fastmcp/examples/auth/keycloak_oauth
Jeremiah Lowin 7d76c9d055
Add examples/ to the ty static-analysis gate (#4466)
* Add examples/ to ty static-analysis gate

* Fix example type errors and stale SDK idioms for ty

* Use typing_extensions.TypedDict for the quiz tool-param type

Question is a take_quiz parameter, so FastMCP builds a Pydantic schema
for it; typing.TypedDict raises PydanticUserError on Python 3.10/3.11
(only 3.12+ accepts it). ty and 3.12 runs miss this, so it slipped in.

* Guard get_access_token() None case in huggingface_oauth example

Caught by the ty gate this PR adds: the example, merged separately,
had never been type-checked against examples/. Matches the existing
aws_oauth/keycloak_oauth pattern.

* Print actual YAML text in custom serializer example
2026-07-18 19:44:13 -04:00
..
client.py AuthKit: auto-bind token audience to resource URL (RFC 8707) (#3905) 2026-04-13 17:11:17 -04:00
README.md AuthKit: auto-bind token audience to resource URL (RFC 8707) (#3905) 2026-04-13 17:11:17 -04:00
server.py Add examples/ to the ty static-analysis gate (#4466) 2026-07-18 19:44:13 -04:00

Keycloak OAuth Example

Demonstrates FastMCP server protection with Keycloak OAuth.

Requires Keycloak 26.6.0 or later with Dynamic Client Registration enabled.

Setup

  1. Configure a Keycloak realm with Dynamic Client Registration enabled and a trusted host policy for your server URL (e.g. http://127.0.0.1:8000/*).

  2. Set environment variables:

    export KEYCLOAK_REALM_URL="http://localhost:8080/realms/your-realm"
    
  3. Run the server:

    python server.py
    
  4. In another terminal, run the client:

    python client.py
    

The client will open your browser for Keycloak authentication.