mirror of
https://github.com/PrefectHQ/fastmcp.git
synced 2026-10-09 14:33:21 +02:00
The component manager's enable and disable routes now use the same auth provider as the HTTP app that serves them, so they follow the same rules as the server's MCP endpoint. This also works for mounted servers, whose routes are served by the parent's app, and for apps built directly with `create_streamable_http_app(..., auth=...)` or `create_sse_app(..., auth=...)`. `required_scopes` adds scopes on top of the server's own; an empty list means "authenticated, no extra scopes". Routes with `required_scopes` on an app without an auth provider return 401. A server with no auth keeps open routes, like its MCP endpoint.
Each route is wrapped individually, and custom routes registered after the component manager are served normally.
```python
from fastmcp import FastMCP
from fastmcp.contrib.component_manager import set_up_component_manager
from fastmcp.server.auth.providers.jwt import StaticTokenVerifier
auth = StaticTokenVerifier(tokens={"token": {"client_id": "ops", "scopes": ["admin"]}})
mcp = FastMCP("svc", auth=auth)
set_up_component_manager(server=mcp, required_scopes=["admin"])
```
Co-authored-by: Bill Easton <williamseaston@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
|
||
|---|---|---|
| .. | ||
| __init__.py | ||
| test_bulk_tool_caller.py | ||
| test_component_manager.py | ||
| test_mcp_mixin.py | ||