fail-Fast Production Secret Assertion: The internal key resolver _get_signing_keys() actively asserts that if settings.DEBUG is False (Production) and settings.SECRET_KEY matches the default insecure fallback string, application startup is aborted immediately with a critical RuntimeError.


Cryptographic Utilities

generate_secure_token

Generates a cryptographically secure random hexadecimal token.

@staticmethod
def generate_secure_token(length: int = 32) -> str: ...

Prop

Type

hash_sha256

Generates a SHA-256 hex digest of the provided string data.

@staticmethod
def hash_sha256(data: str) -> str: ...

Prop

Type

On this page