Commit Graph

707 Commits

Author SHA1 Message Date
Paul Carleton ca0c774ec9 Use token introspection instead of hardcoded token validation
Replace the hardcoded token prefix validation with OAuth 2.0 Token
Introspection (RFC 7662). The server now:
- Discovers the introspection endpoint from AS metadata
- Calls the introspection endpoint to validate each token
- Extracts client_id, scopes, and expiry from the response

This properly integrates with the authorization server rather than
relying on hardcoded token patterns.
2026-01-14 12:14:24 +00:00
Paul Carleton a5c7e7ca2e Update uv.lock for conformance-auth-server 2026-01-14 12:00:10 +00:00
Paul Carleton 327930fe75 Add conformance auth server for OAuth server authentication testing
Adds a new example server that implements OAuth bearer token authentication
for use with the MCP conformance test framework's server auth tests.

The server:
- Returns 401 with WWW-Authenticate header for unauthenticated requests
- Serves Protected Resource Metadata at /.well-known/oauth-protected-resource
- Validates tokens starting with 'test-token' or 'cc-token'
- Implements echo and test-tool tools for testing authenticated calls

Usage:
  MCP_CONFORMANCE_AUTH_SERVER_URL=http://localhost:3000 \
    uv run mcp-conformance-auth-server
2026-01-14 11:57:34 +00:00
gazzadownunder d52937b39c Make refresh_token grant type optional in DCR handler (#1651)
Co-authored-by: Claude <noreply@anthropic.com>
2026-01-05 13:41:45 +00:00
Max Isbey c7cbfbb302 docs: add guidance on discussing features before opening PRs (#1760) 2026-01-01 10:07:06 +01:00
Maxime 78a9504ec1 fix: return HTTP 404 for unknown session IDs instead of 400 (#1808)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2025-12-31 14:06:12 +00:00
jnjpng a9cc822a10 fix: accept HTTP 201 status code in token exchange (#1503)
Co-authored-by: Paul Carleton <paulcarletonjr@gmail.com>
2025-12-19 18:22:00 +00:00
Ankesh Kumar Thakur a4bf947540 fix: Token endpoint response for invalid_client (#1481)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2025-12-19 18:19:00 +00:00
Max Isbey 3f6b0597f1 docs: update CONTRIBUTING with v2 branching strategy (#1804) 2025-12-19 18:11:43 +00:00
V 06748eb4c4 fix: Include extra field for context log (#1535) 2025-12-19 17:54:03 +00:00
Yugan 2aa1ad2a69 feat: standardize timeout values to floats in seconds (#1766) 2025-12-19 12:22:56 +00:00
Yugan 4807eb5a80 Add workflow to comment on PRs when released (#1772) 2025-12-19 11:17:13 +00:00
Max Isbey ef96a31671 ci: add v1.x branch to main-checks workflow (#1802)
Main branch checks / checks (push) Failing after 0s
v1.25.0
2025-12-18 16:59:30 +00:00
zenlytix 8ac0cab98c Fix for Url Elicitation issue 1768 (#1780) 2025-12-15 18:58:17 +01:00
Ondrej Mosnáček 65b36de4eb fix: use correct python command name in test_stdio.py (#1782)
Main branch checks / checks (push) Failing after 0s
Signed-off-by: Ondrej Mosnáček <omosnacek@gmail.com>
v1.24.0
2025-12-12 14:02:38 +00:00
Marcelo Trylesinski a3a4b8d11a Add streamable_http_client which accepts httpx.AsyncClient instead of httpx_client_factory (#1177)
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com>
2025-12-10 16:39:00 +00:00
Camila Rondinini cc8382ce3e Fix JSON-RPC error response ID matching (#1720)
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com>
2025-12-10 16:15:21 +00:00
Jeremiah Lowin 0dedbd9831 feat: client-side support for SEP-1577 sampling with tools (#1722) 2025-12-09 23:36:28 +00:00
Max Isbey 779271ae38 chore: remove release-comment workflow (#1758)
Main branch checks / checks (push) Failing after 0s
v1.23.3
2025-12-09 15:45:08 +00:00
Arjun TS 2bf9b10f63 Skip empty SSE data to avoid parsing errors (#1753)
Co-authored-by: ARJUN-TS1 <arjun.ts1@ibm.com>
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2025-12-09 15:14:23 +00:00
Anton Pidkuiko 8ac11ec604 fix: allow MIME type parameters in resource validation (RFC 2045) (#1755)
Co-authored-by: Claude <noreply@anthropic.com>
2025-12-09 14:56:40 +00:00
Felix Weinberger b7cc25493c feat: add workflow to comment on PRs when released (#1750) 2025-12-09 12:22:07 +00:00
Max Isbey 8b984d93a3 refactor(auth): remove unused _register_client method (#1748) 2025-12-08 21:50:20 +00:00
Felix Weinberger 89ff338174 fix: skip priming events and close_sse_stream for old protocol versions (#1719)
Main branch checks / checks (push) Failing after 0s
v1.23.2
2025-12-04 14:44:08 +00:00
Edison 9ed0b93ceb fix: handle ClosedResourceError in StreamableHTTP message router (#1384)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com>
2025-12-04 11:36:23 +01:00
Tyler Mailman 72a34002aa fix: add lifespan context manager to StreamableHTTP mounting examples (#1669)
Co-authored-by: TheMailmans <tyler@example.com>
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com>
2025-12-03 22:08:21 +00:00
Felix Weinberger 8e02fc17e1 chore: update LATEST_PROTOCOL_VERSION to 2025-11-25 (#1715)
Main branch checks / checks (push) Failing after 1s
v1.23.1
2025-12-02 18:27:27 +00:00
Paul Carleton d3a184119e Merge commit from fork
Main branch checks / checks (push) Failing after 0s
* Auto-enable DNS rebinding protection for localhost servers

