Max Isbey
b8a107d16c
Scope HTTP client redirect following to the request's origin
...
create_mcp_http_client followed every redirect, so everything configured
on a client (headers, auth, request bodies) was re-sent to whatever host
a Location header named. Clients built by the factory now follow
redirects within the same origin (scheme, host, and port), plus
http-to-https upgrades of the same host on default ports, and raise the
new RedirectError for anything else - before the next request is sent.
- transports resolve a refused redirect in-band: requests get a JSON-RPC
error naming the target and the remedy, notifications are delivered to
the session's message handler; the standalone GET stream stops
retrying an endpoint that keeps redirecting
- caller-supplied clients that follow no redirects get the same clear
error on POST, GET stream, and SSE connect instead of an opaque
content-type error
- OAuth discovery, registration, token, refresh, and the
identity-assertion token exchange fail loudly on redirect responses
instead of silently trying the next URL or abandoning the discovery
chain
- RedirectError and create_mcp_http_client are exported from the
top-level mcp package; migration.md documents the behavior change;
docs and examples configure clients through the factory, and the
general-purpose fetch example uses a browser-like client of its own
2026-07-07 19:41:45 +00:00
Max
9bdc03d54e
Add the client-side subscriptions/listen driver ( #3047 )
2026-07-07 14:26:09 +01:00
Max
867bba6263
Share one event loop per test module to stop Windows socketpair churn ( #3070 )
2026-07-07 13:19:04 +01:00
Max
53117cb3a9
Make client-side cancellation work over the 2026 transports ( #3046 )
2026-07-02 19:21:04 +01:00
Max
220d362112
docs: restructure into topical sections and add the four most-asked-for pages ( #3044 )
2026-07-01 21:06:04 +01:00
Max
080f2a869d
Harden the dual-era stream loop's era-lock and rejection semantics ( #3040 )
2026-07-01 17:07:12 +01:00
Max
e50fb5be19
Serve the 2026-07-28 era over stdio and other stream-pair transports ( #3038 )
2026-07-01 00:11:56 +01:00
Max
4df609119f
Add a client extension API ( #3034 )
2026-06-30 21:31:02 +01:00
Max
b15b1d5f07
Add a client-side response cache honoring SEP-2549 caching hints ( #3023 )
2026-06-30 11:31:06 +01:00
Marcelo Trylesinski
c0ecb70e24
Support RFC 8693 token exchange for enterprise IdP flows (SEP-990) ( #2988 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-26 17:57:10 +02:00
Marcelo Trylesinski
ecdf09d44f
Deprecate Server.__init__ handlers for removed capabilities ( #3002 )
2026-06-26 17:51:13 +02:00
Max
08b62308d4
Client auto-resolves InputRequiredResult via existing callbacks (SEP-2322) ( #2998 )
2026-06-26 17:35:23 +02:00
Marcelo Trylesinski
cc596195bb
Switch RFC7523OAuthClientProvider warning to MCPDeprecationWarning ( #2996 )
2026-06-26 15:27:57 +02:00
Max
411a6d3980
Rebuild the docs around tested examples; shrink README.v2.md to a pitch ( #2978 )
2026-06-26 12:49:19 +02:00
Max
587340279e
Conformance burn-down: server-side InputRequiredResult, Mcp-Method/Name validation, x-mcp-header filter (14 scenarios → green) ( #2974 )
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
2026-06-26 09:51:59 +02:00
Marcelo Trylesinski
0ee7f1b293
Split protocol types into a standalone mcp-types package ( #2973 )
2026-06-25 19:18:38 +02:00
Max
03681ed55e
Client call_tool: input_responses/request_state retry params; InputRequiredResult via allow_input_required ( #2968 )
2026-06-25 17:37:00 +02:00
Max
f226d00d0a
Client-side 2026-07-28 support: .discover()/.adopt() + Client(mode=); request-metadata green ( #2950 )
2026-06-25 16:09:23 +02:00
Max
44ce901ce3
OAuth client: keep refresh_token on non-rotating refresh; restore same-origin issuer binding ( #2946 )
2026-06-22 15:21:52 +01:00
Max
5e013d9c54
OAuth client: harden SEP-2352/SEP-2350 edge cases; fix conformance comment ( #2936 )
2026-06-22 14:45:20 +01:00
Max
2397319a68
Server-side 2026-07-28 stateless support: classifier, driver split, server/discover ( #2928 )
2026-06-21 19:34:17 +01:00
