# Flask-AppBuilder: the scaffolding that grew up under Superset and Airflow

> Flask-AppBuilder is a BSD-licensed rapid application development framework built on Flask, generating CRUD views, REST APIs, menus, forms and Google charts from SQLAlchemy models, with role based security that harvests permissions from exposed methods. Its best known consumers are the Superset data exploration platform and the Airflow workflow platform, and the current release line is 5.2.3.

**dpgaspar/Flask-AppBuilder** — Simple and rapid application development framework, built on top of Flask. includes detailed security, auto CRUD generation for your models, google charts and much more. Demo (login with guest/welcome) - http://flaskappbuilder.pythonanywhere.com/

- Repository: https://github.com/dpgaspar/Flask-AppBuilder
- Stars: 4,964 · Forks: 1,443
- Language: Python
- License: BSD-3-Clause
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/dpgaspar-flask-appbuilder

## The scaffolding under Superset and Airflow

Flask-AppBuilder, FAB for short, is a simple and rapid application development framework built on top of Flask, and its adoption list is its strongest reference. The Superset data exploration platform, designed to be visual, intuitive and interactive, and the Airflow platform for programmatically authoring, scheduling and monitoring workflows, are both built on it, which means a large fraction of the data engineering world has interacted with FAB screens without knowing the framework's name. Organizations listed as users include Miniclip, EuroBIC and On Beat Digital. The project is BSD-3-Clause, authored by Daniel Vaz Gaspar, supports Python 3.8 through 3.12 per its badge, styles its code with black, and releases steadily, v5.2.3 on 2026-09-16, v5.2.2 on 2026-06-23 and v5.2.1 on 2026-06-05, with the last push on 2026-09-16. A live demo runs at flaskappbuilder.pythonanywhere.com with guest and welcome credentials. Documentation is hosted on Read the Docs, and the framework's stated design goal is extensive configuration of all functionality while integrating easily with normal Flask and Jinja2 development, so existing templates and routes keep working alongside the generated pieces.

## Permissions harvested from exposed methods

The security model starts from the code rather than from a configuration file. Automatic permissions lookup works from the exposed methods on your views, and the framework inserts into the database all the detailed permissions possible on your application, then grants them all to the Admin Role. Permissions can be public, requiring no authentication, or private, and access control is role based on top of that inventory. The practical effect is that adding a view method creates its permission records, and administering access means assigning those records to roles in a UI rather than hand writing an authorization matrix. The README's screenshots show the security screens, a list of permissions joined to roles, and the framework also supports self user registration so accounts can be created without an administrator in the loop when the application allows it.

## Five doors in: OAuth, OpenID, Database, LDAP, REMOTE_USER

Authentication support covers the five mechanisms a Flask deployment realistically meets, OAuth, OpenID, database accounts, LDAP, and the REMOTE_USER environment variable for front end proxy authentication. The login screenshots demonstrate at least two of them side by side, one for AUTH_DB and one for AUTH_OAUTH, showing the same framework rendering different login flows. The development environment takes the claim seriously enough to ship containers for the harder cases, a docker-compose file standing up PostgreSQL 14 with max_connections raised to 500 on one side and an OpenLDAP server on port 1389 with the memberof schema loaded on the other, so LDAP integration has something real to talk to during development and testing. For API consumers, the REST layer integrates flask-jwt-extended to protect endpoints with JSON web tokens instead of sessions.

## CRUD from model to menu, list, form and chart

The view layer is where the rapid in rapid application development lives. Menu generation is automatic, CRUD generation is automatic, and database records support multiple actions beyond edit and delete. Lists come with a big variety of filters in the framework's own words, and view widgets cover lists, master-detail layouts and thumbnail grids. The widget toolbox includes Select2 dropdowns, Datepicker and DateTimePicker, with related Select2 fields for foreign key picks. Charts are Google charts with automatic group by or direct values and filters, and the screenshots show the three chart shapes, a group by pie chart, a direct time chart, and a group by time chart. An AddOn system lets teams write their own view components and contribute them back, so the widget catalogue is meant to grow beyond what ships.

## A REST API with its own metadata layer

The CRUD REST API features are generated with the same model-first philosophy. RESTful endpoints arrive automatically for each model, internationalized, with integration to flask-jwt-extended for endpoint protection. The interesting part is the metadata contract, the API publishes metadata for dynamic rendering, supports selectable columns and metadata keys, and applies automatic and configurable data validation. The dependency list in setup.py shows the machinery behind that contract, marshmallow with marshmallow-sqlalchemy for serialization against models, apispec with yaml for API specifications, jsonschema for validation, and prison for query parameter parsing. The result is an API a generic client can render against, column names, types and validation rules arriving from the server rather than being mirrored by hand in frontend code. Selectable columns also mean a single endpoint can serve different consumers, a mobile client requesting a narrow projection and a table view requesting the full set, without duplicating serializers.