When a FastMCP server is created with host="127.0.0.1" or "localhost"
and no explicit transport_security is provided, automatically enable
DNS rebinding protection. Both 127.0.0.1 and localhost are allowed
as valid hosts/origins since clients may use either to connect.

* Add tests for auto DNS rebinding protection on localhost

Tests verify that:
- Protection auto-enables for host=127.0.0.1
- Protection auto-enables for host=localhost
- Both 127.0.0.1 and localhost are in allowed hosts/origins
- Protection does NOT auto-enable for other hosts (e.g., 0.0.0.0)
- Explicit transport_security settings are not overridden

* Add IPv6 localhost (::1) support for DNS rebinding protection

Extend auto-enable DNS rebinding protection to also cover IPv6
localhost. When host="::1", protection is now auto-enabled with
appropriate allowed hosts ([::1]:*) and origins (http://[::1]:*).

* Fix import ordering in test file
v1.23.0
2025-12-02 13:23:55 +00:00
Felix Weinberger fa851d93a2 feat: backwards-compatible create_message overloads for SEP-1577 (#1713) 2025-12-02 13:17:45 +00:00
Paul Carleton f82b0c9371 Support client_credentials flow with JWT and Basic auth (#1663)
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com>
2025-12-02 12:53:55 +00:00
Felix Weinberger 281fd4765e Add SSE polling support (SEP-1699) (#1654) 2025-12-02 11:44:49 +00:00
Camila Rondinini 2cd178a962 Add on_session_created callback option (#1710) 2025-12-01 17:48:33 +00:00
Max Isbey c92bb2f7ff SEP-1686: Tasks (#1645) 2025-11-28 18:51:58 +00:00
Felix Weinberger 5983a650cc Skip empty SSE data to avoid parsing errors (#1670) 2025-11-26 18:09:39 +00:00
Chris Coutinho 02b7889929 Implement SEP-1036: URL mode elicitation for secure out-of-band interactions (#1580)
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com>
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com>
2025-11-25 11:00:21 +00:00
Paul Carleton 27279bc157 Update doc string on custom_route (#1660) 2025-11-24 19:20:56 +00:00
Paul Carleton f22501315e feat: implement SEP-991 URL-based client ID (CIMD) support (#1652)
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com>
2025-11-24 17:21:03 +00:00
Felix Weinberger f2517fe14b fix: url for spec (#1659) 2025-11-24 16:59:48 +00:00
Felix Weinberger 091afb82dc Implement SEP-986: Tool name validation (#1655) 2025-11-24 16:46:57 +00:00
Paul Carleton 998f0ee4db [auth][conformance] add conformance auth client (#1640)
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com>
2025-11-24 13:52:04 +00:00
Tapan Chugh b19fa6f279 SEP-1330: Elicitation Enum Schema Improvements and Standards Compliance (#1246)
Co-authored-by: Tapan Chugh <tapanc@cs.washington.edu>
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com>
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com>
2025-11-23 23:32:08 +00:00
Olivier Chafik 71c475588f Implement SEP-1577 - Sampling With Tools (#1594)
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com>
Co-authored-by: Claude <noreply@anthropic.com>
2025-11-22 23:58:14 -05:00
Jon Shea c51936f61f Add client_secret_basic authentication support (#1334)
Co-authored-by: Paul Carleton <paulc@anthropic.com>
2025-11-20 20:53:37 +00:00
Felix Weinberger 397089a78e Add tests for JSON Schema 2020-12 field preservation (SEP-1613) (#1649) 2025-11-20 20:51:13 +00:00
adam jones fcffa14b5b docs: Update examples to use stateless HTTP with JSON responses (#1499)
Main branch checks / checks (push) Failing after 0s
v1.22.0
2025-11-20 15:06:37 +00:00
Liang Wu 9c8f763aa8 chore: Lazy import jsonschema library (#1596)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2025-11-19 15:30:52 +00:00
Andrii Blyzniuk 5489e8b6fb fix get_client_metadata_scopes on 401 (#1631)
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com>
2025-11-16 17:18:50 +00:00
inaku a357380cfa feat: Pass through and expose additional parameters in ClientSessionGroup.call_tool and .connect_to_server (#1576) 2025-11-16 15:57:43 +00:00
Max Isbey 9724ad1ce6 Fix CI highest resolution test to actually test highest versions (#1609)
Main branch checks / checks (push) Failing after 0s
v1.21.1
2025-11-13 20:25:43 +00:00
Victorien 116c13e2c6 Refactor func_metadata() implementation (#1496) 2025-11-13 20:21:15 +00:00