Jeremiah Lowin
a139a06005
sync: bring published-docs to main @ v3.3.0
2026-05-14 22:09:39 -04:00
Jeremiah Lowin
3a9717e6be
Publish docs for v3.2.0 ( #3713 )
...
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Jeremiah Lowin <jlowin@users.noreply.github.com>
Co-authored-by: Marvin Context Protocol <41898282+Marvin Context Protocol@users.noreply.github.com>
Co-authored-by: voidborne-d <voidborne-d@users.noreply.github.com>
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: d 🔹 <258577966+voidborne-d@users.noreply.github.com>
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
Co-authored-by: nightcityblade <nightcityblade@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Bill Easton <strawgate@users.noreply.github.com>
Co-authored-by: Sumanshu Nankana <sumanshunankana@gmail.com>
Co-authored-by: Eric Robinson <ericrobinson@indeed.com>
Co-authored-by: Martim Santos <martimfasantos@gmail.com>
Co-authored-by: d 🔹 <liusway405@gmail.com>
Co-authored-by: Matthieu B <66959271+mtthidoteu@users.noreply.github.com>
Co-authored-by: Sascha Buehrle <47737812+saschabuehrle@users.noreply.github.com>
Co-authored-by: Hakancan <142545736+hkc5@users.noreply.github.com>
Co-authored-by: nightcityblade <jackchen@haloailabs.com>
Co-authored-by: Matt Hallowell <17804673+mhallo@users.noreply.github.com>
Co-authored-by: nate nowack <thrast36@gmail.com>
Co-authored-by: Bill Easton <williamseaston@gmail.com>
Co-authored-by: Marcus Shu <46469249+shulkx@users.noreply.github.com>
Co-authored-by: Rushabh Doshi <radoshi@gmail.com>
Co-authored-by: AIKAWA Shigechika <shige@aikawa.jp>
Co-authored-by: Jeremy Simon <simonjer805@gmail.com>
Co-authored-by: Miguel Miranda Dias <7780875+pandego@users.noreply.github.com>
Co-authored-by: Anthony James Padavano <padavano.anthony@gmail.com>
Co-authored-by: Mostafa Kamal <hiremostafa@gmail.com>
Fix auto-close MRE script posting comment without closing (#3386 )
Fix WorkOS token scope verification bypass 🤖 Generated with Codex (#3407 )
Fix initialize McpError fallthrough 🤖 Generated with Codex (#3413 )
Fix transform arg collisions with passthrough params (#3431 )
Fix get_* returning None when latest version is disabled (#3439 )
Fix get_* returning None when latest version is disabled (#3421 )
Fix server lifespan overlap teardown (#3415 )
Fix $ref output schema object detection regression (#3420 )
resolved annotations (#3429 )
Fix async partial callables rejected by iscoroutinefunction (#3438 )
Fix async partial callables rejected by iscoroutinefunction (#3423 )
fix: add version to components (#3458 )
fix: use intent-based flag for OIDC scope patch in load_access_token (#3465 )
Fixes #3461
fix: normalize Google scope shorthands and surface valid_scopes (#3477 )
fix: resolve ty 0.0.23 type-checking errors and bump pin (#3481 )
fix: shield lifespan teardown from cancellation (#3480 )
fix: forward custom_route endpoints from mounted servers (#3462 )
fix updates _get_additional_http_routes() to traverse providers,
Fixes #3457
fix: remove hardcoded version from CLI help text (#3456 )
fix: monty 0.0.8 compatibility, drop external_functions from constructor (#3468 )
fix: task test teardown hanging 5s per test (#3499 )
Closes #3498
fix: validate workspace path is a directory before cursor install (#3440 )
Fixes #3426
fix: handle re.error from malformed URI templates in build_regex (#3501 )
fix: reject empty/OIDC-only required_scopes in AzureProvider (#3503 )
fix: restrict $ref resolution to local refs only (SSRF/LFI) (#3502 )
fix warnings and timeouts (#3504 )
close upgrade check issue when build passes (#3505 )
Closes #3484
fix: URL-encode path params to prevent SSRF/path traversal (GHSA-vv7q-7jx5-f767) (#3507 )
fix: prevent path traversal in skill download (#3493 )
fix: prefer IdP-granted scopes over client-requested scopes in OAuthProxy (#3492 )
fix: remove unrelated transform and http.py changes from PR scope
fix: remove forced follow_redirects from httpx_client_factory calls (#3496 )
fix: stop passing follow_redirects to httpx_client_factory
fix: restore follow_redirects=True for custom httpx client factories
Closes #3509
fix: CSRF double-submit cookie check in consent flow (#3519 )
fix: validate server names in install commands (#3522 )
fix: use raw strings for regex in pytest.raises match (#3523 )
fix: reject refresh tokens used as Bearer access tokens (#3524 )
fix: route ResourcesAsTools/PromptsAsTools through server middleware (#3495 )
fix: resolve Pyright "Module is not callable" on @tool, @resource, @prompt decorators (#3540 )
