🚀 The fast, Pythonic way to build MCP servers and clients. https://gofastmcp.com
Find a file
Jeremiah Lowin 67e8448389
[codex] Add OAuthProxy RFC 9207 issuer responses (#4438)
* Add OAuthProxy issuer response parameter

* Cover OAuthProxy issuer error redirects

* Relax host origin guard defaults (#4439)

* Use exact issuer in authorize errors

* Restore HTTP host guard compatibility (#4472)

* Hugging Face Auth Integration (#4385)

Co-authored-by: Jeremiah Lowin <153965+jlowin@users.noreply.github.com>

* Docs: add v3.4.4 changelog entries (#4473)

* Explain unnormalized issuer; cover consent-denial path base_url

* Revert "Merge remote-tracking branch 'origin/release/3.x' into codex/oauth-proxy-rfc9207-issuer"

This reverts commit 9e34b1686c, reversing
changes made to 640dc60fe0.

* Preserve callback query bytes when appending iss/code/state params

add_query_params previously decoded the existing query with parse_qsl
and re-encoded it, mutating opaque or signed query strings (a valueless
?flag became ?flag=, non-UTF-8 percent-encoded bytes got replaced).
Append the newly-encoded params to the existing query string instead of
round-tripping it through parse/encode.

Also fixes a stray bare `httpx` reference in a test that should use
httpx2 following the SDK v2 migration.

* Attach RFC 9207 iss to authorize() success redirects too

AuthorizationHandler only added iss to error redirects from the SDK's
base handler, not to code redirects returned directly by authorize()
overrides that bypass consent/upstream (as GitHub's mocked test does).
Since metadata now unconditionally advertises
authorization_response_iss_parameter_supported, any client-facing
redirect missing iss hard-fails RFC 9207-aware clients.

Also fixes HeadlessOAuth, which parsed code/state from the redirect
but silently dropped iss, so the same regression would have masked
itself across every other provider integration test too.

* Carry RFC 9207 iss through the production OAuth callback path

OAuthProxy advertises authorization_response_iss_parameter_supported and
sends iss on every authorization redirect, but the client's production
callback chain (CallbackResponse -> OAuthCallbackResult -> OAuth.callback_handler)
had no iss field, so it was silently dropped and the SDK's
validate_authorization_response_iss rejected the callback. HeadlessOAuth
already carried iss through, which is why CI stayed green while real
clients failed.

Add iss to CallbackResponse and OAuthCallbackResult, thread it through
store_result_once for both success and error branches, and pass it into
AuthorizationCodeResult in OAuth.callback_handler.

* Don't duplicate iss when a provider redirect already carries one

* Consolidate RFC 9207 iss handling into a single redirect helper

Every client-facing authorization redirect must carry exactly one iss.
That invariant was being enforced by hand at five separate call sites,
each building its own params dict -- which is how the success-redirect
path shipped without iss in the first place, and how a registered
redirect_uri that already carries its own iss could end up duplicated.
Route all five sites through build_client_redirect(), which owns the
idempotent replace-or-append behavior so no caller can get it wrong.

---------

Co-authored-by: shaun smith <1936278+evalstate@users.noreply.github.com>
2026-07-19 09:52:43 -04:00
.claude Raise fastmcp.ValidationError for invalid tool arguments (#4392) 2026-06-27 11:14:20 -04:00
.cursor/rules Add agent skills for testing and code review (#2846) 2026-01-12 11:24:39 -05:00
.github Make examples/ actually trigger the ty gate (#4541) 2026-07-18 20:58:24 -04:00
docs Fix #4292: SSRF guard breaks OAuth/JWKS fetches behind a corporate HTTP proxy (#4412) 2026-07-18 21:42:52 -04:00
examples Fix-issue-4284 : Add Auth0MCPProvider for Auth0 Auth for MCP (#4411) 2026-07-18 21:15:02 -04:00
fastmcp_remote feat(remote): add --verify flag for TLS certificate verification (#4369) 2026-06-24 12:09:22 -04:00
fastmcp_slim [codex] Add OAuthProxy RFC 9207 issuer responses (#4438) 2026-07-19 09:52:43 -04:00
scripts Exempt maintainers from MRE auto-close (#4220) 2026-05-23 09:02:44 -04:00
skills/fastmcp-client-cli Add fastmcp discover and name-based server resolution (#3055) 2026-02-01 21:27:22 -05:00
tests [codex] Add OAuthProxy RFC 9207 issuer responses (#4438) 2026-07-19 09:52:43 -04:00
v3-notes docs: fix stale get_* references, now list_* (#3168) 2026-02-12 13:45:49 -06:00
.ccignore Update .ccignore 2025-06-30 18:41:04 -04:00
.coderabbit.yaml Exclude auto-generated python-sdk docs from CodeRabbit reviews (#3206) 2026-02-17 18:28:20 -05:00
.gitignore chore: gitignore .claude/worktrees/ (#3529) 2026-03-16 14:50:15 -04:00
.pre-commit-config.yaml Make examples/ actually trigger the ty gate (#4541) 2026-07-18 20:58:24 -04:00
.python-version Initial commit 2024-11-29 16:42:40 -05:00
AGENTS.md reverse CLAUDE.md/AGENTS.md symlink direction (#3294) 2026-02-25 11:18:59 -05:00
CLAUDE.md Migrate to MCP Python SDK v2 (#4437) 2026-07-06 17:36:45 -04:00
CODE_OF_CONDUCT.md Create CODE_OF_CONDUCT.md (#1523) 2025-08-16 16:28:15 -04:00
CONTRIBUTING.md Clarify PR-reopen flow and fix label-race that broke auto-reopen (#4518) 2026-07-17 17:43:05 -04:00
justfile Add fastmcp-slim for client-only installs (#4122) 2026-05-11 17:13:21 -04:00
LICENSE Basic cleanup 2025-04-05 17:39:51 -04:00
logo.py Update CLI logo (#2220) 2025-10-22 21:29:04 -04:00
loq.toml fix(resources): round-trip path values with reserved characters in URI templates (#4368) 2026-06-24 13:56:04 -04:00
pyproject.toml Add examples/ to the ty static-analysis gate (#4466) 2026-07-18 19:44:13 -04:00
README.md fix: Trendshift link and badge in README.md (#4236) 2026-05-26 14:18:15 -04:00
SECURITY.md Update security policy (#3521) 2026-03-15 14:12:17 -04:00
uv.lock Migrate to MCP SDK v2.0.0b2 (httpx2) (#4503) 2026-07-18 15:12:47 -04:00

