modelcontextprotocol / modelcontextprotocol/python-sdk

Authentication in High Level MCPServer

Ouverte
#3,283 3 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

P3 question v1 v2
Langage dominant
Python
Étoiles
24.3k
Forks
4k
Merge moyen
1 j 1 h
PR mergées (30 j)
31

Description

Question

I'm trying to understand the authentication model in the new MCP Python SDK v2.

I want to implement the simplest possible authentication for a remote Streamable HTTP MCP server:

  1. The server has a pre-configured bearer token.
  2. The client sends Authorization: Bearer <token>.
  3. The server verifies the token.
  4. If valid, the MCP request is allowed.
  5. There is no OAuth login flow and no Authorization Server involved.

I initially tried using TokenVerifier:

class StaticTokenVerifier(TokenVerifier):
    async def verify_token(self, token: str) -> AccessToken | None:
        if token == ACCESS_TOKEN:
            return AccessToken(token=token)

        return None

However, MCPServer requires AuthSettings whenever a token_verifier is supplied. AuthSettings in my version requires both issuer_url and resource_server_url.

I don't understand why issuer_url is required for this use case. There is no Authorization Server issuing the token—the token is simply pre-configured on the MCP server.

Adding AuthSettings also appears to cause the client to enter the OAuth discovery/authorization flow. For example, I encountered:

The connection is now reaching the OAuth authorization step,
but this server does not implement an /authorize endpoint.

I also encountered a protected-resource URL validation error when the URL differed only by localhost vs 127.0.0.1:

Protected resource [http://localhost:10000/mcp] does not match expected
[http://127.0.0.1:10000/mcp] (or origin)

My understanding is that TokenVerifier and the OAuth discovery/authorization-server configuration are separate concerns. The low-level SDK code appears to support BearerAuthBackend(token_verifier) independently, while resource_server_url is used for protected-resource metadata.

Is there a supported way in MCP Python SDK v2 to implement simple bearer-token authentication for Streamable HTTP without configuring an OAuth Authorization Server and without having to implement or manually compose Starlette middleware?

In other words, I'm looking for the equivalent of:

HTTP Request
     ↓
Authorization: Bearer alice-token
     ↓
TokenVerifier
     ↓
valid → MCP request
invalid → 401

without requiring:

Authorization Server
    ↓
/authorize
/token
OAuth discovery
issuer_url
resource_server_url

Is this supported by the high-level MCPServer API, or is OAuth intentionally a prerequisite for using TokenVerifier?

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Commencez par la configuration d’authentification de haut niveau de MCPServer et comparez-la au parcours de bas niveau de BearerAuthBackend et TokenVerifier décrit dans l’issue. Déterminez pourquoi AuthSettings, issuer_url et resource_server_url sont requis ; le travail est terminé lorsqu’une configuration prise en charge est identifiée ou qu’une lacune ciblée de l’API est confirmée.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
api, authentication, backend-api-design
Type d'issue
Fonctionnalité
Difficulté
4/5
Temps estimé
3-5 jours
Activité
Calme
Clarté
À clarifier
Accessibilité débutants
38/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.