## smtp.OAuth


An OAuth credential authenticates to SMTP with an access token instead of a password, through XOAUTH2.


Usage

``` python
smtp.OAuth(
    username,
    credential,
    scope=None,
)
```


[connect()](Backend.md#epistole.Backend.connect) gets one token from `credential`, and sends it with `username` through `smtplib.SMTP.auth`. It sends no token to a server that does not offer `AUTH XOAUTH2`, and raises [AuthenticationError](exceptions.AuthenticationError.md#epistole.exceptions.AuthenticationError) instead.

Epistole derives the scope from the issuer. A [graph.ClientSecret](graph.ClientSecret.md#epistole.graph.ClientSecret) or [graph.Certificate](graph.Certificate.md#epistole.graph.Certificate) requests `https://outlook.office365.com/.default`. A [graph.ManagedIdentity](graph.ManagedIdentity.md#epistole.graph.ManagedIdentity) requests the resource `https://outlook.office365.com` instead, because `msal`'s managed identity client takes no scope. A Gmail value requests `https://mail.google.com/`, which Gmail requires though it also grants reading and deleting every message. Epistole cannot read the issuer of a [TokenCredential](TokenCredential.md#epistole.TokenCredential), so it takes `scope` instead. See ADR-0011.


## Attributes


`username: str`  
The mailbox the token belongs to, sent as XOAUTH2's `user`. `smtplib` encodes it as ASCII, so [connect()](Backend.md#epistole.Backend.connect) raises `UnicodeEncodeError` for any other character.

`credential: (`\
`    graph.ClientSecret`\
`    | graph.Certificate`\
`    | graph.ManagedIdentity`\
`    | gmail.ServiceAccount`\
`    | gmail.AuthorizedUser`\
`    | TokenCredential`\
`)`  
A value from `epistole.graph` or `epistole.gmail`, or a [TokenCredential](TokenCredential.md#epistole.TokenCredential).

`scope: str | None`  
The scope a [TokenCredential](TokenCredential.md#epistole.TokenCredential)'s [get_token](TokenCredential.md#epistole.TokenCredential.get_token) receives. It is required with a [TokenCredential](TokenCredential.md#epistole.TokenCredential), and [OAuth](smtp.OAuth.md#epistole.smtp.OAuth) raises `TypeError` for it with any other credential.


## Methods

| Name | Description |
|----|----|
| [__post_init__()](#__post_init__) | Raise `TypeError` for a credential of another type, for a [TokenCredential](TokenCredential.md#epistole.TokenCredential) without `scope`, or for any other credential with it (ADR-0011). |

------------------------------------------------------------------------


#### \_\_post_init\_\_()


Raise `TypeError` for a credential of another type, for a [TokenCredential](TokenCredential.md#epistole.TokenCredential) without `scope`, or for any other credential with it (ADR-0011).


Usage

``` python
__post_init__()
```