FastMCP Logo

FastMCP 🚀

Move fast and make things.

Made with 💙 by Prefect

Docs Discord PyPI - Version Tests License

prefecthq%2Ffastmcp | Trendshift


The Model Context Protocol (MCP) connects LLMs to tools and data. FastMCP gives you everything you need to go from prototype to production:

from fastmcp import FastMCP

mcp = FastMCP("Demo 🚀")

@mcp.tool
def add(a: int, b: int) -> int:
    """Add two numbers"""
    return a + b

if __name__ == "__main__":
    mcp.run()

Why FastMCP

Building an effective MCP application is harder than it looks. FastMCP handles all of it. Declare a tool with a Python function, and the schema, validation, and documentation are generated automatically. Connect to a server with a URL, and transport negotiation, authentication, and protocol lifecycle are managed for you. You focus on your logic, and the MCP part just works: with FastMCP, best practices are built in.

That's why FastMCP is the standard framework for working with MCP. FastMCP 1.0 was incorporated into the official MCP Python SDK in 2024. Today, the actively maintained standalone project is downloaded a million times a day, and some version of FastMCP powers 70% of MCP servers across all languages.

FastMCP has three pillars:

Servers
Servers

Expose tools, resources, and prompts to LLMs.
Apps
Apps

Give your tools interactive UIs rendered directly in the conversation.
Clients
Clients

Connect to any MCP server — local or remote, programmatic or CLI.

Servers wrap your Python functions into MCP-compliant tools, resources, and prompts. Clients connect to any server with full protocol support. And Apps give your tools interactive UIs rendered directly in the conversation.

Ready to build? Start with the installation guide or jump straight to the quickstart.

Run FastMCP in production with Horizon

FastMCP is the standard way to build MCP servers. Prefect Horizon is the enterprise MCP gateway for running them safely.

Built by the FastMCP team, Horizon packages the best practices we've learned shipping the world's most popular MCP framework.

Deploy FastMCP servers from GitHub with branch previews and instant rollback. Create a private registry of every MCP your company uses. Secure access with SSO and tool-level RBAC. Get audit logs, observability, and governance across your MCP stack. Remix approved tools into purpose-built endpoints for teams and agents.

Start with FastMCP. Scale with Horizon →

Installation

We recommend installing FastMCP with uv:

uv pip install fastmcp

For full installation instructions, including verification and upgrading, see the Installation Guide.

Upgrading? We have guides for:

Note

If import fastmcp fails right after a pip upgrade from FastMCP 3.2 or earlier, run pip install --force-reinstall fastmcp. See Troubleshooting for why this happens (uv is unaffected).

📚 Documentation

FastMCP's complete documentation is available at gofastmcp.com, including detailed guides, API references, and advanced patterns.

Documentation is also available in llms.txt format, which is a simple markdown standard that LLMs can consume easily:

  • llms.txt is essentially a sitemap, listing all the pages in the documentation.
  • llms-full.txt contains the entire documentation. Note this may exceed the context window of your LLM.

Community: Join our Discord server to connect with other FastMCP developers and share what you're building.

Contributing

We welcome contributions! See the Contributing Guide for setup instructions, testing requirements, and PR guidelines.