Jeremiah Lowin
a139a06005
sync: bring published-docs to main @ v3.3.0
2026-05-14 22:09:39 -04:00
Jeremiah Lowin
3a9717e6be
Publish docs for v3.2.0 ( #3713 )
...
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Jeremiah Lowin <jlowin@users.noreply.github.com>
Co-authored-by: Marvin Context Protocol <41898282+Marvin Context Protocol@users.noreply.github.com>
Co-authored-by: voidborne-d <voidborne-d@users.noreply.github.com>
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: d 🔹 <258577966+voidborne-d@users.noreply.github.com>
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
Co-authored-by: nightcityblade <nightcityblade@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Bill Easton <strawgate@users.noreply.github.com>
Co-authored-by: Sumanshu Nankana <sumanshunankana@gmail.com>
Co-authored-by: Eric Robinson <ericrobinson@indeed.com>
Co-authored-by: Martim Santos <martimfasantos@gmail.com>
Co-authored-by: d 🔹 <liusway405@gmail.com>
Co-authored-by: Matthieu B <66959271+mtthidoteu@users.noreply.github.com>
Co-authored-by: Sascha Buehrle <47737812+saschabuehrle@users.noreply.github.com>
Co-authored-by: Hakancan <142545736+hkc5@users.noreply.github.com>
Co-authored-by: nightcityblade <jackchen@haloailabs.com>
Co-authored-by: Matt Hallowell <17804673+mhallo@users.noreply.github.com>
Co-authored-by: nate nowack <thrast36@gmail.com>
Co-authored-by: Bill Easton <williamseaston@gmail.com>
Co-authored-by: Marcus Shu <46469249+shulkx@users.noreply.github.com>
Co-authored-by: Rushabh Doshi <radoshi@gmail.com>
Co-authored-by: AIKAWA Shigechika <shige@aikawa.jp>
Co-authored-by: Jeremy Simon <simonjer805@gmail.com>
Co-authored-by: Miguel Miranda Dias <7780875+pandego@users.noreply.github.com>
Co-authored-by: Anthony James Padavano <padavano.anthony@gmail.com>
Co-authored-by: Mostafa Kamal <hiremostafa@gmail.com>
Fix auto-close MRE script posting comment without closing (#3386 )
Fix WorkOS token scope verification bypass 🤖 Generated with Codex (#3407 )
Fix initialize McpError fallthrough 🤖 Generated with Codex (#3413 )
Fix transform arg collisions with passthrough params (#3431 )
Fix get_* returning None when latest version is disabled (#3439 )
Fix get_* returning None when latest version is disabled (#3421 )
Fix server lifespan overlap teardown (#3415 )
Fix $ref output schema object detection regression (#3420 )
resolved annotations (#3429 )
Fix async partial callables rejected by iscoroutinefunction (#3438 )
Fix async partial callables rejected by iscoroutinefunction (#3423 )
fix: add version to components (#3458 )
fix: use intent-based flag for OIDC scope patch in load_access_token (#3465 )
Fixes #3461
fix: normalize Google scope shorthands and surface valid_scopes (#3477 )
fix: resolve ty 0.0.23 type-checking errors and bump pin (#3481 )
fix: shield lifespan teardown from cancellation (#3480 )
fix: forward custom_route endpoints from mounted servers (#3462 )
fix updates _get_additional_http_routes() to traverse providers,
Fixes #3457
fix: remove hardcoded version from CLI help text (#3456 )
fix: monty 0.0.8 compatibility, drop external_functions from constructor (#3468 )
fix: task test teardown hanging 5s per test (#3499 )
Closes #3498
fix: validate workspace path is a directory before cursor install (#3440 )
Fixes #3426
fix: handle re.error from malformed URI templates in build_regex (#3501 )
fix: reject empty/OIDC-only required_scopes in AzureProvider (#3503 )
fix: restrict $ref resolution to local refs only (SSRF/LFI) (#3502 )
fix warnings and timeouts (#3504 )
close upgrade check issue when build passes (#3505 )
Closes #3484
fix: URL-encode path params to prevent SSRF/path traversal (GHSA-vv7q-7jx5-f767) (#3507 )
