Max
4dc224fab2
[v1.x] Apply the request body limit to the SSE and OAuth endpoints ( #3344 )
2026-08-21 17:02:59 +01:00
Max
ae3338f6b3
[v1.x] Complete the FastMCP Settings model at import time ( #3352 )
2026-08-21 12:02:46 +01:00
Max
e8283746d0
[v1.x] fix: reject trailing newline in tool-name validation ( #3086 )
...
Main branch checks / checks (push) Failing after 0s
Conformance Tests / server-conformance (push) Has been cancelled
Conformance Tests / client-conformance (push) Has been cancelled
Deploy Docs / deploy-docs (push) Has been cancelled
Co-authored-by: otiscuilei <otiscui@icloud.com >
2026-07-17 14:19:59 +01:00
Marcelo Trylesinski
5f0b6af9f2
[v1.x] Add Streamable HTTP request body limits ( #3101 )
2026-07-16 09:54:29 +01:00
Max
777b8d0671
[v1.x] Support TransportSecuritySettings in the WebSocket server transport ( #2992 )
Main branch checks / checks (push) Failing after 1s
2026-06-26 13:31:33 +02:00
Max
6df3d73426
[v1.x] Buffer per-request StreamableHTTP streams; store priming event before dispatch ( #2948 )
2026-06-23 14:57:45 +01:00
Max
494eb11d36
[v1.x] Support Python 3.14 ( #2769 )
2026-06-03 11:27:55 +01:00
Max
ce267b6fc5
[v1.x] Bind transport sessions to the authenticated principal ( #2719 )
2026-05-29 16:46:37 +00:00
Max
1abcca2408
[v1.x] Add subject and claims to AccessToken ( #2690 )
2026-05-26 15:49:44 +01:00
Owen Devereaux
6524782667
[v1.x] fix: handle ClosedResourceError when transport closes mid-request ( #2334 )
...
Main branch checks / checks (push) Failing after 0s
Co-authored-by: Owen Devereaux <owendevereaux@users.noreply.github.com >
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-03-24 22:24:47 +00:00
Max Isbey
2e9897e2b9
[v1.x] fix: handle non-UTF-8 bytes in stdio server stdin ( #2303 )
2026-03-17 18:40:43 +00:00
Felix Weinberger
23a615783e
feat: add idle timeout for StreamableHTTP sessions ( #1994 )
2026-02-18 10:34:18 +00:00
Luca Chang
3d9d34552a
[v1.x] fix: return HTTP 404 for unknown session IDs instead of 400 ( #1945 )
...
Main branch checks / checks (push) Failing after 1s
Co-authored-by: Maxime <67350340+max-rousseau@users.noreply.github.com >
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-01-24 19:09:14 +00:00
Max Isbey
d891525958
Backport: Support for Resource and ResourceTemplate metadata ( #1928 )
...
Co-authored-by: Jacem Elwaar <jacem@mcpappsbuilders.com >
2026-01-22 14:02:25 +00:00
zenlytix
8ac0cab98c
Fix for Url Elicitation issue 1768 ( #1780 )
2025-12-15 18:58:17 +01:00
Marcelo Trylesinski
a3a4b8d11a
Add streamable_http_client which accepts httpx.AsyncClient instead of httpx_client_factory ( #1177 )
...
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
2025-12-10 16:39:00 +00:00
Paul Carleton
d3a184119e
Merge commit from fork
...
Main branch checks / checks (push) Failing after 0s
* Auto-enable DNS rebinding protection for localhost servers
When a FastMCP server is created with host="127.0.0.1" or "localhost"
and no explicit transport_security is provided, automatically enable
DNS rebinding protection. Both 127.0.0.1 and localhost are allowed
as valid hosts/origins since clients may use either to connect.
* Add tests for auto DNS rebinding protection on localhost
Tests verify that:
- Protection auto-enables for host=127.0.0.1
- Protection auto-enables for host=localhost
- Both 127.0.0.1 and localhost are in allowed hosts/origins
- Protection does NOT auto-enable for other hosts (e.g., 0.0.0.0)
- Explicit transport_security settings are not overridden
* Add IPv6 localhost (::1) support for DNS rebinding protection
Extend auto-enable DNS rebinding protection to also cover IPv6
localhost. When host="::1", protection is now auto-enabled with
appropriate allowed hosts ([::1]:*) and origins (http://[::1] :*).
* Fix import ordering in test file
2025-12-02 13:23:55 +00:00
Max Isbey
c92bb2f7ff
SEP-1686: Tasks ( #1645 )
2025-11-28 18:51:58 +00:00
Chris Coutinho
02b7889929
Implement SEP-1036: URL mode elicitation for secure out-of-band interactions ( #1580 )
...
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
2025-11-25 11:00:21 +00:00
Tapan Chugh
b19fa6f279
SEP-1330: Elicitation Enum Schema Improvements and Standards Compliance ( #1246 )
...
Co-authored-by: Tapan Chugh <tapanc@cs.washington.edu >
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-11-23 23:32:08 +00:00
Olivier Chafik
71c475588f
Implement SEP-1577 - Sampling With Tools ( #1594 )
...
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
Co-authored-by: Claude <noreply@anthropic.com >
2025-11-22 23:58:14 -05:00
Jon Shea
c51936f61f
Add client_secret_basic authentication support ( #1334 )
...
