mirror of
https://github.com/PrefectHQ/fastmcp.git
synced 2026-08-09 15:19:10 +02:00
* Add M2M client credentials auth providers Wrap the SDK's client_credentials and private_key_jwt OAuth providers as FastMCP-idiomatic ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, enabling browser-free client authentication via Client(auth=...). * Fix M2M token cache collision and explicit-scope drop Namespace the token cache by client_id so distinct clients sharing one store don't overwrite each other's tokens; pin caller-supplied scopes so the token request keeps them; fix CodeQL URL-substring check in tests; drop unused logger. * Preserve step-up scope union, scope-aware token cache, restore token expiry Only pin the caller's explicit scopes on initial authorization, leaving the SDK's step-up scope union intact; namespace the token cache by requested scopes as well as client_id; restore persisted absolute expiry on init so an expired stored token is re-fetched. * Skip expiry restore for non-expiring reloaded tokens * Distinguish expires_in=0 from omitted when restoring expiry * Scope step-up flag to the flow via ContextVar; runnable JWT signing example |
||
|---|---|---|
| .. | ||
| .cursor/rules | ||
| apps | ||
| assets | ||
| cli | ||
| clients | ||
| community | ||
| css | ||
| deployment | ||
| development | ||
| getting-started | ||
| integrations | ||
| more | ||
| patterns | ||
| public/schemas/fastmcp.json | ||
| python-sdk | ||
| servers | ||
| snippets | ||
| tutorials | ||
| v2 | ||
| .ccignore | ||
| changelog.mdx | ||
| docs.json | ||
| fastmcp-analytics.js | ||
| prefab-demo-payloads.js | ||
| python-sdk-pages.json | ||
| unify-intent.js | ||
| updates.mdx | ||
| v2-banner.js | ||
| v2-navigation.json | ||