fix: prevent path traversal in skill download (#3493 )
fix: prefer IdP-granted scopes over client-requested scopes in OAuthProxy (#3492 )
fix: remove unrelated transform and http.py changes from PR scope
fix: remove forced follow_redirects from httpx_client_factory calls (#3496 )
fix: stop passing follow_redirects to httpx_client_factory
fix: restore follow_redirects=True for custom httpx client factories
Closes #3509
fix: CSRF double-submit cookie check in consent flow (#3519 )
fix: validate server names in install commands (#3522 )
fix: use raw strings for regex in pytest.raises match (#3523 )
fix: reject refresh tokens used as Bearer access tokens (#3524 )
fix: route ResourcesAsTools/PromptsAsTools through server middleware (#3495 )
fix: resolve Pyright "Module is not callable" on @tool, @resource, @prompt decorators (#3540 )
fix: filter warnings by message in KEY_PREFIX test (#3549 )
fix: suppress output schema for ToolResult subclass annotations (#3548 )
fix: increase sleep duration in proxy cache tests (#3567 )
fix: store absolute token expiry to prevent stale expires_in on reload (#3572 )
fix: preserve tool properties named 'title' during schema compression (#3582 )
Fix loopback redirect URI port matching per RFC 8252 §7.3 (#3589 )
Fix app tool routing: visibility check and middleware propagation (#3591 )
Fix query parameter serialization to respect OpenAPI explode/style settings (#3595 )
Fix dev apps form: union types, textarea support, JSON parsing (#3597 )
fix(google): replace deprecated /oauth2/v1/tokeninfo with /oauth2/v3/userinfo (#3603 )
fix: resolve EntraOBOToken dependency injection through MultiAuth (#3609 )
fix(docs): correct misleading stateless_http header (#3622 )
fix: filesystem provider import machinery (#3626 )
Closes #3625 (issues 2, 3, 6)
fix: recover StdioTransport after subprocess exits (#3630 )
fix(server): preserve mounted tool task metadata (#3632 )
fix: scope deprecation warning filter to FastMCPDeprecationWarning (#3649 )
fix imports, add PrefabAppConfig (#3650 )
fix: resolve CurrentFastMCP/ctx.fastmcp to child server in mounted background tasks (#3651 )
Fix blocking docs issues: chart imports, Select API, Rx consistency (#3652 )
closed by default (#3657 )
Fix prompt caching middleware missing wrap/unwrap round-trip (#3666 )
fix: serialize object query params per OpenAPI style/explode rules (#3662 )
Fixes #2857
fix: HTTP request headers not accessible in background task workers (#3631 )
fix: restore HTTP headers in worker execution path for background tasks (#3681 )
fix: strip discriminator after dereferencing schemas (#3682 )
fix: remove stale ty:ignore directives for ty 0.0.26 (#3684 )
Fix docs gaps in app provider pages (#3690 )
fix: dev apps log panel UX improvements (#3698 )
fix dev server empty string args (#3700 )
2026-03-30 16:48:30 -04:00
dgenio
8ad4eb8321
Add proxy_set_header Connection '' to nginx configs
...
Generated with GitHub Copilot
2026-03-02 16:09:44 -05:00
dgenio
f3b1055b2a
Add SSE Polling cross-reference to nginx timeout guidance
...
Generated with GitHub Copilot
2026-03-02 16:09:44 -05:00
dgenio
62c5520180
Add reverse proxy (nginx) section to HTTP deployment docs
2026-03-02 16:09:44 -05:00
Jeremiah Lowin
62cc28c7b0
Update FastMCP Cloud references to Prefect Horizon ( #2978 )
2026-01-21 20:52:08 -05:00
Jeremiah Lowin
27d318810f
Fix FastAPI mounting examples in docs ( #2962 )
2026-01-20 17:58:39 -05:00
Jeremiah Lowin
3af9de197a
Restructure documentation for FastMCP 3.0 ( #2951 )
2026-01-19 21:33:35 -05:00
Jeremiah Lowin
a39b3534e4
SEP-1699: Add SSE polling support with EventStore ( #2564 )
...
