[Server] Expose request-level metadata (e.g., securitySchema) to tool handlers
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Start by tracing the server's tool dispatching layer and how the incoming request envelope reaches tool handlers; the issue does not name specific files or tests. Compare injecting CallToolRequest with injecting the meta section, then add coverage showing a handler can read securitySchema and that existing parameter-only handlers still work.
Written by the indexing model from the issue text.
Description
Is your feature request related to a problem? Please describe.
Tool handlers currently receive only the parameters defined for the tool call.
Metadata included in the request envelope (for example a securitySchema) is not available inside the handler.
This makes it impossible to perform logic that depends on contextual information from the request itself.
Describe the solution you’d like
A way for tool handlers to access the metadata from the incoming request envelope.
This could be done by injecting either the full request object or just the meta section into the handler method.
Having this information available would allow tools to perform authorization checks, tenant selection, and similar context-dependent actions.
Describe alternatives you’ve considered
The only workaround at the moment is extracting envelope metadata before the request reaches the tool dispatching layer and storing it somewhere manually.
Once inside the handler, that information can no longer be accessed in a clean or reliable way.
Additional context
A common use case is reading a securitySchema sent by the client.
This information is part of the envelope, not part of the tool parameters, and is therefore currently inaccessible inside tool logic.
What tool handlers currently look like
use MCP\Server\Attributes\McpTool;
final class ExampleTools
{
#[McpTool(name: 'example_action')]
public function exampleAction(string $input): array
{
// Only defined parameters are available.
// Envelope metadata (e.g., securitySchema) cannot be accessed here.
return ['result' => 'ok'];
}
}
Proposed Option A — Inject full request object
use MCP\Server\Attributes\McpTool;
use MCP\Types\CallToolRequest;
final class ExampleTools
{
#[McpTool(name: 'example_action')]
public function exampleAction(
string $input,
CallToolRequest $request,
): array {
$meta = $request->meta ?? null;
$schema = $meta['securitySchema'] ?? null;
return [
'result' => 'ok',
'securitySchema' => $schema,
];
}
}
Proposed Option B — Inject only the meta section
use MCP\Server\Attributes\McpTool;
final class ExampleTools
{
#[McpTool(name: 'example_action')]
public function exampleAction(
string $input,
array $meta = [],
): array {
$schema = $meta['securitySchema'] ?? null;
return [
'result' => 'ok',
'securitySchema' => $schema,
];
}
}
- Dominant language
- PHP
- Stars
- 1.6k
- Forks
- 173
- Avg merge
- 2d 49m
- Merged PRs (30d)
- 23
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from modelcontextprotocol/php-sdk
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStan OpenServer
Difficulty 1/5 Under an hour Newbie friendliness 78/100
modelcontextprotocol/php-sdk#468 · 2 comments ·
-
needs confirmation needs maintainer action Server
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
modelcontextprotocol/php-sdk#398 · 1 reaction ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
modelcontextprotocol/php-sdk#370 ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 55/100
modelcontextprotocol/php-sdk#510 · 1 comment ·
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 45/100
modelcontextprotocol/php-sdk#504 ·
All issues in modelcontextprotocol/php-sdk
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
-
a11y admissions.uiowa.edu needs grooming SiteImprove best practice
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Save States Menu Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
pluginsGLPI/datainjection#673 ·