mirror of
https://github.com/PrefectHQ/fastmcp.git
synced 2026-08-10 23:59:10 +02:00
* Update docs for required scopes * add scopes * Fix Azure scope validation Azure returns unprefixed scopes in JWT tokens but requires prefixed scopes in authorization requests. The previous implementation incorrectly validated tokens against prefixed scopes, causing "invalid_token" errors. Simplified AzureProvider to use standard JWTVerifier with unprefixed scopes for validation. Scopes are only prefixed when building the Azure authorization URL via _build_upstream_authorize_url() override. Closes #2263
44 lines
1.6 KiB
Python
44 lines
1.6 KiB
Python
"""Azure (Microsoft Entra) OAuth server example for FastMCP.
|
|
|
|
This example demonstrates how to protect a FastMCP server with Azure/Microsoft OAuth.
|
|
|
|
Required environment variables:
|
|
- AZURE_CLIENT_ID: Your Azure application (client) ID
|
|
- AZURE_CLIENT_SECRET: Your Azure client secret
|
|
- AZURE_TENANT_ID: Tenant ID
|
|
Options: "organizations" (work/school), "consumers" (personal), or specific tenant ID
|
|
- AZURE_REQUIRED_SCOPES: At least one scope required (e.g., "read" or "read,write")
|
|
These must match scope names created under "Expose an API" in your Azure App registration
|
|
|
|
To run:
|
|
python server.py
|
|
"""
|
|
|
|
import os
|
|
|
|
from fastmcp import FastMCP
|
|
from fastmcp.server.auth.providers.azure import AzureProvider
|
|
|
|
auth = AzureProvider(
|
|
client_id=os.getenv("FASTMCP_SERVER_AUTH_AZURE_CLIENT_ID") or "",
|
|
client_secret=os.getenv("FASTMCP_SERVER_AUTH_AZURE_CLIENT_SECRET") or "",
|
|
tenant_id=os.getenv("FASTMCP_SERVER_AUTH_AZURE_TENANT_ID")
|
|
or "", # Required for single-tenant apps - get from Azure Portal
|
|
base_url="http://localhost:8000",
|
|
required_scopes=["read"],
|
|
# required_scopes is automatically loaded from FASTMCP_SERVER_AUTH_AZURE_REQUIRED_SCOPES
|
|
# At least one scope is required - use unprefixed scope names from your Azure App (e.g., ["read", "write"])
|
|
# redirect_path="/auth/callback", # Default path - change if using a different callback URL
|
|
)
|
|
|
|
mcp = FastMCP("Azure OAuth Example Server", auth=auth)
|
|
|
|
|
|
@mcp.tool
|
|
def echo(message: str) -> str:
|
|
"""Echo the provided message."""
|
|
return message
|
|
|
|
|
|
if __name__ == "__main__":
|
|
mcp.run(transport="http", port=8000)
|