T14 - server MRTR (multi round trip requests) handling
Maintainers usually reply within 4 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 42/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- scala
- Domain
- api, backend, documentation, testing
Research direction
Start with the listed conformance scenarios, especially input-required-result-multi-round, request-state, capability-check, and validate-input, to establish the required behavior across server variants. Then add docs/server/mrtr.md and link it from docs/server/tools.md, docs/server/prompts.md, and docs/server/resources.md. Done means all 13 server scenarios and the three server-stateless MRTR checks pass, with the documented helper and capability rules covered.
Written by the indexing model from the issue text.
Description
Target branch: 2026-07-28-protocol-support
Requires:
A chimp server can ask the client for input while it handles tools/call, prompts/get or resources/read, without keeping any state between the first request and the retry. This follows the Multi Round-Trip Requests pattern that replaces server-initiated requests in 2026-07-28. Legacy clients are not affected.
Requesting input
- A tool, prompt or resource handler can end a request with an input-required outcome instead of a result. The outcome names the input requests under keys the handler chooses, and may carry an opaque request state. The request kinds are form elicitation, URL elicitation, sampling and roots.
- The client receives
resultType: input_requiredwithinputRequestsandrequestState. Onlytools/call,prompts/getandresources/readcan answer this way. Every other request never does. - On the retry the handler reads the client's answers under the same keys, and the request state it produced. A handler that never asks for input behaves as today.
- A handler can ask again on a retry, with a new state, for as many rounds as it needs.
- A handler can read the client's capabilities and choose what to ask for, for example sampling when the client supports it and a form otherwise.
Rules the server enforces, so handlers do not have to
- An input-required outcome carries at least one of input requests or request state.
- No input request reaches a client that did not declare the matching capability. Such a request fails with
-32021,requiredCapabilitiesnaming the missing capability, and HTTP 400. inputResponsesthat are not an object, or whose value does not have the shape of the expected answer, fail with-32602.- Keys in
inputResponsesthat the handler did not ask for are ignored. - A retry that lacks an answer the handler needs leads to a new input-required outcome, not an error. The fixture tools behave this way and the docs recommend it.
- An input-required outcome on a legacy request becomes an internal error with a message that names the required protocol version.
Request state
- Chimp ships a helper that produces and verifies an integrity-protected request state: HMAC-SHA256 over a payload the handler chooses, plus an expiry and an identifier of the originating request, keyed by a secret the server owner provides.
- A state that was changed, has expired, or belongs to another request or principal is rejected with
-32602. The handler never runs on an unverified state when it uses the helper. - The state is opaque to the client and the client echoes it verbatim. The server treats it as untrusted input.
Coverage
- The rules above hold for the sync and streaming servers, over HTTP and stdio, on ZIO, Ox and Pekko.
- The conformance server offers the fixture tools
test_input_required_result_elicitation,test_input_required_result_sampling,test_input_required_result_list_roots,test_input_required_result_request_state,test_input_required_result_multiple_inputs,test_input_required_result_multi_round,test_input_required_result_tampered_state,test_input_required_result_capabilities,test_streaming_elicitation, and the prompttest_input_required_result_prompt. The tooltest_missing_capabilityfrom T8 gets its real behaviour here: it asks for sampling, so a client without that capability gets-32021.
Spec:
- MRTR - Supported Requests
- MRTR - Server Requirements
- MRTR - Error Handling
- MRTR - Security Considerations
- Tools - Input Required Tool Results
- Prompts - Getting a Prompt
- Resources - Reading Resources
- Elicitation - URL Mode Flow
- Basic - Error Codes
Conformance scenarios that must pass after this task:
- Server:
input-required-result-basic-elicitation,input-required-result-basic-sampling,input-required-result-basic-list-roots,input-required-result-request-state,input-required-result-multiple-input-requests,input-required-result-multi-round,input-required-result-missing-input-response,input-required-result-non-tool-request,input-required-result-result-type,input-required-result-tampered-state,input-required-result-capability-check,input-required-result-ignore-extra-params,input-required-result-validate-input. These 13 leave the 2026-07-28 baseline. server-statelessleaves the baseline: its three MRTR checks (sep-2575-server-rejects-undeclared-capability,sep-2575-missing-capability-http-400,sep-2575-http-server-no-independent-requests-on-stream) pass
Docs: yes.
- New page
docs/server/mrtr.md(added to the toctree): how a handler asks for input, how it reads the answers on the retry, the request state helper and the secret it needs, the capability rule, and the advice to ask again instead of failing when an answer is missing. docs/server/tools.md,docs/server/prompts.md,docs/server/resources.md: one line each that points to the new page.
- Dominant language
- Scala
- Stars
- 102
- Forks
- 10
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 13
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from softwaremill/chimp
-
tier:2 SDK
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
softwaremill/chimp#145 ·
Maintainers usually reply within 4 days
-
2026-07-28 version support
Difficulty 5/5 Over a week Newbie friendliness 35/100
softwaremill/chimp#255 ·
Maintainers usually reply within 4 days
-
2026-07-28 version support
Difficulty 5/5 Over a week Newbie friendliness 42/100
softwaremill/chimp#254 ·
Maintainers usually reply within 4 days
-
2026-07-28 version support
Difficulty 5/5 Over a week Newbie friendliness 45/100
softwaremill/chimp#253 ·
Maintainers usually reply within 4 days
-
2026-07-28 version support
Difficulty 5/5 Over a week Newbie friendliness 35/100
softwaremill/chimp#251 ·
Maintainers usually reply within 4 days
All issues in softwaremill/chimp
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
arrays_zip with two same-named inputs fails with "ArrowArray struct has 2 children (expected 1)"Openbug requires-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
apache/datafusion-comet#6251 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
ergoplatform/ergo#2579 ·
Maintainers usually reply within 2 days
-
x:action/improve x:size/tiny x:type/content
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day