Paul Carleton
2443150d44
merge fix
2025-11-20 20:03:44 +00:00
Jon Shea
fe0e62e011
Add client_secret_basic auth support to MCP client
...
- Implement HTTP Basic auth for OAuth token requests
- Automatically sets selects auth method when OAuthClientProvider is
configured with OAuthClientMetadata that has
token_endpoint_auth_method=None.
- Made OAuthClientMetadata.token_endpoint_auth_method optional to
support the above auto-configuration.
- Removed ` "token_endpoint_auth_method": "client_secret_post"` from the
simple-auth-client example as is now auto-configured.
2025-11-20 19:45:22 +00:00
Jon Shea
eac35d441c
Add client_secret_basic authentication support
...
Add support for HTTP Basic Authentication (client_secret_basic) as a
client authentication method for the token and revoke endpoints, alongside
the existing client_secret_post method. This improves compatibility with
OAuth servers like Keycloak that use Basic auth.
Key changes:
- Update OAuthClientMetadata to accept "client_secret_basic" as valid
token_endpoint_auth_method
- Return 401 status for authentication failures (was 400)
- Update metadata endpoints to advertise both auth methods
- Add tests for both auth methods and edge cases
2025-11-20 19:44:21 +00:00
Liang Wu
9c8f763aa8
chore: Lazy import jsonschema library ( #1596 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2025-11-19 15:30:52 +00:00
Andrii Blyzniuk
5489e8b6fb
fix get_client_metadata_scopes on 401 ( #1631 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2025-11-16 17:18:50 +00:00
inaku
a357380cfa
feat: Pass through and expose additional parameters in ClientSessionGroup.call_tool and .connect_to_server ( #1576 )
2025-11-16 15:57:43 +00:00
Max Isbey
91ccdb3d65
Fix OAuth discovery fallback and URL ordering ( #1624 )
2025-11-13 19:37:24 +00:00
Max Isbey
7d12e83cf4
refactor: extract OAuth helper functions and simplify provider state ( #1586 )
2025-11-13 13:28:48 +00:00
Max Isbey
89e9c43acf
Get baseline 100% clean coverage ( #1553 )
2025-11-11 14:09:32 +01:00
Camila Rondinini
9eae96a05e
Add get_server_capabilities() to ClientSession ( #1588 )
Main branch checks / checks (push) Failing after 0s
2025-11-06 20:44:40 +00:00
Chris Coutinho
3390e49c01
Implement SEP-985: OAuth Protected Resource Metadata discovery fallback ( #1548 )
...
Co-authored-by: Claude <noreply@anthropic.com >
Co-authored-by: Paul Carleton <paulc@anthropic.com >
2025-11-05 15:51:02 +00:00
Luca Chang
f161149680
Implement RFC 7523 JWT flows ( #1247 )
...
Co-authored-by: Yann Jouanin <yann.jouanin@valueandco.com >
2025-10-29 16:48:08 +00:00
Max Isbey
db9e451551
fix: Replace remaining manual server polling with wait_for_server helper ( #1529 )
2025-10-29 11:27:57 +00:00
mingo007
b7e4ae7542
test: use errno.ENOENT for command not found assertion ( #1498 )
2025-10-23 16:30:50 -07:00
Samuel Felipe Chenatti
40acbc596c
Expose RequestParams._meta in ClientSession.call_tool ( #1231 )
...
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-10-17 17:57:56 +01:00
Felix Weinberger
de89457683
fix: send params as empty object for list methods without cursor ( #1453 )
2025-10-14 11:11:38 +01:00
Dogacan Colak
0e29cc4130
[client] Implement MCP OAuth scope selection and step-up authorization ( #1324 )
2025-10-13 14:18:00 +01:00
Peter Alexander
60f4b2d10a
Add comprehensive Unicode tests for streamable HTTP transport ( #1381 )
2025-09-29 14:09:33 +01:00
Sreenath Somarajapuram
07ae8c0d4e
types: Setting default value for method: Literal ( #1292 )
2025-08-26 16:22:56 +01:00
Justin Wang
9c6fd15a88
SDK Parity: Avoid Parsing Server Response for non-JsonRPCMessage Requests ( #1290 )
2025-08-26 16:14:47 +01:00
keurcien
e750a06a99
fix: avoid uncessary retries in OAuth authenticated requests ( #1206 )
...
