Max
32d32908fe
[v1.x] Pass a list to parametrize in test_docs_examples (pytest 9.1.0 compat) ( #2889 )
Main branch checks / checks (push) Failing after 1s
v1.28.0
2026-06-16 21:29:51 +00:00
Max
0dca751056
[v1.x] Deflake the child process cleanup tests ( #2839 )
2026-06-11 16:48:13 +00:00
Max
52258a9564
[v1.x] Add a v2 status banner to the README ( #2835 )
2026-06-11 09:39:38 +01:00
Max
b8f491724c
[v1.x] Deprecate the WebSocket transport and the experimental tasks entry points ( #2828 )
2026-06-11 09:20:19 +01:00
Sheldon
2309e5ef97
fix: omit null optional fields from task result payloads ( #2809 )
...
Co-authored-by: Sheldon <neooosky@gmail.com >
2026-06-10 10:37:52 +01:00
Max
494eb11d36
[v1.x] Support Python 3.14 ( #2769 )
2026-06-03 11:27:55 +01:00
Max
62137874ff
[v1.x] Scope experimental tasks to the session that created them ( #2720 )
Main branch checks / checks (push) Failing after 0s
v1.27.2
2026-05-29 18:05:58 +01:00
Max
ce267b6fc5
[v1.x] Bind transport sessions to the authenticated principal ( #2719 )
2026-05-29 16:46:37 +00:00
Max
1abcca2408
[v1.x] Add subject and claims to AccessToken ( #2690 )
2026-05-26 15:49:44 +01:00
Max
9773a3f75e
[v1.x] ci: deploy docs to py.sdk.modelcontextprotocol.io via Pages artifact ( #2635 )
2026-05-18 14:29:15 +00:00
Max
77431ebe7d
[v1.x] refactor: import SSEError from httpx_sse public API ( #2561 )
Main branch checks / checks (push) Failing after 0s
v1.27.1
2026-05-08 12:42:45 -04:00
Max
2034cae340
[v1.x] build: restrict httpx to <1.0.0 ( #2559 )
2026-05-08 13:18:01 +00:00
Felix Weinberger
73d458baac
[v1.x] fix(auth): coerce empty-string optional URL fields to None in OAuthClientMetadata ( #2405 )
2026-04-13 18:53:58 +01:00
Max
8d4c2f5834
[v1.x] fix: catch PydanticUserError when generating output schema (pydantic 2.13 compat) ( #2435 )
2026-04-13 17:09:19 +01:00
Owen Devereaux
6524782667
[v1.x] fix: handle ClosedResourceError when transport closes mid-request ( #2334 )
...
Main branch checks / checks (push) Failing after 0s
Co-authored-by: Owen Devereaux <owendevereaux@users.noreply.github.com >
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
v1.27.0
2026-03-24 22:24:47 +00:00
Max Isbey
2e9897e2b9
[v1.x] fix: handle non-UTF-8 bytes in stdio server stdin ( #2303 )
2026-03-17 18:40:43 +00:00
BabyChrist666
f8d98b63a7
Backport: Add missing TasksCallCapability to v1.x ( #2137 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
Co-authored-by: Claude <noreply@anthropic.com >
2026-03-02 12:56:24 +00:00
Felix Weinberger
c68e254bad
docs: add server-side tool error handling documentation ( #2129 )
2026-02-24 11:31:00 +00:00
Felix Weinberger
1ef124e4a8
docs: add snippet verification for docs/ pages ( #2115 )
2026-02-23 15:38:15 +00:00
Felix Weinberger
cfbbd7d71a
docs: fix GitHub links to point to v1.x branch ( #2102 )
2026-02-23 15:26:21 +00:00
Felix Weinberger
1f9fb348f3
docs: fix stub pages and improve docs structure ( #2101 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-02-23 15:18:24 +00:00
Felix Weinberger
c86477c7b7
docs: comprehensive feature documentation for SEP-1730 Tier 1 ( #2090 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-02-23 14:57:16 +00:00
Felix Weinberger
a77462b64d
docs: restructure README into docs/ pages ( #2091 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2026-02-23 14:17:12 +00:00
Felix Weinberger
b1adfcd885
Add VERSIONING.md, ROADMAP.md, and DEPENDENCY_POLICY.md ( #2084 )
2026-02-19 17:23:58 +00:00
Max Isbey
66aaf93bcd
[v1.x] fix: prevent command injection in example URL opening ( #2085 )
2026-02-18 19:04:18 +00:00
Felix Weinberger
23a615783e
feat: add idle timeout for StreamableHTTP sessions ( #1994 )
2026-02-18 10:34:18 +00:00
Felix Weinberger
67458948ae
fix: add RFC 8707 resource validation to OAuth client ( #2069 )
2026-02-17 14:35:42 +00:00
Felix Weinberger
78ddff022b
ci: backport conformance tests from main to v1.x ( #2068 )
2026-02-16 19:27:57 +00:00
Max Isbey
bac2789e09
fix: remove unused requests dependency from simple-chatbot example ( #1959 )
2026-01-26 14:03:06 +00:00
Luca Chang
3d9d34552a
[v1.x] fix: return HTTP 404 for unknown session IDs instead of 400 ( #1945 )
...
Main branch checks / checks (push) Failing after 1s
Co-authored-by: Maxime <67350340+max-rousseau@users.noreply.github.com >
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
v1.26.0
2026-01-24 19:09:14 +00:00
Max Isbey
d891525958
Backport: Support for Resource and ResourceTemplate metadata ( #1928 )
...
