Python: Foundry Hosting: preserve standard MCP approval identity across continuation
Maintainers usually reply within 1 day
@eavanvalkenburg is already working on this.
Since Sep 18, 2026.
Assessment
This issue has not been assessed yet.
Description
Foundry Hosting drops the standard Responses approval_request_id relationship when converting a provider MCP call into an outbound response. Clients consequently cannot identify which approval authorized that call.
Observed behavior
Reproduced with agent-framework-core 1.17.0, agent-framework-foundry-hosting 1.0.0b260910 and azure-ai-agentserver-responses 2.2.0b1. The same emission paths were also inspected at commit 0ad2e44.
- The provider MCP call carries
approval_request_idin the original item retained byContent.raw_representation. _OutputItemTracker._open_mcp_callpasses server label, tool name and item ID to the response builder, but omits the approval link.- Hosting generates a new outbound ID for
mcp_approval_requestand stores that ID with the original approval content for incoming decisions. Copying the provider's original approval ID unchanged would therefore be insufficient when the outbound approval has a different ID.
For example: a provider issues approval A, Hosting exposes approval B, and the client approves B. The provider must receive the decision for A. When its subsequent mcp_call refers to A, the outbound call must refer to the corresponding approval B that the client received. Currently that outbound relationship is lost.
Expected behavior
Preserve the explicit approval relationship through incremental events, terminal snapshots, stored history and continuation. Both incoming decisions and outgoing call references must use the appropriate identities for their side of the transport boundary. Do not reconstruct identity from matching names, arguments or output text.
The relationship is defined by the OpenAI Responses MCP contract.
Related SDK change
Azure/azure-sdk-for-python#49037 adds optional approval_request_id support to the MCP builder and preserves it in added/done/terminal output. Hosting still needs to supply the correct outbound approval identity.
Implementation and validation considerations
Confirm whether Hosting should preserve provider IDs or persist an explicit source-to-outbound mapping, including storage scope, collision handling and replay rules. Follow the function-calling loop specification for approval-resume and history changes.
Cover multiple same-name/same-argument approvals, generated outbound IDs, approve/deny, matching call references, restart/replay, and streaming/non-streaming output. This issue concerns existing standard MCP relationships; it does not propose adding a local-function approval field to the protocol.
- Dominant language
- Python
- Stars
- 13.9k
- Forks
- 2.4k
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 440
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/agent-framework
-
.NET python triage
Difficulty 1/5 Under an hour Newbie friendliness 85/100
microsoft/agent-framework#9092 · 1 comment ·
Maintainers usually reply within 1 day
-
Python: raw-data content mappings lose annotations and attachment metadataPossibly taken @moonbox3 claimed this 7 days ago. Openpython triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
microsoft/agent-framework#8632 · 2 comments ·
Maintainers usually reply within 1 day
-
Python: Clarify when to use platformPossibly taken @eavanvalkenburg claimed this 6 days ago. Openpython triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
microsoft/agent-framework#8599 · 1 comment ·
Maintainers usually reply within 1 day
-
.NET Compaction - Update docs to refer to `AIContextProvider` deep divePossibly taken A pull request linked to this issue is open or already merged. Open.NET compaction documentation
Difficulty 1/5 Under an hour Newbie friendliness 82/100
microsoft/agent-framework#4629 · 1 comment ·
Maintainers usually reply within 1 day
-
Python: [Feature]: A deterministic pre-execution verification middleware for agent actions — AgentDojo v2.2 re-run: ASR=0 / FP=0 (open artifacts, full fix-cycle trajectory inside)Possibly taken @eavanvalkenburg claimed this today. Openagents middleware python
microsoft/agent-framework#9132 · 1 assignee ·
Maintainers usually reply within 1 day
All issues in microsoft/agent-framework
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 83/100
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
fabriziosalmi/certmate#1207 ·
Maintainers usually reply within 1 day
-
[work-item] adam-adae-onset-emergence: document the minute-precision datetime coercion (ASTTMF not derivable)Possibly taken @muse-yamaa-bot claimed this today. Openwork-item
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
CommunityToolkit/Aspire#2231 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
volcengine/OpenViking#5711 ·
Maintainers usually reply within 1 day