Max Isbey
6b0166f3d1
Split the registration request model from the registered-client record
...
OAuthClientInformationFull, the client's parse of the authorization server's
Dynamic Client Registration response, inherited from OAuthClientMetadata, the
request the client sends. That typed the response as though it had to be a
request this SDK would send. RFC 7591 3.2.1 says otherwise: the server may
reject or replace any requested metadata value, and real servers echo an
application_type outside OIDC Registration's web/native, an explicit null,
an auth method the SDK does not implement, or an empty redirect_uris. Each
raised ValidationError on a 2xx response, after the server had already
provisioned the client, so the registration was discarded and orphaned.
Make the two models siblings over a shared OAuthClientMetadataBase. The
request keeps its strict types, so the SDK still refuses to send an
unregistered application_type. The record accepts what a server may echo:
application_type and token_endpoint_auth_method are str | None (with an
echoed "" read as absent, as the optional URL fields already were),
grant_types is list[str], and redirect_uris may be absent or empty.
client_id is now required, as RFC 7591 3.2.1 makes it in the response.
Whether a substituted value is usable is judged where it matters, not at
parse: an auth method the client cannot apply is reported as an
OAuthRegistrationError when the registration completes, before the record
is stored or any interactive authorization begins, and prepare_token_auth
reports the same for a stored record. The recognized set is derived from
the one TokenEndpointAuthMethod type so the two cannot drift.
The bundled registration endpoint now returns all registered metadata in
its 201 response, building the record from the validated request's dump so
a field can no longer be silently dropped from the echo; it previously
omitted application_type, reporting the default in place of a client's
"web".
2026-07-26 11:03:23 +00:00
Max
11934c90ae
Replace FileResource.is_binary with an encoding field ( #3171 )
2026-07-26 00:58:06 +01:00
Max
814072c94d
Narrow message_handler's parameter to notifications and exceptions ( #3168 )
2026-07-26 00:24:48 +01:00
Max
47bfa85e83
Remove the unused timeout parameter from OAuthClientProvider ( #3165 )
2026-07-26 00:22:15 +01:00
Max
3212591946
Stop advertising MCP_* env vars for MCPServer settings; drop pydantic-settings ( #3170 )
2026-07-25 23:22:27 +01:00
Max
7163d8263f
Remove the deprecated RFC7523OAuthClientProvider ( #3169 )
2026-07-25 22:50:57 +01:00
Max
e90a66b554
Rename scopes= to scope= on the client-credentials OAuth providers ( #3166 )
2026-07-25 20:23:36 +01:00
Max
5dd062d077
Remove Context.client_id ( #3167 )
2026-07-25 19:11:51 +01:00
Max
629ca297d2
Isolate the stdio server's stdin and stdout from handler subprocesses ( #3117 )
2026-07-25 13:05:51 +01:00
Max
837ef904f8
Align with spec #3002 : optional clientInfo, serverInfo in result _meta ( #3143 )
Deploy Docs / deploy-docs (push) Has been cancelled
CI / checks (push) Failing after 24m23s
CI / all-green (push) Has been cancelled
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
GitHub Actions Security Analysis / zizmor (push) Has been cancelled
2026-07-23 12:00:36 +01:00
Marcelo Trylesinski
03aaebd3aa
Add Streamable HTTP request body limits ( #3095 )
2026-07-16 08:33:32 +02:00
Marcelo Trylesinski
2713b53b12
Replace httpx and httpx-sse with httpx2 ( #2972 )
...