Co-authored-by: Jacem Elwaar <jacem@mcpappsbuilders.com >
2026-01-22 14:02:25 +00:00
Max Isbey
d3787c96b4
ci: add all-green job to pull-request-checks workflow ( #1929 )
2026-01-22 13:56:22 +00:00
Max Isbey
ef96a31671
ci: add v1.x branch to main-checks workflow ( #1802 )
Main branch checks / checks (push) Failing after 0s
v1.25.0
2025-12-18 16:59:30 +00:00
zenlytix
8ac0cab98c
Fix for Url Elicitation issue 1768 ( #1780 )
2025-12-15 18:58:17 +01:00
Ondrej Mosnáček
65b36de4eb
fix: use correct python command name in test_stdio.py ( #1782 )
...
Main branch checks / checks (push) Failing after 0s
Signed-off-by: Ondrej Mosnáček <omosnacek@gmail.com >
v1.24.0
2025-12-12 14:02:38 +00:00
Marcelo Trylesinski
a3a4b8d11a
Add streamable_http_client which accepts httpx.AsyncClient instead of httpx_client_factory ( #1177 )
...
Co-authored-by: Felix Weinberger <fweinberger@anthropic.com >
2025-12-10 16:39:00 +00:00
Camila Rondinini
cc8382ce3e
Fix JSON-RPC error response ID matching ( #1720 )
...
Co-authored-by: Claude <noreply@anthropic.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-12-10 16:15:21 +00:00
Jeremiah Lowin
0dedbd9831
feat: client-side support for SEP-1577 sampling with tools ( #1722 )
2025-12-09 23:36:28 +00:00
Max Isbey
779271ae38
chore: remove release-comment workflow ( #1758 )
Main branch checks / checks (push) Failing after 0s
v1.23.3
2025-12-09 15:45:08 +00:00
Arjun TS
2bf9b10f63
Skip empty SSE data to avoid parsing errors ( #1753 )
...
Co-authored-by: ARJUN-TS1 <arjun.ts1@ibm.com >
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
2025-12-09 15:14:23 +00:00
Anton Pidkuiko
8ac11ec604
fix: allow MIME type parameters in resource validation (RFC 2045) ( #1755 )
...
Co-authored-by: Claude <noreply@anthropic.com >
2025-12-09 14:56:40 +00:00
Felix Weinberger
b7cc25493c
feat: add workflow to comment on PRs when released ( #1750 )
2025-12-09 12:22:07 +00:00
Max Isbey
8b984d93a3
refactor(auth): remove unused _register_client method ( #1748 )
2025-12-08 21:50:20 +00:00
Felix Weinberger
89ff338174
fix: skip priming events and close_sse_stream for old protocol versions ( #1719 )
Main branch checks / checks (push) Failing after 0s
v1.23.2
2025-12-04 14:44:08 +00:00
Edison
9ed0b93ceb
fix: handle ClosedResourceError in StreamableHTTP message router ( #1384 )
...
Co-authored-by: Max Isbey <224885523+maxisbey@users.noreply.github.com >
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2025-12-04 11:36:23 +01:00
Tyler Mailman
72a34002aa
fix: add lifespan context manager to StreamableHTTP mounting examples ( #1669 )
...
Co-authored-by: TheMailmans <tyler@example.com >
Co-authored-by: Marcelo Trylesinski <marcelotryle@gmail.com >
2025-12-03 22:08:21 +00:00
Felix Weinberger
8e02fc17e1
chore: update LATEST_PROTOCOL_VERSION to 2025-11-25 ( #1715 )
Main branch checks / checks (push) Failing after 1s
v1.23.1
2025-12-02 18:27:27 +00:00
Paul Carleton
d3a184119e
Merge commit from fork
...
Main branch checks / checks (push) Failing after 0s
* Auto-enable DNS rebinding protection for localhost servers
When a FastMCP server is created with host="127.0.0.1" or "localhost"
and no explicit transport_security is provided, automatically enable
DNS rebinding protection. Both 127.0.0.1 and localhost are allowed
as valid hosts/origins since clients may use either to connect.
* Add tests for auto DNS rebinding protection on localhost
Tests verify that:
- Protection auto-enables for host=127.0.0.1
- Protection auto-enables for host=localhost
- Both 127.0.0.1 and localhost are in allowed hosts/origins
- Protection does NOT auto-enable for other hosts (e.g., 0.0.0.0)
- Explicit transport_security settings are not overridden
* Add IPv6 localhost (::1) support for DNS rebinding protection
Extend auto-enable DNS rebinding protection to also cover IPv6
localhost. When host="::1", protection is now auto-enabled with
appropriate allowed hosts ([::1]:*) and origins (http://[::1] :*).
* Fix import ordering in test file
v1.23.0
2025-12-02 13:23:55 +00:00
Felix Weinberger
fa851d93a2
feat: backwards-compatible create_message overloads for SEP-1577 ( #1713 )
2025-12-02 13:17:45 +00:00
Paul Carleton
f82b0c9371
Support client_credentials flow with JWT and Basic auth ( #1663 )
...
Co-authored-by: Claude <noreply@anthropic.com >
Co-authored-by: Felix Weinberger <3823880+felixweinberger@users.noreply.github.com >
2025-12-02 12:53:55 +00:00