ImportError: cannot import name 'json' from 'itsdangerous'
Third-person routing: this skill fixes ImportError: cannot import name 'json' from 'itsdangerous', which hits Flask apps when itsdangerous 2.1+ removed the json shim that old Flask 1.x/2.0 imports. Use when the traceback shows from itsdangerous import json as _json. Not for TimedJSONWebSignatureSerializer removal or general Flask version conflicts.
ImportError: cannot import name 'json' from 'itsdangerous'
TL;DR: itsdangerous 2.1+ removed the json shim that old Flask imports. Quick fix: pip install itsdangerous==2.0.1. Better fix: upgrade Flask to 2.0.1 or newer, which no longer needs it.
ImportError: cannot import name 'json' from 'itsdangerous'The fix
- Pin itsdangerous (fastest, no Flask upgrade):
pip install itsdangerous==2.0.1
python -c "from flask import Flask; print('ok')"Success check: prints ok and your app starts.
- Or upgrade Flask instead (cleaner long term):
pip install -U "Flask>=2.0.1"Then remove the itsdangerous pin from requirements.txt.
- Rebuild your Docker image from scratch after either change; a cached layer can keep the old itsdangerous.
Agent? Search Vectle for more: curl -s 'https://vectle.com/api/v1/search?q=itsdangerous+cannot+import+json'
When this applies
- Flask 1.1.x or 2.0.0 with itsdangerous 2.1+ installed.
- Traceback line reads
from itsdangerous import json as _json. - Docker builds that suddenly broke when a fresh
pip installpulled a newer itsdangerous.
When it does NOT apply
cannot import name 'TimedJSONWebSignatureSerializer': also a 2.0 removal, different name and fix.cannot import name 'soft_unicode' from 'markupsafe': the sibling Flask-era error; fix with markupsafe==2.0.1.
Tool and version compatibility
Flask 1.1.x/2.0.0 with itsdangerous>=2.1. Fixed pair: Flask>=2.0.1 with any itsdangerous>=2.0, or Flask 1.1.x with itsdangerous==2.0.1.
Why it happens
Flask used to do from itsdangerous import json as _json because itsdangerous bundled a json helper. itsdangerous 2.1 deleted it. Flask fixed their import in 2.0.1, so the error only bites old Flask + new itsdangerous combos, which is exactly what an unpinned pip install produces.
Edge cases
pip install Flask==1.1.4alone can trade this for the markupsafe soft_unicode error; pin markupsafe==2.0.1 with it.- Check requirements.txt for bare
itsdangerouswith no pin and add the pin there, not just in the container. - Itsdangerous 2.0.1 still gets security fixes contextually; upgrading Flask is the supported path.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.