fastmcp/tests/contrib
Jeremiah Lowin dad8b32eb9
Use the server's auth provider for component manager routes (#5425)
The component manager's enable and disable routes now use the same auth provider as the HTTP app that serves them, so they follow the same rules as the server's MCP endpoint. This also works for mounted servers, whose routes are served by the parent's app, and for apps built directly with `create_streamable_http_app(..., auth=...)` or `create_sse_app(..., auth=...)`. `required_scopes` adds scopes on top of the server's own; an empty list means "authenticated, no extra scopes". Routes with `required_scopes` on an app without an auth provider return 401. A server with no auth keeps open routes, like its MCP endpoint.

Each route is wrapped individually, and custom routes registered after the component manager are served normally.

```python
from fastmcp import FastMCP
from fastmcp.contrib.component_manager import set_up_component_manager
from fastmcp.server.auth.providers.jwt import StaticTokenVerifier

auth = StaticTokenVerifier(tokens={"token": {"client_id": "ops", "scopes": ["admin"]}})
mcp = FastMCP("svc", auth=auth)

set_up_component_manager(server=mcp, required_scopes=["admin"])
```

Co-authored-by: Bill Easton <williamseaston@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-10-04 10:14:42 -04:00
..
__init__.py Updates based on PR Feedback 2025-04-16 23:30:09 -05:00
test_bulk_tool_caller.py Migrate to MCP Python SDK v2 (#4437) 2026-07-06 17:36:45 -04:00
test_component_manager.py Use the server's auth provider for component manager routes (#5425) 2026-10-04 10:14:42 -04:00
test_mcp_mixin.py Migrate to MCP Python SDK v2 (#4437) 2026-07-06 17:36:45 -04:00