Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Authentication in High Level MCPServer

Offen
#3,283 3 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
38/100
Issue-Typ
Feature
Klarheit
Muss geklärt werden
Aktivitätsstatus
Ruhig
Tech-Stack
python

Rechercherichtung

Beginne mit der übergeordneten MCPServer-Authentifizierungskonfiguration und vergleiche sie mit dem im Issue beschriebenen Pfad über BearerAuthBackend und TokenVerifier. Verfolge, warum AuthSettings, issuer_url und resource_server_url erforderlich sind; als abgeschlossen gilt die Untersuchung, wenn eine unterstützte Konfiguration identifiziert oder eine gezielte API-Lücke bestätigt wurde.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

P3 question v1 v2

Question

I'm trying to understand the authentication model in the new MCP Python SDK v2.

I want to implement the simplest possible authentication for a remote Streamable HTTP MCP server:

  1. The server has a pre-configured bearer token.
  2. The client sends Authorization: Bearer <token>.
  3. The server verifies the token.
  4. If valid, the MCP request is allowed.
  5. There is no OAuth login flow and no Authorization Server involved.

I initially tried using TokenVerifier:

class StaticTokenVerifier(TokenVerifier):
    async def verify_token(self, token: str) -> AccessToken | None:
        if token == ACCESS_TOKEN:
            return AccessToken(token=token)

        return None

However, MCPServer requires AuthSettings whenever a token_verifier is supplied. AuthSettings in my version requires both issuer_url and resource_server_url.

I don't understand why issuer_url is required for this use case. There is no Authorization Server issuing the token—the token is simply pre-configured on the MCP server.

Adding AuthSettings also appears to cause the client to enter the OAuth discovery/authorization flow. For example, I encountered:

The connection is now reaching the OAuth authorization step,
but this server does not implement an /authorize endpoint.

I also encountered a protected-resource URL validation error when the URL differed only by localhost vs 127.0.0.1:

Protected resource [http://localhost:10000/mcp] does not match expected
[http://127.0.0.1:10000/mcp] (or origin)

My understanding is that TokenVerifier and the OAuth discovery/authorization-server configuration are separate concerns. The low-level SDK code appears to support BearerAuthBackend(token_verifier) independently, while resource_server_url is used for protected-resource metadata.

Is there a supported way in MCP Python SDK v2 to implement simple bearer-token authentication for Streamable HTTP without configuring an OAuth Authorization Server and without having to implement or manually compose Starlette middleware?

In other words, I'm looking for the equivalent of:

HTTP Request
     ↓
Authorization: Bearer alice-token
     ↓
TokenVerifier
     ↓
valid → MCP request
invalid → 401

without requiring:

Authorization Server
    ↓
/authorize
/token
OAuth discovery
issuer_url
resource_server_url

Is this supported by the high-level MCPServer API, or is OAuth intentionally a prerequisite for using TokenVerifier?

Vorherrschende Sprache
Python
Sterne
24.3k
Forks
4k
Ø Merge
1 T. 11 Std.
Gemergte PRs (30 T.)
30

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus modelcontextprotocol/python-sdk

Alle Issues in modelcontextprotocol/python-sdk

Ähnliche Issues

Weitere Issues zu Python

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.