CI / checks (push) Failing after 1s
CI / all-green (push) Has been cancelled
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-07-14 17:05:08 +01:00
Max
9bdc03d54e
Add the client-side subscriptions/listen driver ( #3047 )
2026-07-07 14:26:09 +01:00
Max
d287c9868f
Extend resolver DI to sampling and roots requests ( #3049 )
2026-07-06 18:25:57 +01:00
Max
bf4402725d
docs: restructure the migration guide around topical groups with a navigation layer ( #3058 )
2026-07-02 18:54:21 +01:00
Max
e4d95e0d44
docs: add a "What's new in v2" page ( #3054 )
2026-07-02 15:01:30 +01:00
Max
220d362112
docs: restructure into topical sections and add the four most-asked-for pages ( #3044 )
2026-07-01 21:06:04 +01:00
Max
080f2a869d
Harden the dual-era stream loop's era-lock and rejection semantics ( #3040 )
2026-07-01 17:07:12 +01:00
Max
48ef569f7e
Validate Mcp-Param-* headers server-side on the 2026-07-28 HTTP path (SEP-2243) ( #3033 )
2026-06-30 21:39:32 +01:00
Max
4df609119f
Add a client extension API ( #3034 )
2026-06-30 21:31:02 +01:00
Max
b15b1d5f07
Add a client-side response cache honoring SEP-2549 caching hints ( #3023 )
2026-06-30 11:31:06 +01:00
Max
8d0f928e40
Pass InputRequiredResult through the MCPServer prompt and resource pipelines ( #3020 )
2026-06-29 16:50:58 +01:00
Max
533c6a8226
Add cache_hints constructor map for SEP-2549 caching hints ( #3015 )
2026-06-29 14:11:15 +00:00
Marcelo Trylesinski
c85836a081
Drive resolver elicitation over the 2026-07-28 input_required flow ( #2986 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 14:39:43 +01:00
Max
24fdd909ac
docs: convert bold cross-references into links, link SEP and RFC mentions ( #3017 )
2026-06-29 11:07:26 +00:00
Marcelo Trylesinski
f664db8952
Add resolver dependency injection for MCPServer tools ( #2969 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 11:51:46 +01:00
Marcelo Trylesinski
4b519782f1
Add a pluggable server extension API with MCP Apps ( #3003 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-29 10:58:05 +01:00
Max
24717cc8eb
feat: RFC 6570 URI templates with operator-aware security ( #2356 )
2026-06-26 20:29:17 +02:00
Marcelo Trylesinski
c0ecb70e24
Support RFC 8693 token exchange for enterprise IdP flows (SEP-990) ( #2988 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-26 17:57:10 +02:00
Marcelo Trylesinski
ecdf09d44f
Deprecate Server.__init__ handlers for removed capabilities ( #3002 )
2026-06-26 17:51:13 +02:00
Max
08b62308d4
Client auto-resolves InputRequiredResult via existing callbacks (SEP-2322) ( #2998 )
2026-06-26 17:35:23 +02:00
Marcelo Trylesinski
5b2713d40c
Mirror x-mcp-header tool arguments into Mcp-Param-* request headers (SEP-2243) ( #2990 )
2026-06-26 14:36:56 +02:00
Max
3a8da8c0c3
Fix docs/release follow-ups from the mcp-types package split ( #2977 )
2026-06-26 13:16:09 +02:00
Marcelo Trylesinski
f41a5193f3
Preserve empty issuer/resource paths on AuthSettings ( #2987 )
2026-06-26 11:41:41 +02:00
Max
587340279e
Conformance burn-down: server-side InputRequiredResult, Mcp-Method/Name validation, x-mcp-header filter (14 scenarios → green) ( #2974 )
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
2026-06-26 09:51:59 +02:00
Marcelo Trylesinski
0ee7f1b293
Split protocol types into a standalone mcp-types package ( #2973 )
2026-06-25 19:18:38 +02:00
Max
03681ed55e
Client call_tool: input_responses/request_state retry params; InputRequiredResult via allow_input_required ( #2968 )
2026-06-25 17:37:00 +02:00
Max
f226d00d0a
Client-side 2026-07-28 support: .discover()/.adopt() + Client(mode=); request-metadata green ( #2950 )
2026-06-25 16:09:23 +02:00
Marcelo Trylesinski
ad81ca234a
Slim ServerMiddleware to (ctx, call_next) and add OpenTelemetryMiddleware ( #2941 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-22 14:46:30 +01:00
Max
2397319a68
Server-side 2026-07-28 stateless support: classifier, driver split, server/discover ( #2928 )
2026-06-21 19:34:17 +01:00
Marcelo Trylesinski
44724284b3
Bind client credentials to their authorization server (SEP-2352) ( #2933 )
2026-06-20 18:47:22 +01:00
Marcelo Trylesinski
1331131650
Union previously requested scopes on step-up re-authorization (SEP-2350) ( #2931 )
2026-06-20 18:45:04 +02:00
Marcelo Trylesinski
4573e4ac33
Deprecate roots, sampling, and logging methods per SEP-2577 ( #2926 )
2026-06-20 18:25:41 +02:00
Marcelo Trylesinski
cf41441e44
Send application_type during Dynamic Client Registration (SEP-837) ( #2930 )
2026-06-20 18:19:12 +02:00
Marcelo Trylesinski
60f37e9d7c
Document redirect_uri wire-format change in OAuth migration note ( #2929 )
2026-06-20 16:14:03 +00:00
Marcelo Trylesinski
48cf4950dc
Validate the iss authorization-response parameter (RFC 9207 / SEP-2468) ( #2921 )
2026-06-20 17:54:18 +02:00
Marcelo Trylesinski
b7a5bffed0
Preserve empty URL paths on OAuth metadata models ( #2925 )
2026-06-20 15:32:03 +00:00
冯基魁
fda4c54362
fix: correct MCPServer call_tool result type ( #2816 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2026-06-20 16:56:16 +02:00
Marcelo Trylesinski
f253682393
Return -32602 for resource not found (SEP-2164) ( #2920 )
2026-06-20 16:55:23 +02:00
Max
84bf9bde05
First end-to-end 2026-07-28 stateless tools/call (experimental entry + ClientSession pin) ( #2917 )
2026-06-20 14:55:59 +01:00