fix: filter warnings by message in KEY_PREFIX test (#3549 )
fix: suppress output schema for ToolResult subclass annotations (#3548 )
fix: increase sleep duration in proxy cache tests (#3567 )
fix: store absolute token expiry to prevent stale expires_in on reload (#3572 )
fix: preserve tool properties named 'title' during schema compression (#3582 )
Fix loopback redirect URI port matching per RFC 8252 §7.3 (#3589 )
Fix app tool routing: visibility check and middleware propagation (#3591 )
Fix query parameter serialization to respect OpenAPI explode/style settings (#3595 )
Fix dev apps form: union types, textarea support, JSON parsing (#3597 )
fix(google): replace deprecated /oauth2/v1/tokeninfo with /oauth2/v3/userinfo (#3603 )
fix: resolve EntraOBOToken dependency injection through MultiAuth (#3609 )
fix(docs): correct misleading stateless_http header (#3622 )
fix: filesystem provider import machinery (#3626 )
Closes #3625 (issues 2, 3, 6)
fix: recover StdioTransport after subprocess exits (#3630 )
fix(server): preserve mounted tool task metadata (#3632 )
fix: scope deprecation warning filter to FastMCPDeprecationWarning (#3649 )
fix imports, add PrefabAppConfig (#3650 )
fix: resolve CurrentFastMCP/ctx.fastmcp to child server in mounted background tasks (#3651 )
Fix blocking docs issues: chart imports, Select API, Rx consistency (#3652 )
closed by default (#3657 )
Fix prompt caching middleware missing wrap/unwrap round-trip (#3666 )
fix: serialize object query params per OpenAPI style/explode rules (#3662 )
Fixes #2857
fix: HTTP request headers not accessible in background task workers (#3631 )
fix: restore HTTP headers in worker execution path for background tasks (#3681 )
fix: strip discriminator after dereferencing schemas (#3682 )
fix: remove stale ty:ignore directives for ty 0.0.26 (#3684 )
Fix docs gaps in app provider pages (#3690 )
fix: dev apps log panel UX improvements (#3698 )
fix dev server empty string args (#3700 )
2026-03-30 16:48:30 -04:00
Jeremiah Lowin
610551c7b6
Split large test files to comply with loq line limit ( #3328 )
2026-02-28 11:21:11 -05:00
manojPal23234
507e6b80ab
OpenAPI: rewrite $ref under propertyNames and patternProperties in _replace_ref_with_defs; add regression test for dict[StrEnum, Model] ( #3306 )
...
* Normalize OpenAPI $ref everywhere (incl. propertyNames); migrate components→$defs; add regression test
* Fix: normalize $ref in propertyNames and additionalProperties; add regression test
* Deterministic migration: components.schemas override $defs on collision; preserve direct $defs refs via alias; add collision test
* Fix: rewrite $ref in propertyNames and patternProperties in _replace_ref_with_defs
* Fix syntax error, formatting, and stray files
* Skip boolean subschemas in patternProperties
---------
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
2026-02-26 16:08:54 -05:00
Jeremiah Lowin
1caf40eee8
Fix circular reference crash in OpenAPI schemas ( #3245 )
...
* Fix circular reference crash in OpenAPI schemas (#3242 , #1206 , #1016 )
* chore: Update SDK documentation
---------
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
2026-02-20 09:21:54 -05:00
Jeremiah Lowin
fe57c3d689
Make $ref dereferencing optional via FastMCP(dereference_refs=...) ( #3151 )
...
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
2026-02-11 13:45:37 -05:00
Jeremiah Lowin
880d835ccc
Add CIMD (Client ID Metadata Document) support for OAuth ( #2871 )
2026-02-06 13:44:52 -05:00
Jeremiah Lowin
2b6a0faf1c
Add loq file size limits and clean up type ignores ( #2859 )
2026-01-13 07:29:12 -05:00
Jeremiah Lowin
627c6cdad4
Dereference $ref in tool schemas for MCP client compatibility ( #2808 )
2026-01-07 18:30:08 -05:00
Jeremiah Lowin
b501f05794
Switch to new OpenAPI parser as default ( #2513 )
...
* Switch to new OpenAPI parser as default
Remove the legacy OpenAPI parser and make the experimental parser the
default. The experimental parser (introduced in 2.11) offers better
performance, improved compatibility, and a more maintainable architecture.
- Delete legacy parser (server/openapi.py, utilities/openapi.py)
- Move experimental parser to main locations
- Remove enable_new_openapi_parser feature flag
- Update documentation to remove experimental references
* Add deprecation stubs for experimental OpenAPI imports
* Add deprecated enable_new_openapi_parser setting and deprecation tests
* SDK docs
* REview comments
* Fix docstrings
* Update docstring
* Review comments
* Fix broken links
2025-12-01 20:29:18 -05:00
Jeremiah Lowin
6cc9559f84
Bump ty to ==0.0.1a25 ( #2350 )
...