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
2025-08-22 11:45:54 +01:00
David Soria Parra
0926613714
Update dependencies and fix type issues ( #1268 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2025-08-14 10:40:47 +01:00
Marcelo Trylesinski
c7671e470c
Add pyright strict mode on the whole project ( #1254 )
2025-08-11 18:56:37 +01:00
Luca Chang
35777b9811
fix: perform auth server metadata discovery fallbacks on any 4xx ( #1193 )
Main branch checks / checks (push) Failing after 1s
2025-07-24 11:32:35 +01:00
Clare Liguori
6a84a2f79f
fix: fix OAuth flow request object handling ( #1174 )
Main branch checks / checks (push) Failing after 2s
2025-07-21 13:36:21 +01:00
Luca Chang
99c4f3c906
Support falling back to OIDC metadata for auth ( #1061 )
Main branch checks / checks (push) Failing after 1s
2025-07-17 20:06:38 +01:00
yurikunash
eb5146dc8b
Implement RFC9728 - Support WWW-Authenticate header by MCP client ( #1071 )
2025-07-15 10:23:39 +01:00
Marcelo Trylesinski
95b44fb0d7
tests: use inline_snapshot.Is on parametrized test ( #945 )
...
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-07-14 21:59:37 +01:00
Jeremiah Lowin
81fe63a81d
Ensure failed oauth registration response is read before accessing response.text ( #1118 )
...
Co-authored-by: ihrpr <inna@anthropic.com >
2025-07-10 22:01:17 +01:00
Felix Weinberger
3abefeeeaf
fweinberger/align shutdown with spec ( #1091 )
...
Co-authored-by: davenpi <davenport.ianc@gmail.com >
2025-07-09 10:14:30 -04:00
Felix Weinberger
e0336213e8
Improve child process termination on POSIX & Windows ( #1078 )
...
Co-authored-by: jingx8885 <jingxu8885@qq.com >
Co-authored-by: Surya Prakash Susarla <susarla.surya.prakash.1998@gmail.com >
2025-07-08 15:04:06 +01:00
Felix Weinberger
cf72565d9a
Unify process termination on POSIX & Windows (+ tests) ( #1044 )
...
Co-authored-by: Cristian Pufu <cristian.pufu@uipath.com >
2025-07-08 14:57:39 +01:00
Marcelo Trylesinski
9301924f44
chore: bump ruff ( #1085 )
2025-07-04 09:01:17 +01:00
bhosmer-ant
43bb24f62b
feat: Add structured output support for tool functions ( #993 )
2025-06-26 09:36:17 +01:00
dr3s
41f3bc35ce
Make "resource" optional on earlier protocols ( #1017 )
...
Co-authored-by: Andres March <>
2025-06-25 10:18:24 +01:00
Inna Harper
674768802a
Fix /.well-known/oauth-authorization-server dropping path ( #1014 )
2025-06-24 15:43:26 +01:00
Inna Harper
17f9c00c53
MCP server separation into Authorization Server (AS) and Resource Server (RS) roles per spec PR #338 ( #982 )
...
Co-authored-by: Paul Carleton <paulc@anthropic.com >
2025-06-23 14:19:03 +01:00
Marcelo Trylesinski
543961968c
Use 120 characters instead of 88 ( #856 )
2025-06-11 11:45:50 +02:00
dr3s
1a9ead07f5
relax validation ( #879 )
2025-06-09 19:21:01 +01:00
Sam Tombury
2bce10bdb1
Support Cursor OAuth client registration ( #895 )
2025-06-07 07:24:11 -07:00
Lorenzo
7f94bef85e
Client sampling and roots capabilities set to None if not implemented ( #802 )
...
Co-authored-by: ihrpr <inna@anthropic.com >
2025-05-29 09:56:34 +01:00
Tim Child
f5dd324354
Prevent stdio connection hang for missing server path. ( #401 )
...
Co-authored-by: ihrpr <inna@anthropic.com >
2025-05-28 22:57:46 +01:00
ihrpr
9dad26620f
Fix auth tests and ruff format ( #818 )
2025-05-27 17:00:01 +01:00
Pedro Rodrigues
6e418e62f9
Fix building auth metadata paths ( #779 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2025-05-26 15:19:18 +02:00
Christian Clauss
073471cdf1
Python lint: Ruff rule PLW1510 -- subprocess-run-without-check ( #794 )
2025-05-23 16:44:23 +01:00
Nate Barbettini
e80c0150e1
fix: Pass cursor parameter to server ( #745 )
Main branch checks / checks (push) Failing after 0s
Check uv.lock / check-lock (push) Has been cancelled
2025-05-21 22:27:06 +01:00
ihrpr
e33cd41c7a
Add OAuth authentication client for HTTPX ( #751 )
...
Co-authored-by: Paul Carleton <paulc@anthropic.com >
2025-05-19 20:38:04 +01:00
ihrpr
5d33861cad
Add progress notification callback for client ( #721 )
2025-05-15 17:45:58 +01:00
ihrpr
13f018264c
Set 2025-03-26 as the latest protocol version ( #719 )
2025-05-15 09:29:54 +01:00
Jerome
a00b20a427
feat: add cursor pagination support to all client list methods ( #718 )
2025-05-15 09:04:04 +01:00