mirror of
https://github.com/PrefectHQ/fastmcp.git
synced 2026-08-09 15:19:10 +02:00
* Add examples/ to ty static-analysis gate * Fix example type errors and stale SDK idioms for ty * Use typing_extensions.TypedDict for the quiz tool-param type Question is a take_quiz parameter, so FastMCP builds a Pydantic schema for it; typing.TypedDict raises PydanticUserError on Python 3.10/3.11 (only 3.12+ accepts it). ty and 3.12 runs miss this, so it slipped in. * Guard get_access_token() None case in huggingface_oauth example Caught by the ty gate this PR adds: the example, merged separately, had never been type-checked against examples/. Matches the existing aws_oauth/keycloak_oauth pattern. * Print actual YAML text in custom serializer example
61 lines
1.8 KiB
Python
61 lines
1.8 KiB
Python
"""AWS Cognito OAuth server example for FastMCP.
|
|
|
|
This example demonstrates how to protect a FastMCP server with AWS Cognito.
|
|
|
|
Required environment variables:
|
|
- FASTMCP_SERVER_AUTH_AWS_COGNITO_USER_POOL_ID: Your AWS Cognito User Pool ID
|
|
- FASTMCP_SERVER_AUTH_AWS_COGNITO_AWS_REGION: Your AWS region (optional, defaults to eu-central-1)
|
|
- FASTMCP_SERVER_AUTH_AWS_COGNITO_CLIENT_ID: Your Cognito app client ID
|
|
- FASTMCP_SERVER_AUTH_AWS_COGNITO_CLIENT_SECRET: Your Cognito app client secret
|
|
|
|
To run:
|
|
python server.py
|
|
"""
|
|
|
|
import logging
|
|
import os
|
|
|
|
from dotenv import load_dotenv
|
|
|
|
from fastmcp import FastMCP
|
|
from fastmcp.server.auth.providers.aws import AWSCognitoProvider
|
|
from fastmcp.server.dependencies import get_access_token
|
|
|
|
logging.basicConfig(level=logging.DEBUG)
|
|
|
|
load_dotenv(".env", override=True)
|
|
|
|
auth = AWSCognitoProvider(
|
|
user_pool_id=os.getenv("FASTMCP_SERVER_AUTH_AWS_COGNITO_USER_POOL_ID") or "",
|
|
aws_region=os.getenv("FASTMCP_SERVER_AUTH_AWS_COGNITO_AWS_REGION")
|
|
or "eu-central-1",
|
|
client_id=os.getenv("FASTMCP_SERVER_AUTH_AWS_COGNITO_CLIENT_ID") or "",
|
|
client_secret=os.getenv("FASTMCP_SERVER_AUTH_AWS_COGNITO_CLIENT_SECRET") or "",
|
|
base_url="http://127.0.0.1:8000",
|
|
# redirect_path="/custom/callback"
|
|
)
|
|
|
|
mcp = FastMCP("AWS Cognito OAuth Example Server", auth=auth)
|
|
|
|
|
|
@mcp.tool
|
|
def echo(message: str) -> str:
|
|
"""Echo the provided message."""
|
|
return message
|
|
|
|
|
|
@mcp.tool
|
|
async def get_access_token_claims() -> dict:
|
|
"""Get the authenticated user's access token claims."""
|
|
token = get_access_token()
|
|
if token is None:
|
|
return {"error": "Not authenticated"}
|
|
return {
|
|
"sub": token.claims.get("sub"),
|
|
"username": token.claims.get("username"),
|
|
"cognito:groups": token.claims.get("cognito:groups", []),
|
|
}
|
|
|
|
|
|
if __name__ == "__main__":
|
|
mcp.run(transport="http", port=8000)
|