Max Isbey
aeac39f67d
Correct the scope-selection migration note and a stale test docstring
...
The migration entry named the wrong v1 trigger for the removed
authorization-server fallback: it fired when the protected resource
metadata was absent or omitted scopes_supported, not when it published an
empty list. Also note that the offline_access append needs a base scope,
so flows that previously drew only on the authorization server's list
no longer request it.
No-Verification-Needed: doc- and comment-only edits
2026-07-27 19:56:56 +00:00
Max Isbey
da19abc3d6
Align scope selection with the spec chain and stop mutating caller metadata
...
Drop the authorization-server scopes_supported tier from scope selection.
That list is the server's catalog rather than what the resource needs,
so falling back to it could request every scope the server supports
when the protected resource metadata published an empty list. The
chain is now WWW-Authenticate scope, then PRM scopes_supported, then the
caller-configured scope, then omit; an empty published list falls
through instead of pinning an empty scope. AS metadata is still consulted
for whether offline_access may be added.
The provider now works on a copy of the caller's OAuthClientMetadata, so
the flow's scope selection no longer rewrites the caller's model and the
configured-scope snapshot cannot pick up another provider's discovered
scopes when metadata is reused across providers.
2026-07-27 19:46:08 +00:00
Max Isbey
218510ee1c
Fall back to the caller-configured scope when the server advertises none
...
The OAuth client's scope-selection step overwrote the scope a caller
set on the provider on every 401, and when the server advertised no
scopes at all it left the token request with no scope. The configured
scope is now the last-resort tier after the WWW-Authenticate challenge
and the server's scopes_supported, matching the TypeScript SDK.
A source that yields no scopes (absent, null, or an empty list) now
falls through to the next tier instead of pinning an empty scope.
2026-07-25 20:47:59 +00:00
Max
e90a66b554
Rename scopes= to scope= on the client-credentials OAuth providers ( #3166 )
2026-07-25 20:23:36 +01:00
Max
5dd062d077
Remove Context.client_id ( #3167 )
2026-07-25 19:11:51 +01:00
Max
0cb920f126
Make CacheConfig() the Client cache default and None the off switch ( #3164 )
2026-07-25 17:50:53 +01:00
Max
629ca297d2
Isolate the stdio server's stdin and stdout from handler subprocesses ( #3117 )
2026-07-25 13:05:51 +01:00
Max
00a70148bc
Serve the 2026-07-28 protocol over stdio: decide the era from the opening request ( #3152 )
CI / checks (push) Failing after 1s
Deploy Docs / deploy-docs (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
CI / all-green (push) Has been cancelled
2026-07-24 13:46:37 +01:00
Max
837ef904f8
Align with spec #3002 : optional clientInfo, serverInfo in result _meta ( #3143 )
Deploy Docs / deploy-docs (push) Has been cancelled
CI / checks (push) Failing after 24m23s
CI / all-green (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
2026-07-23 12:00:36 +01:00
Max
3a6f2996cd
docs: load media examples from disk instead of inline base64 ( #3108 )
2026-07-16 20:41:05 +01:00
Max
ebcc4dc3fb
Pin pymdown-extensions back to 11.0 ( #3106 )
2026-07-16 20:25:33 +01:00
Max
497f7afa61
docs: make API reference rendering independent of page order ( #3107 )
2026-07-16 18:29:44 +01:00
Andre.Kalberer
e464f72c12
docs: document Windows stdio subprocess stdin handling ( #3079 )
2026-07-16 11:25:47 +01:00
Marcelo Trylesinski
03aaebd3aa
Add Streamable HTTP request body limits ( #3095 )
2026-07-16 08:33:32 +02:00
Marcelo Trylesinski
2713b53b12
Replace httpx and httpx-sse with httpx2 ( #2972 )
...
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
v2.0.0b2
2026-07-14 17:05:08 +01:00
Otis Cui
1216c53693
fix: reject trailing newline in tool-name and URI-template varname validation ( #3076 )
...
Python's $ with re.match also matches just before a single trailing newline, so tool-name validation accepted "name\n" and UriTemplate.parse accepted varnames like "foo\n". Switch both checks to re.fullmatch.
Closes #3084
2026-07-10 12:56:54 +00:00
Marcelo Trylesinski
4fc8882c02
docs: replace MkDocs with Zensical ( #3073 )
...