Marcelo Trylesinski
44724284b3
Bind client credentials to their authorization server (SEP-2352) ( #2933 )
2026-06-20 18:47:22 +01:00
Marcelo Trylesinski
3169922492
Move scope step-up test to top-level function ( #2932 )
2026-06-20 18:45:10 +01:00
Marcelo Trylesinski
1331131650
Union previously requested scopes on step-up re-authorization (SEP-2350) ( #2931 )
2026-06-20 18:45:04 +02:00
Marcelo Trylesinski
4573e4ac33
Deprecate roots, sampling, and logging methods per SEP-2577 ( #2926 )
2026-06-20 18:25:41 +02:00
Marcelo Trylesinski
cf41441e44
Send application_type during Dynamic Client Registration (SEP-837) ( #2930 )
2026-06-20 18:19:12 +02:00
Marcelo Trylesinski
48cf4950dc
Validate the iss authorization-response parameter (RFC 9207 / SEP-2468) ( #2921 )
2026-06-20 17:54:18 +02:00
Marcelo Trylesinski
b7a5bffed0
Preserve empty URL paths on OAuth metadata models ( #2925 )
2026-06-20 15:32:03 +00:00
Max
5a3412ddc1
Ignore pre-2026 protocol_version pins at the StreamableHTTP transport ( #2923 )
2026-06-20 17:29:57 +02:00
Max
84bf9bde05
First end-to-end 2026-07-28 stateless tools/call (experimental entry + ClientSession pin) ( #2917 )
2026-06-20 14:55:59 +01:00
Max
65be5a7147
Protocol types for 2026-07-28: superset monolith, committed per-version packages, and wire-method maps ( #2849 )
2026-06-16 17:40:14 +01:00
Max
1012d60004
[v2] ClientSession runs on JSONRPCDispatcher; BaseSession removed ( #2838 )
2026-06-15 14:46:34 +01:00
Max
7267818e44
Fix unknown-method error code and add a protocol version registry ( #2836 )
2026-06-11 16:47:22 +01:00
Max
5d826490b6
[v2] Dispatcher/ServerRunner receive-path swap — replaces BaseSession ( #2710 )
2026-06-09 12:58:47 +01:00
Max
b478bff56d
Remove the unsupported WebSocket transport ( #2785 )
2026-06-08 12:05:27 +01:00
Max
bdc48e98b1
Fix stdio client shutdown bugs and rebuild the stdio test suite ( #2773 )
2026-06-05 16:15:43 +01:00
Max
ed39e73c0b
Run SSE and Unicode transport tests in process instead of over sockets ( #2765 )
2026-06-02 21:46:53 +01:00
Gyeongjun Paik (Kent)
3d7b311de0
fix: align Context logging methods with MCP spec data type ( #2366 )
...
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com >
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-04-14 21:41:51 +00:00
Wils Dawson
437d15aa71
SEP-2207: Refresh token guidance ( #2039 )
2026-04-14 11:48:07 +01:00
Marcelo Trylesinski
e6235d1667
Propagate contextvars.Context through anyio streams without modifying SessionMessage ( #2298 )
2026-03-31 12:49:38 -04:00
Max Isbey
883d893097
test: rewrite cli.claude config tests to assert JSON output directly ( #2311 )
...
Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com>
Co-authored-by: Felix Weinberger <felixweinberger@users.noreply.github.com >
2026-03-19 15:16:34 +00:00
Max Isbey
20dd94632e
feat(client): store InitializeResult as initialize_result ( #2300 )
2026-03-18 17:31:26 +00:00
Max Isbey
67201a9bbd
test: fix WS test port race; narrow to single smoke test covering both transport ends ( #2267 )
2026-03-18 15:48:30 +00:00
Max Isbey
75a80b6f07
refactor: connect-first stream lifecycle for sse and streamable_http ( #2292 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2026-03-16 23:30:20 +00:00
Max Isbey
e1fd62e0f3
fix: close all memory stream ends in client transport cleanup ( #2266 )
2026-03-13 14:43:54 +00:00
Max Isbey
dd52713517
Rewrite TestChildProcessCleanup with socket-based deterministic liveness probe ( #2265 )
2026-03-12 12:52:32 +00:00
Max Isbey
31a38b5078
fix: correct Context type parameters across examples and tests ( #2256 )
2026-03-09 16:52:56 +00:00
Giulio Leone
7c0224828b
fix(oauth): include client_id in token request body for client_secret_post ( #2185 )
...
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
2026-03-05 14:57:33 +00:00
Max Isbey
cc22bf5464
refactor: remove request_ctx ContextVar, thread Context explicitly ( #2203 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2026-03-04 13:23:02 +00:00
Jonathan Hefner
cb07adeca3
docs: add code fences to Example: docstring blocks ( #2104 )
2026-02-19 21:06:11 +01:00