* Add EventStore and SSE polling support (SEP-1699)
* Add close_sse_stream() method to Context
* Add SSE polling documentation
* Fix missing Context import in docs example
* Remove EventStore from root __init__.py, update docs imports
- Removed EventStore import and export from src/fastmcp/__init__.py
- Updated docs to import EventStore from fastmcp.server.event_store
- Resolves merge conflict by not exporting EventStore from root package
2025-12-09 09:55:51 -05:00
alex
bc5c1bfbd7
docs: document stateless_http for horizontal scaling ( #2547 )
2025-12-06 11:59:01 -05:00
Jeremiah Lowin
9cade6c8c8
Fix RFC 8414 path-aware authorization server metadata discovery ( #2533 )
...
* Fix RFC 8414 path-aware authorization server metadata discovery
Override get_well_known_routes() in OAuthProvider to rewrite the
authorization server metadata route to be path-aware based on issuer_url,
matching how protected resource metadata already works.
Closes #2527
* Update readme
2025-12-03 19:16:59 -05:00
Shengshenlan
8b546fd294
Update http.mdx
...
add a hint
2025-11-18 17:10:50 +08:00
Jeremiah Lowin
6d600e36db
Remove trailing slashes from MCP endpoint URLs in docs ( #2277 )
2025-10-27 10:36:47 -04:00
William Easton
063ffe9f64
Derive jwt_signing_key from Client Secret, default to Encrypted Disk Store ( #2223 )
...
* Checkpoint progress
* Checkpoint progress
* add derive b64 method
* PR clean-up
* refactor da proxy
* Updates to tests
* Make jwt_signing_key required for oauth proxy
* use typing_extensions and fix tests
* PR Cleanup
* also adjust integration tests
* Update docs, use client secret to derive jwt signing key
* You win some you lose some, gg claude
* check for both in derive
* update documentation / clean up
* Update http.mdx
---------
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
2025-10-24 19:08:58 -04:00
Jeremiah Lowin
686082a5b5
Add platform-aware OAuth token persistence ( #2218 )
...
* Add comprehensive keyring integration tests
Prevents OS keyring pollution during testing by adding a global mock in
conftest.py. Tests verify keyring behavior across platforms and fallback
scenarios without writing to the actual system keyring.
- Add global mock_keyring fixture to tests/conftest.py
- Add TestOAuthProxyKeyring class with 6 keyring-specific tests
- Remove try/except ImportError for keyring (now required dependency)
- Add keyring extra to py-key-value-aio dependency
- Clean up extraneous implementation comments in oauth_proxy.py
* Update OAuth keyring documentation
Update all OAuth-related documentation to reflect keyring-based key management:
- Add version badges to jwt_signing_key, token_encryption_key, and client_storage parameters
- Standardize "Default behavior (`None`):" formatting with backticks
- Ensure consistent messaging about development-only defaults across all docs
- Update oauth-proxy.mdx, oidc-proxy.mdx, http.mdx, storage-backends.mdx, and upgrade-guide.mdx
2025-10-22 20:42:24 -04:00
Jeremiah Lowin
254ff1a25d
Make CORS opt-in via middleware parameter ( #2150 )
2025-10-20 15:33:13 -04:00
Jeremiah Lowin
09e899a699
docs: Add AWS Cognito resource server requirement and CORS guidance ( #2149 )
2025-10-20 15:28:16 -04:00
Jeremiah Lowin
330eaed11f
OAuth proxy issues its own tokens ( #2109 )
...
* OAuth proxy issues its own tokens
Implement token factory pattern where proxy issues FastMCP JWTs
instead of forwarding upstream tokens. Tokens are minimal references
(JTI) that map to encrypted upstream credentials stored server-side.
* Update run-tests.yml
* Update secret generation and docs
* Add upgrade guide
2025-10-17 14:31:53 -04:00
Jeremiah Lowin
d472e30765
Support mounting OAuth-protected servers under path prefixes ( #2119 )
...
* Add issuer_url parameter to OAuth providers for mounting scenarios
* Add get_well_known_routes
* Update docs
* Improve docs and tests
* Trigger CI
* Fix conditional test execution for Windows
2025-10-17 11:44:49 -04:00