Co-authored-by: Claude <noreply@anthropic.com >
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-07-10 12:48:46 +01:00
Max
74a242ae7f
ci: pick the docs-preview toolchain from the PR checkout ( #3081 )
2026-07-09 13:57:14 +01:00
Max
148278e07f
Gate the test matrix and retry setup-uv's flaky manifest fetch ( #3080 )
2026-07-09 12:32:53 +01:00
Max
9bdc03d54e
Add the client-side subscriptions/listen driver ( #3047 )
2026-07-07 14:26:09 +01:00
Max
6d2e908f2b
docs: pin mkdocs<2 and silence the mkdocs-material advisory banner in CI ( #3072 )
2026-07-07 13:45:30 +01:00
Max
867bba6263
Share one event loop per test module to stop Windows socketpair churn ( #3070 )
2026-07-07 13:19:04 +01:00
Max
d287c9868f
Extend resolver DI to sampling and roots requests ( #3049 )
2026-07-06 18:25:57 +01:00
Max
53117cb3a9
Make client-side cancellation work over the 2026 transports ( #3046 )
2026-07-02 19:21:04 +01:00
Max
bf4402725d
docs: restructure the migration guide around topical groups with a navigation layer ( #3058 )
2026-07-02 18:54:21 +01:00
Max
2359b40285
docs: modernize the site theme ( #3057 )
2026-07-02 16:17:33 +01:00
Max
e4d95e0d44
docs: add a "What's new in v2" page ( #3054 )
2026-07-02 15:01:30 +01:00
Max
220d362112
docs: restructure into topical sections and add the four most-asked-for pages ( #3044 )
2026-07-01 21:06:04 +01:00
Max
080f2a869d
Harden the dual-era stream loop's era-lock and rejection semantics ( #3040 )
2026-07-01 17:07:12 +01:00
Max
d39c68df23
De-flake conformance CI: solo re-verification, spawn-storm reduction, result artifacts ( #3043 )
2026-07-01 16:59:06 +01:00
Max
0da9092037
Point pre-release install pins at 2.0.0b1 ( #3039 )
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
v2.0.0b1
2026-07-01 00:14:52 +01:00
Max
e50fb5be19
Serve the 2026-07-28 era over stdio and other stream-pair transports ( #3038 )
2026-07-01 00:11:56 +01:00
Max
dcf8a6a0b5
Document pydantic.ValidationError in client Raises sections ( #3036 )
2026-07-01 00:03:17 +01:00
Max
410cc0db31
Add v2 feedback issue template ( #3037 )
2026-07-01 00:03:11 +01:00
Max
ca10dade2c
Serve subscriptions/listen with a pluggable event bus (SEP-2575) ( #3035 )
2026-06-30 23:01:04 +01:00
Max
48ef569f7e
Validate Mcp-Param-* headers server-side on the 2026-07-28 HTTP path (SEP-2243) ( #3033 )
2026-06-30 21:39:32 +01:00
Max
4df609119f
Add a client extension API ( #3034 )
2026-06-30 21:31:02 +01:00
Max
7322ca56f4
Require integrity protection for MRTR requestState ( #3032 )
2026-06-30 21:30:32 +01:00
Den Delimarsky
985652491a
Add Cloudflare Pages docs preview with /preview-docs slash command ( #3028 )
2026-06-30 16:47:21 +01:00
Max
0b200ef03b
Surface skipped conformance scenarios as baselined known failures ( #3030 )
2026-06-30 13:07:05 +01:00
Max
b15b1d5f07
Add a client-side response cache honoring SEP-2549 caching hints ( #3023 )
2026-06-30 11:31:06 +01:00
Max
67d7593df1
docs: publish llms.txt and markdown renditions of the docs ( #3024 )
2026-06-30 11:30:55 +01:00
Max
8d0f928e40
Pass InputRequiredResult through the MCPServer prompt and resource pipelines ( #3020 )
2026-06-29 16:50:58 +01:00
Max
8f2c97b769
Consult request_state only for the question a resolver is asking ( #3019 )
2026-06-29 16:44:05 +01:00
Max
533c6a8226
Add cache_hints constructor map for SEP-2549 caching hints ( #3015 )
2026-06-29 14:11:15 +00:00
Marcelo Trylesinski
c85836a081
Drive resolver elicitation over the 2026-07-28 input_required flow ( #2986 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 14:39:43 +01:00
Max
24fdd909ac
docs: convert bold cross-references into links, link SEP and RFC mentions ( #3017 )
2026-06-29 11:07:26 +00:00
Max
f2e63c979a
Promote the v2 README to README.md ahead of the first v2 beta ( #3014 )
2026-06-29 12:01:54 +01:00
Marcelo Trylesinski
f664db8952
Add resolver dependency injection for MCPServer tools ( #2969 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 11:51:46 +01:00
Marcelo Trylesinski
4b519782f1
Add a pluggable server extension API with MCP Apps ( #3003 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 10:58:05 +01:00