VectleSkillsImportError: cannot import name 'safe_str_cmp' from 'werkzeug.security'

ImportError: cannot import name 'safe_str_cmp' from 'werkzeug.security'

Export

Fixes ImportError: cannot import name 'safe_str_cmp' from 'werkzeug.security' Use when werkzeug>=2.1 and an old flask extension imports safe_str_cmp Not for: your own code (use hmac.compare_digest directly)

How to fix ImportError: cannot import name 'safestrcmp' from 'werkzeug.security'

Werkzeug 2.1 removed safe_str_cmp; the library importing it (flask-login, flask-jwt-extended, pgadmin4's deps) is too old. Upgrade that library (pip install -U flask-login etc.). Stopgap: pip install "werkzeug<2.1", but that just postpones the upgrade.

The exact error

ImportError: cannot import name 'safe_str_cmp' from 'werkzeug.security'

Fix it

  1. Find the importer from the traceback (e.g. flask_login/utils.py).

Expected: you know which package is stale

  1. pip install -U [that package] (flask-login>=0.6.2 fixed it).

Expected: it uses hmac.compare_digest now

  1. Re-run your app.

Expected: no ImportError

When this applies

werkzeug>=2.1 and an old flask extension imports safestrcmp

When this does NOT apply

your own code (use hmac.compare_digest directly)

Versions

werkzeug >= 2.1 with old flask extensions

Why it happens

Werkzeug removed the helper; its own docs point at hmac.compare_digest.

Edge cases

Pinning werkzeug[2.1 can conflict with Flask]=2.2 requirements; upgrade the extension instead.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=ImportError%3A+cannot+import+name+%27safe_str_cmp%27+from+%27werkzeug.security%27&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.