Co-authored-by: Paul Carleton <paulc@anthropic.com >
2025-11-20 20:53:37 +00:00
Victorien
116c13e2c6
Refactor func_metadata() implementation ( #1496 )
2025-11-13 20:21:15 +00:00
Max Isbey
89e9c43acf
Get baseline 100% clean coverage ( #1553 )
2025-11-11 14:09:32 +01:00
Luca Chang
f161149680
Implement RFC 7523 JWT flows ( #1247 )
...
Co-authored-by: Yann Jouanin <yann.jouanin@valueandco.com >
2025-10-29 16:48:08 +00:00
Max Isbey
db9e451551
fix: Replace remaining manual server polling with wait_for_server helper ( #1529 )
2025-10-29 11:27:57 +00:00
Max Isbey
3e86edfb2f
fix: Replace arbitrary sleeps with active server readiness checks in tests ( #1527 )
...
Co-authored-by: Claude <noreply@anthropic.com >
2025-10-28 21:42:33 +00:00
Max Isbey
f97f7c4a7d
fix: Replace fixed sleep with active server readiness check in SSE tests ( #1526 )
2025-10-28 19:49:13 +00:00
Brandon Shar
1200ba0082
Allow CallToolResult to be returned directly to support _meta field for OpenAI Apps ( #1459 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2025-10-21 18:52:08 +00:00
Mat Leonard
98f82485bd
feat: add tool metadata in FastMCP.tool decorator ( #1463 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2025-10-17 11:18:34 +00:00
daamitt
dcc68ce56b
fix: Set the Server session initialization state immediately after respond… ( #1478 )
...
Main branch checks / checks (push) Failing after 0s
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2025-10-15 13:56:43 +01:00
Fenn Bailey
cd7253c593
feat: add resource annotations support to FastMCP ( #1468 )
2025-10-14 11:07:37 +01:00
AishwaryaKalloli
b4e50aa9f9
Handles message type Exception in lowlevel/server.py _handle_message function. Mentioned as TODO on line 528. ( #786 )
...
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-10-13 14:29:03 +01:00
Brandon Wu
b8e758b02b
feat: add ability to remove tools ( #1322 )
...
Co-authored-by: David Soria Parra <167242713+dsp-ant@users.noreply.github.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
Co-authored-by: Claude <noreply@anthropic.com >
2025-10-06 14:16:50 +01:00
Marcus Shu
df3e428ee8
Improve OAuth protected resource metadata URL construction per RFC 9728 ( #1407 )
2025-10-06 13:52:44 +01:00
automaton82
9323efad99
Issue 1379 patch - Fix MCP server OAuth not working with Visual Studio Code and others with extra grant_types ( #1380 )
2025-09-29 11:13:16 +01:00
Jon Shea
1940040ac3
Accept additional response_types values from OAuth servers ( #1323 )
2025-09-26 20:29:06 +01:00
Tapan Chugh
b85e7bd1a9
feat: Add SDK support for SEP-1034 default values in elicitation schemas ( #1337 )
...
Co-authored-by: Tapan Chugh <tapanc@cs.washington.edu >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-09-24 16:33:45 +01:00
Max Isbey
4fb975c6dc
feat: add paginated list decorators for prompts, resources, and tools ( #1286 )
...
Co-authored-by: Claude <noreply@anthropic.com >
2025-09-23 14:58:06 +01:00
Yann Jouanin
20596e5f41
Add test for ProtectedResourceMetadataParsing ( #1236 )
...
Co-authored-by: Paul Carleton <paulcarletonjr@gmail.com >
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-09-23 12:48:21 +01:00
Peter Alexander
7e93a9fc19
Return HTTP 403 for invalid Origin headers ( #1353 )
2025-09-22 16:44:51 +01:00
pchoudhury22
ca5cb4cb67
fix(fastmcp): propagate mimeType in resource template list ( #1186 )
...
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-09-17 14:50:41 +01:00
David Soria Parra
c3717e7ad3
Fix context injection for resources and prompts ( #1336 )
Main branch checks / checks (push) Failing after 0s
2025-09-11 14:30:06 +01:00
Eleftheria Stein-Kousathana
47d35f0b3c
Allow ping requests before initialization ( #1312 )
2025-09-01 22:37:36 +01:00
jess
1644b822b3
changes structured temperature to not deadly ( #1328 )
2025-08-31 23:09:49 +00:00
Sreenath Somarajapuram
07ae8c0d4e
types: Setting default value for method: Literal ( #1292 )
2025-08-26 16:22:56 +01:00
San Nguyen
eaf7cf41d5
fix: error too many values to unpack (expected 2) ( #1279 )
...
Signed-off-by: San Nguyen <vinhsannguyen91@gmail.com >
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-08-23 21:36:39 +01:00
xavier
f4b2957a20
Added Audio to FastMCP ( #1130 )
2025-08-22 11:45:38 +01:00
David Soria Parra
0926613714
Update dependencies and fix type issues ( #1268 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2025-08-14 10:40:47 +01:00
Marcelo Trylesinski
c7671e470c
Add pyright strict mode on the whole project ( #1254 )
2025-08-11 18:56:37 +01:00