- Add null checks for client_id before using in OAuthTransaction, AuthorizationCode, AccessToken, RefreshToken
- Add null check for redirect_uris before len() call
- Import AuthorizeError from mcp.server.auth.provider
- Add scope validation to InMemoryOAuthProvider.register_client() to match MCP SDK behavior
- Ensures unit tests catch scope-related bugs like the MCP SDK 1.21.1 issue
- Remove debug breakpoint from OAuth client redirect_handler
- Add null checks for client_id before using in OAuthTransaction, AuthorizationCode, AccessToken, RefreshToken
- Add null check for redirect_uris before len() call
- Import AuthorizeError from mcp.server.auth.provider
- Add scope validation to InMemoryOAuthProvider.register_client() to match MCP SDK behavior
- Ensures unit tests catch scope-related bugs like the MCP SDK 1.21.1 issue
- Remove debug breakpoint from OAuth client redirect_handler
The on_initialize hook (2.13.0) runs before the MCP session is established, causing request_context
to be unavailable. Changed request_context to return None instead of raising, allowing middleware to
check availability and use HTTP helpers when needed. Updated docs to guide this pattern.
Closes#2393
* fix(OpenAPIParser): Fix missing for response schemas in experimental OpenAPI parser
* chore: run linting
---------
Co-authored-by: Christoph Netsch <netsch@alpamayo.ch>
* docs: clarify pytest-asyncio dependency and asyncio mode configuration
Added a Prerequisites section to the testing documentation explaining:
- pytest-asyncio is required for async test functions and fixtures
- Recommended configuration: asyncio_mode = 'auto' in pyproject.toml
- This eliminates need for @pytest.mark.asyncio decorators
Resolves#2372
Co-authored-by: William Easton <strawgate@users.noreply.github.com>
* feat: add testing_demo example with comprehensive test suite
Add a standalone example project demonstrating FastMCP testing patterns:
- Tools, resources, and prompts with full test coverage
- pytest-asyncio configuration in pyproject.toml
- 18 passing tests showing async fixtures, parametrized tests, and more
- Documentation explaining testing best practices
Co-authored-by: William Easton <strawgate@users.noreply.github.com>
---------
Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: William Easton <strawgate@users.noreply.github.com>
custom oauth providers sometimes require extra parameters in their token calls, hence the need for the _extra_token_params in the inital token request. This PR includes those extra token params in the token refresh request too.
Allow traceback-related kwargs to override defaults by building a dict
with defaults first, then updating with user-provided values.
Fixes#2356
Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: William Easton <strawgate@users.noreply.github.com>
OAuth consent tests were timing out on Windows due to SQLite database
locking when OAuthProxy instances used the default DiskStore without
explicit MemoryStore configuration. Added explicit client_storage=MemoryStore()
to three tests in TestConsentPageServerIcon.
Also restored parallel testing on Windows (--numprocesses auto) which
was previously disabled but is now safe with proper test isolation.
* Fix consent form action for subpath mounting
When a FastMCP server is mounted at a subpath (e.g., /api/v1), the consent
form used a hardcoded absolute path (/consent/submit) that didn't include
the mount prefix, causing 404 errors on submission.
Changed the form to use an empty action (action="") which submits to the
current URL, making it work correctly regardless of mount path. Also
consolidated the consent endpoints to handle both GET and POST at /consent.
Fixes#2380
* Update integration test to use /consent instead of /consent/submit
* Allow OAuth instance to use the same httpx factory as the Transport
* Fix test
* Update SSL verification mode assertion in tests
* This is actually not needed
* Creating a Client instance is not needed for this test
* Fix test
* Apply httpx_client_factory fix to SSETransport
Extends the OAuth httpx_client_factory changes to SSETransport.
SSETransport had the same issues as StreamableHttpTransport where it
wasn't passing the custom httpx client factory to OAuth, causing
certificate verification settings to be ignored during OAuth flows.
Changes:
- Set httpx_client_factory before calling _set_auth()
- Pass httpx_client_factory to OAuth constructor
- Add test for SSETransport OAuth client factory propagation
---------
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
* Fix OAuth metadata endpoint URLs when base_url differs from issuer_url
OAuth operational endpoints (/authorize, /token) are mounted at base_url,
but metadata was incorrectly declaring them at issuer_url. This caused
clients following the documented mounting pattern to receive incorrect
endpoint URLs in /.well-known/oauth-authorization-server.
Fixes#2287
* Update auth.py
* Remove unnecessary assertion from OAuthProvider init
* Add info log when issuer_url differs from base_url
* feat: Add optional meta parameter to Client tool call methods
* fix: Add support for mcp<1.19
* chore: cleaner solution
* Refactor call_tool to directly accept meta parameter and add tests for meta functionality
---------
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
* Add manual initialization control to Client
- Add auto_initialize parameter (default True) to control automatic initialization
- Make initialize() method public with idempotent caching
- Add comprehensive test suite for initialization behavior
* Document client initialization control and server instructions
- Expand documentation to cover auto_initialize parameter
- Show manual initialization for advanced use cases
- Document accessing server instructions via initialize_result
* Update client.mdx
* Bump ty to >=0.0.1a25 with type fixes
Follow-up to #2295. Updates ty and fixes compatibility issues with alpha 25, including:
- Updated ignore comment syntax (possibly-unbound-attribute → possibly-missing-attribute)
- Fixed async generator type handling with anext()
- Fixed type narrowing for timeout parameters
- Converted base_url assignments to AnyHttpUrl after string manipulation
- Added CallToolResult to return type annotations
- Removed redundant type casts
- Fixed test form data to use strings instead of bytes
ty alpha 25 has limitations with isinstance() narrowing on unions (see pyproject.toml for details), requiring some targeted type ignores.
* Pin ty to ==0.0.1a25
Alpha releases can have breaking changes, so pin to the tested version.
* 🤖 Security: Validate Cursor deeplink URLs and replace cmd.exe on Windows
- Add URL scheme validation to reject non-cursor:// URLs
- Replace subprocess cmd.exe call with os.startfile() on Windows
- Add tests for scheme validation and error handling
* 🤖 Fix tests for cross-platform deeplink validation
* switch from pre-commit to prek
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
* fix prek tools list in contributing.mdx - include prettier, not pytest
* Use prek-action for caching
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
- Restructured confusing sections: 'Object-like Results' → 'Dictionaries and Objects', 'Non-object Results' → 'Primitives and Collections', 'Complex Type Example' → 'Typed Models'
- Simplified CodeGroup examples to show Tool Definition + MCP Result instead of 3-4 confusing tabs
- Split Primitives/Collections into separate CodeGroups for clarity
- Renamed 'Full Control with ToolResult' → 'ToolResult and Metadata' for better TOC visibility
- Flattened ToolResult documentation with inline field descriptions instead of nested headings
- Added version badge for ToolResult meta field (2.13.1)
- Added clarification that ToolResult meta is separate from @mcp.tool meta
- Improved example server with realistic metadata (execution time, character/word counts)
- Fixed code formatting (multi-line objects, trailing commas)
* Add meta to ToolResult
* add this at the client level and test the full integration
* add example
* slipped through linting somehow
---------
Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>
Updates authlib from 1.6.1 to 1.6.5 to address CVE-2025-61920, which
fixes a denial of service vulnerability in JOSE implementation that
accepts unbounded JWS/JWT header and signature segments.
* Mark flaky Windows test for retry
test_multi_client_transform_with_filtering occasionally times out on Windows CI during exception formatting in linecache.checkcache(). Add @pytest.mark.flaky with 3 retries.
* Remove unnecessary delay from flaky marker