Skip to content

auth specification in ClientSessionGroup #1723

Description

@erwang01

Description

It would be nice for the ClientSessionGroup to be OAuth compatible by allowing us to specify the OAuth httpx.Auth provider when passing in the ServerParameters rather than passing the bearer tokens manually via the headers field. This will allow us to do the OAuth token exchange flow straight from the ClientSessionGroup.

References

Here is the singleton ClientSession example of an OAuth flow: https://github.com/modelcontextprotocol/python-sdk/blob/main/examples/clients/simple-auth-client/mcp_simple_auth_client/main.py

It would be nice to have an example of a ClientSessionGroup using that same flow.

Activity

  1. added
    enhancementRequest for a new feature that's not currently supported
    authIssues and PRs related to Authentication / OAuth
    needs confirmationNeeds confirmation that the PR is actually required or needed.
    on Dec 9, 2025
  2. added
    ready for workEnough information for someone to start working on
    P2Moderate issues affecting some users, edge cases, potentially valuable feature
    help wantedContributions especially welcome
    and removed
    needs confirmationNeeds confirmation that the PR is actually required or needed.
    on Dec 10, 2025
  3. the-ayyi commented on Dec 19, 2025

    @the-ayyi

    @maxisbey Let me know if anyone is working on this. Otherwise, I will take this.

  4. IT-HONGREAT commented on Feb 14, 2026

    @IT-HONGREAT

    Hi @maxisbey !!
    I've implemented this by adding an auth: httpx.Auth | None field to both SseServerParameters & StreamableHttpParameters,which gets passed through to the underlying sse_client() and create_mcp_http_client() calls. Will open a PR shortly.

  5. added
    needs decisionIssue is actionable, needs maintainer decision on whether to implement
    and removed
    ready for workEnough information for someone to start working on
    on Apr 17, 2026
  6. musi22 commented on Sep 17, 2026

    @musi22

    Hi! I’m interested in implementing this. I traced the ClientSessionGroup connection path and propose adding optional httpx2.Auth support directly on SseServerParameters and StreamableHttpParameters, propagating it into sse_client and create_mcp_http_client. Existing header behavior remains 100% backward compatible, and authentication applies cleanly only to the relevant HTTP transports.

    I have implemented this with 100% test coverage, serialization safety (ConfigDict(arbitrary_types_allowed=True, exclude=True)), per-server auth isolation, and updated documentation in session-groups.md.

    Would you like me to open the PR for review?

  7. Mohammedib24 commented on Sep 19, 2026

    @Mohammedib24

    I'd like to take this.

    The transports already accept an httpx.Auth (sse_client has auth=, and the streamable-HTTP path goes through create_mcp_http_client, which also has auth=) — the missing piece is that SseServerParameters / StreamableHttpParameters can't carry one.

    My proposed approach is to add an optional auth field to both parameter models and thread it through _establish_session. This should allow ClientSessionGroup to use the same authentication flow already supported by the underlying transports.

    Does that approach look right?

    Disclosure: I used AI assistance to investigate and draft this proposal; I've reviewed it and understand the proposed changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Moderate issues affecting some users, edge cases, potentially valuable featureauthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedhelp wantedContributions especially welcomeneeds decisionIssue is actionable, needs maintainer decision on whether to implement

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions