Max Isbey
bad42e2841
Emit RFC 6750 scope= in WWW-Authenticate and validate token audience
...
BearerAuthBackend / RequireAuthMiddleware now produce spec-conformant
challenges and reject tokens issued for a different resource server.
- A request with no credentials gets a bare `Bearer` challenge (with
scope/resource_metadata only), not error="invalid_token" -- RFC 6750
Section 3.1 says the error attribute SHOULD NOT appear when no
authentication information was presented.
- A malformed/unknown token, an expired token, or a token whose audience
does not match the configured resource_server_url is answered 401
invalid_token with a specific error_description, carried via a new
InvalidTokenUser marker so the middleware can distinguish it from
no-credentials.
- All challenges (401 and the 403 insufficient_scope path) now advertise
the required scopes in a `scope=` parameter, which the SDK client
already reads to drive step-up.
- New check_token_audience() helper canonicalises default ports before
comparing, and is wired through both the lowlevel and MCPServer
Starlette stacks via the auth settings' resource_server_url.
Docs and migration guide updated; the corresponding interaction-suite
divergence entries are now closed.
2026-06-27 18:53:13 +00:00
Max
e942d00b98
Re-vendor 2026-07-28 schema at spec ead35b59 (SubscriptionsListenResult) ( #3006 )
2026-06-27 10:15:34 +02:00
Max
24717cc8eb
feat: RFC 6570 URI templates with operator-aware security ( #2356 )
2026-06-26 20:29:17 +02:00
Max
067f90578c
Add SSE response mode to the 2026 streamable-HTTP server entry ( #3001 )
2026-06-26 19:09:08 +02:00
Marcelo Trylesinski
c0ecb70e24
Support RFC 8693 token exchange for enterprise IdP flows (SEP-990) ( #2988 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-26 17:57:10 +02:00
Marcelo Trylesinski
ecdf09d44f
Deprecate Server.__init__ handlers for removed capabilities ( #3002 )
2026-06-26 17:51:13 +02:00
Max
08b62308d4
Client auto-resolves InputRequiredResult via existing callbacks (SEP-2322) ( #2998 )
2026-06-26 17:35:23 +02:00
Marcelo Trylesinski
3945bdde11
Remove the dispatch-tier middleware hook ( #2997 )
2026-06-26 17:08:16 +02:00
Marcelo Trylesinski
b31d95a429
Make OpenTelemetry tracing the single default middleware ( #2995 )
2026-06-26 15:47:37 +02:00
Marcelo Trylesinski
cc596195bb
Switch RFC7523OAuthClientProvider warning to MCPDeprecationWarning ( #2996 )
2026-06-26 15:27:57 +02:00
Marcelo Trylesinski
5b2713d40c
Mirror x-mcp-header tool arguments into Mcp-Param-* request headers (SEP-2243) ( #2990 )
2026-06-26 14:36:56 +02:00
Max
3a8da8c0c3
Fix docs/release follow-ups from the mcp-types package split ( #2977 )
2026-06-26 13:16:09 +02:00
Max
411a6d3980
Rebuild the docs around tested examples; shrink README.v2.md to a pitch ( #2978 )
2026-06-26 12:49:19 +02:00
Max
4caa41f6d5
Add story-style examples suite (27 stories + harness + CI) ( #2957 )
2026-06-26 12:02:27 +02:00
Max
9dc8c5f02d
find_invalid_x_mcp_header: never repr a non-string annotation value ( #2989 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2026-06-26 09:54:28 +00:00
Marcelo Trylesinski
f41a5193f3
Preserve empty issuer/resource paths on AuthSettings ( #2987 )
2026-06-26 11:41:41 +02:00
Max
587340279e
Conformance burn-down: server-side InputRequiredResult, Mcp-Method/Name validation, x-mcp-header filter (14 scenarios → green) ( #2974 )
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
2026-06-26 09:51:59 +02:00
Marcelo Trylesinski
0ee7f1b293
Split protocol types into a standalone mcp-types package ( #2973 )
2026-06-25 19:18:38 +02:00
Max
03681ed55e
Client call_tool: input_responses/request_state retry params; InputRequiredResult via allow_input_required ( #2968 )
2026-06-25 17:37:00 +02:00
Marcelo Trylesinski
96bf22e57a
Stop flagging snake_case is_error results as tool errors in OTel span ( #2971 )
2026-06-25 15:24:45 +00:00
Marcelo Trylesinski
1b1abf6ab6
Add GenAI semantic-convention attributes to OpenTelemetryMiddleware ( #2970 )
2026-06-25 14:43:54 +00:00
Max
f226d00d0a
Client-side 2026-07-28 support: .discover()/.adopt() + Client(mode=); request-metadata green ( #2950 )
2026-06-25 16:09:23 +02:00
Max
ae13ede143
lowlevel Server: widen on_* return types for InputRequiredResult; add subscriptions/listen slot ( #2967 )
2026-06-25 14:20:01 +02:00
Max
a527142312
Buffer per-request StreamableHTTP streams to avoid serial-router head-of-line block ( #2934 )
2026-06-22 16:20:45 +01:00
Max
44ce901ce3
OAuth client: keep refresh_token on non-rotating refresh; restore same-origin issuer binding ( #2946 )
2026-06-22 15:21:52 +01:00
Marcelo Trylesinski
ad81ca234a
Slim ServerMiddleware to (ctx, call_next) and add OpenTelemetryMiddleware ( #2941 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-06-22 14:46:30 +01:00
Max
5e013d9c54
OAuth client: harden SEP-2352/SEP-2350 edge cases; fix conformance comment ( #2936 )
2026-06-22 14:45:20 +01:00
Max
2397319a68
Server-side 2026-07-28 stateless support: classifier, driver split, server/discover ( #2928 )
2026-06-21 19:34:17 +01:00
Marcelo Trylesinski
44724284b3
Bind client credentials to their authorization server (SEP-2352) ( #2933 )
2026-06-20 18:47:22 +01:00
Marcelo Trylesinski
1331131650
Union previously requested scopes on step-up re-authorization (SEP-2350) ( #2931 )
2026-06-20 18:45:04 +02:00
Marcelo Trylesinski
4573e4ac33
Deprecate roots, sampling, and logging methods per SEP-2577 ( #2926 )
2026-06-20 18:25:41 +02:00
Marcelo Trylesinski
cf41441e44
Send application_type during Dynamic Client Registration (SEP-837) ( #2930 )
2026-06-20 18:19:12 +02:00
Marcelo Trylesinski
48cf4950dc
Validate the iss authorization-response parameter (RFC 9207 / SEP-2468) ( #2921 )
2026-06-20 17:54:18 +02:00
Marcelo Trylesinski
b7a5bffed0
Preserve empty URL paths on OAuth metadata models ( #2925 )
2026-06-20 15:32:03 +00:00
Max
5a3412ddc1
Ignore pre-2026 protocol_version pins at the StreamableHTTP transport ( #2923 )
2026-06-20 17:29:57 +02:00
冯基魁
fda4c54362
fix: correct MCPServer call_tool result type ( #2816 )
...
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2026-06-20 16:56:16 +02:00
Marcelo Trylesinski
f253682393
Return -32602 for resource not found (SEP-2164) ( #2920 )
2026-06-20 16:55:23 +02:00
Max
84bf9bde05
First end-to-end 2026-07-28 stateless tools/call (experimental entry + ClientSession pin) ( #2917 )
2026-06-20 14:55:59 +01:00
Max
1cec2d60f4
Relax monolith ElicitRequestURLParams.elicitation_id for 2026-07-28 ( #2913 )
2026-06-19 16:06:08 +01:00
Max
510832aa45
Re-vendor 2026-07-28 schema and absorb spec #2907 error-code renumber ( #2912 )
2026-06-19 15:46:15 +01:00
Max
734746a3d9
Resolve protocol version per request and expose it as ctx.protocol_version ( #2886 )
2026-06-17 08:46:42 +01:00
Max
47bbab3bc3
Drop stale superset-leniency note from ElicitResult.content docstring ( #2884 )
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
2026-06-16 22:08:29 +01:00
Max
7703df1539
Expand site-absolute spec links in generated docstrings to full URLs ( #2885 )
2026-06-16 13:55:43 -07:00
Max
65be5a7147
Protocol types for 2026-07-28: superset monolith, committed per-version packages, and wire-method maps ( #2849 )
2026-06-16 17:40:14 +01:00
Max
1012d60004
[v2] ClientSession runs on JSONRPCDispatcher; BaseSession removed ( #2838 )
2026-06-15 14:46:34 +01:00
Max
7267818e44
Fix unknown-method error code and add a protocol version registry ( #2836 )
2026-06-11 16:47:22 +01:00
Max
1e21814ed5
Update the v2 status banner and pin spawned environments to the running SDK version ( #2834 )
CI / checks (push) Failing after 0s
CI / all-green (push) Has been cancelled
2026-06-11 09:41:19 +01:00
Max
5d826490b6
[v2] Dispatcher/ServerRunner receive-path swap — replaces BaseSession ( #2710 )
2026-06-09 12:58:47 +01:00
Max
b478bff56d
Remove the unsupported WebSocket transport ( #2785 )
2026-06-08 12:05:27 +01:00
Max
bdc48e98b1
Fix stdio client shutdown bugs and rebuild the stdio test suite ( #2773 )
2026-06-05 16:15:43 +01:00