* Bump ty to >=0.0.1a25 with type fixes
Follow-up to #2295 . Updates ty and fixes compatibility issues with alpha 25, including:
- Updated ignore comment syntax (possibly-unbound-attribute → possibly-missing-attribute)
- Fixed async generator type handling with anext()
- Fixed type narrowing for timeout parameters
- Converted base_url assignments to AnyHttpUrl after string manipulation
- Added CallToolResult to return type annotations
- Removed redundant type casts
- Fixed test form data to use strings instead of bytes
ty alpha 25 has limitations with isinstance() narrowing on unions (see pyproject.toml for details), requiring some targeted type ignores.
* Pin ty to ==0.0.1a25
Alpha releases can have breaking changes, so pin to the tested version.
2025-11-02 20:02:45 -05:00
William Easton
94b1eb9d6e
feat: introduce inline snapshots ( #1605 )
...
Co-authored-by: William Easton <strawgate@users.noreply.github.com>
Co-authored-by: marvin-context-protocol[bot] <225465937+marvin-context-protocol[bot]@users.noreply.github.com>
2025-08-25 10:08:55 -04:00
Jeremiah Lowin
52a0fc078a
Fix nullable field handling in OpenAPI to JSON Schema conversion ( #1279 )
...
Co-authored-by: Claude <noreply@anthropic.com>
2025-07-28 20:31:23 -04:00
Magnus
912bba2385
fix: replace oneOf with anyOf in OpenAPI schemas to handle overlapping unions ( #1119 )
...
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
2025-07-11 13:31:45 -04:00
Jeremiah Lowin
6c9263001b
Add output schema support for OpenAPI tools ( #1073 )
...
* Add output schema support for OpenAPI tools
Implement automatic output schema extraction from OpenAPI responses for
FastMCP tools, addressing issue #1070 . Tools generated from OpenAPI specs
now have meaningful output schemas instead of null, improving agent
efficiency when working with structured API responses.
- Add extract_output_schema_from_responses() function to parse response schemas
- Enhance OpenAPITool to accept and use output schemas with proper wrapping
- Automatically wrap non-object responses to comply with MCP requirements
- Include schema definitions and compress unused ones
- Add comprehensive test suite covering object, array, and primitive responses
- Update existing tests to handle structured output with proper typing
- Maintain backward compatibility for specs without response schemas
🤖 Generated with [Claude Code](https://claude.ai/code )
Co-Authored-By: Claude <noreply@anthropic.com>
* Move output schema tests to dedicated test file
Reorganize output schema tests into test_openapi_output_schemas.py to keep
the main test_openapi.py file focused and smaller, as requested. Added two
additional tests for schema definitions handling.
- Move all extract_output_schema_from_responses() tests to new file
- Add tests for schema definitions inclusion
- Remove output schema imports from main test file
---------
Co-authored-by: Claude <noreply@anthropic.com>
2025-07-07 12:51:01 -04:00
Aditya Bansal
f524652f25
Add OpenAPI extensions support to HTTPRoute
...
- Add extensions field to HTTPRoute class to store x-* fields
- Extract extensions from operation's model_extra in parser
- Add test to verify extensions are properly parsed
2025-06-27 15:27:36 -07:00
Jeremiah Lowin
6584750667
Fix external schema reference handling in OpenAPI parser
...
Previously, external schema references (URLs) in OpenAPI schemas were
silently passed through and only failed during JSON schema validation
with confusing "failed to match exactly one schema" errors.
This change:
- Detects external references in _replace_ref_with_defs() and raises clear error messages
- Updates exception handlers to propagate external reference errors while preserving other error handling
- Adds comprehensive test coverage for external reference detection
- Provides helpful error messages explaining that FastMCP only supports local schema references
Fixes #926
🤖 Generated with [Claude Code](https://claude.ai/code )
Co-Authored-By: Claude <noreply@anthropic.com>
2025-06-25 21:25:06 -04:00
Owen W. Taylor
14d1b8a94d
openapi: Rewrite recursive #/components/schemas/ references
...
When a schema referenced another schema as #/components/schemas/...
that wasn't properly rewritten into #/$defs/..
2025-06-20 14:34:47 -04:00
Jeremiah Lowin
a8c309f59f
Make sure tests are atomic
2025-06-04 10:29:25 -04:00
ShiWei
82a987b900
add tests for _replace_ref_with_defs
2025-06-04 09:23:37 +08:00
ShiWei
6baa906813
replace nested requestBody's #/components/ with
2025-06-04 08:54:55 +08:00
Jeremiah Lowin
213abc4244
Pass client headers through to OpenAPI client
2025-05-23 12:38:24 -04:00
Jeremiah Lowin
ff318e655d
Add reprs for OpenAPI objects
2025-05-14 13:42:20 -04:00
Jeremiah Lowin
56801435ac
Support openapi 3.0 and 3.1
2025-04-13 22:38:37 -04:00
Jeremiah Lowin
79190e40e9
Ensure that openapi tags are transferred to MCP objects
2025-04-12 12:40:57 -04:00
zzstoatzz
16af43e272
use type
2025-04-11 03:42:00 -05:00
Jeremiah Lowin
9ca99d5809
Add OpenAPI server and tests
2025-04-10 11:16:58 -04:00
Jeremiah Lowin
a683abb8a3
Add openapi parsing utilities
2025-04-08 21:11:52 -04:00