modelcontextprotocol / modelcontextprotocol/python-sdk

Protected Resource Metadata resource erroneous when setting up authentication on server

未关闭
#1,264 7 条评论 2 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

auth bug P2 ready for work
主要语言
Python
星标
24.3k
派生
4k
平均合并
1 天 1 小时
30 天内合并 PR
31

描述

Initial Checks
Description

I am getting the following error when I try to enable MCP server authentication and configure it in VSCODE copilot:

Error Error sending message to http://localhost:8000/mcp: Error: Protected Resource Metadata resource "http://localhost:8000/" does not match MCP server resolved resource "http://localhost:8000/mcp". The MCP server must follow OAuth spec https://datatracker.ietf.org/doc/html/rfc9728#PRConfigurationValidation

From what I have seen, the error is caused because the metada that is returned in the endpoint "/.well-known/oauth-protected-resource" in the resource field does not match the url of the MCP server to be configured to use copilot and what is specified in the definition if they should match. You can see here https://datatracker.ietf.org/doc/html/rfc9728#PRConfigurationValidation

I have made a small snippet of code available here https://github.com/carlosemart/python-mcp-oauth-example in which you can see that the well-know answer is:

{
    "resource": "http://localhost:8000/",
    "authorization_servers": [
        "https://auth.example.com/"
    ],
    "scopes_supported": [
        "user"
    ],
    "bearer_methods_supported": [
        "header"
    ]
}

and in the resource field you should see "http://localhost:8000/mcp" which is the url that is configured in VSCODE.

Example Code
from mcp.server.auth.provider import AccessToken, TokenVerifier
from mcp.server.auth.settings import AuthSettings
from mcp.server.fastmcp import FastMCP
from pydantic import AnyHttpUrl


class SimpleTokenVerifier(TokenVerifier):
    """Simple token verifier for demonstration."""

    async def verify_token(self, token: str) -> AccessToken | None:
        return AccessToken(
            token=token,
            scopes=["user"],
        )


# Create an MCP server
mcp = FastMCP(
    "Demo",
    stateless_http=True,
    # Token verifier for authentication
    token_verifier=SimpleTokenVerifier(),
    # Auth settings for RFC 9728 Protected Resource Metadata
    auth=AuthSettings(
        issuer_url=AnyHttpUrl("https://auth.example.com"),  # Authorization Server URL
        resource_server_url=AnyHttpUrl("http://localhost:8000"),  # This server's URL
        required_scopes=["user"],
    ),
)


# Add an addition tool
@mcp.tool()
def add(a: int, b: int) -> int:
    """Add two numbers"""
    return a + b


# Add a dynamic greeting resource
@mcp.resource("greeting://{name}")
def get_greeting(name: str) -> str:
    """Get a personalized greeting"""
    return f"Hello, {name}!"


# Add a prompt
@mcp.prompt()
def greet_user(name: str, style: str = "friendly") -> str:
    """Generate a greeting prompt"""
    styles = {
        "friendly": "Please write a warm, friendly greeting",
        "formal": "Please write a formal, professional greeting",
        "casual": "Please write a casual, relaxed greeting",
    }

    return f"{styles.get(style, styles['friendly'])} for someone named {name}."


def main():
    """Entry point for the direct execution server."""
    mcp.run(transport="streamable-http")


if __name__ == "__main__":
    main()


Python & MCP Python SDK
Tested with python version 3.11.9 and 3.12.5, and MCP Python SDK 1.12.4 version

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 AuthSettings 和 issue 中描述的受保护资源元数据端点开始,然后使用提供的 Python 示例和 streamable-HTTP 服务器复现该行为。将配置的 MCP URL 与元数据资源值进行比较,并参考 RFC 9728 的验证要求。当元数据报告配置的 /mcp 资源,且身份验证设置不再触发不匹配错误时,即表示完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
api, authentication
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
活跃
描述清晰度
基本清楚
新手友好度
58/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。