## Forms read the model, Django style field sets included

Forms are generated in all three life cycle shapes, Add, Edit and Show, straight from the database models. Each field can carry labels and descriptions, and base validators come from the model's definition automatically, with custom validators, extra fields and custom filters for related dropdown lists available where the model does not say enough. Image and file support handles upload and database field association, and the README's promise is sweeping, it will handle everything for you. Field sets arrive Django style, letting a long form be grouped into sections rather than one scrolling page. The foundation under all of it is Flask-WTF with WTForms, one of the eight dependencies the README lists, and the frontend dressing is Bootstrap 3.1.1 CSS and JavaScript with Font-Awesome icons for menus and actions.

## Vertical partitioning and the audit mixin

The database layer is SQLAlchemy throughout, with multiple database support spanning sqlite, MySQL, Oracle, MSSQL and DB2, and partial support for MongoDB through MongoEngine. Multiple database connections are supported through vertical partitioning, so different model groups can live on different engines inside one application. A small but telling convenience is the audit mixin, an easy mixin that adds created and changed by user tracking plus timestamps to any model, the four columns compliance minded applications end up adding by hand everywhere. The setup.py constraints keep the foundation current, Flask at 2 or 3, SQLAlchemy at 1.4 or 2.x, Flask-SQLAlchemy from 2.4 up, plus Flask-Limiter for rate limiting and Flask-Babel for translations, with python-dateutil handling date parsing.

## A fab command, twenty five examples, and Babel

The package installs a Flask CLI extension named fab, registered through the flask.commands entry point to flask_appbuilder.cli, so subcommands like security and database operations run under the standard flask tool rather than a separate binary. Internationalization goes through Babel with a babel directory holding the translations, and the repository carries a readthedocs configuration, tox for multi environment testing and a coverage setup. The examples directory is the real documentation layer, twenty five plus projects covering base_api, crud_rest_api, composite_keys, enums, extendsecurity in two flavors, factoryapp, masterdetail, mongoengine, oauth, quickactions, quickcharts in two flavors, quickfiles, quickimages, four quickhowto variants and quickmigrate. The README points to a YouTube installation video and a Google group and Gitter for support, with contributions welcomed through issues and forks.

## Conclusion

Choose Flask-AppBuilder when a Flask project needs admin style CRUD, role based permissions and a REST layer generated from the same SQLAlchemy models, and the Django batteries included approach is attractive without moving off Flask. Choose plain Flask or a lighter extension set when the application is an API or a bespoke frontend and generated list views would just be in the way. Before adopting, check the frontend baseline against your expectations, the shipped UI is Bootstrap 3.1.1 with Select2 and DatePicker, verify your Python version falls in the 3.8 to 3.12 badge range, and walk the twenty plus examples directory, since patterns like composite keys, MongoEngine and OAuth integrations are demonstrated there rather than exhaustively documented.

## FAQ

### what is flask appbuilder?

Flask-AppBuilder is a BSD-licensed simple and rapid application development framework built on top of Flask, providing detailed security with role based permissions, automatic CRUD generation for SQLAlchemy models, Google charts, automatic menus, forms and REST APIs. A demo runs at flaskappbuilder.pythonanywhere.com with guest and welcome login credentials.

### Which projects are built on Flask-AppBuilder?

The README lists Superset, a data exploration platform designed to be visual, intuitive and interactive, and Airflow, a platform to programmatically author, schedule and monitor workflows. Organizations listed as users include Miniclip, EuroBIC and On Beat Digital.

### What authentication methods does Flask-AppBuilder support?

Authentication support covers OAuth, OpenID, database accounts, LDAP, and the REMOTE_USER environment variable, with self user registration also supported. The REST layer can protect endpoints with flask-jwt-extended, and the development docker-compose file stands up PostgreSQL and OpenLDAP containers for testing the database and LDAP paths.

## Sources

- [dpgaspar/Flask-AppBuilder on GitHub](https://github.com/dpgaspar/Flask-AppBuilder)
- [Issues](https://github.com/dpgaspar/Flask-AppBuilder/issues)
- [License: BSD-3-Clause](https://github.com/dpgaspar/Flask-AppBuilder/blob/master/LICENSE)
- [README](https://github.com/dpgaspar/Flask-AppBuilder/blob/master/README.md)
- [Releases](https://github.com/dpgaspar/Flask-AppBuilder/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/dpgaspar-flask-appbuilder
