Repository navigation
auth specification in ClientSessionGroup #1723
Description
Activity
- addedenhancementRequest for a new feature that's not currently supportedRequest for a new feature that's not currently supportedauthIssues and PRs related to Authentication / OAuthIssues and PRs related to Authentication / OAuthneeds confirmationNeeds confirmation that the PR is actually required or needed.Needs confirmation that the PR is actually required or needed.
on Dec 9, 2025 - addedready for workEnough information for someone to start working onEnough information for someone to start working onP2Moderate issues affecting some users, edge cases, potentially valuable featureModerate issues affecting some users, edge cases, potentially valuable featurehelp wantedContributions especially welcomeContributions especially welcomeand removedneeds confirmationNeeds confirmation that the PR is actually required or needed.Needs confirmation that the PR is actually required or needed.
on Dec 10, 2025 @maxisbey Let me know if anyone is working on this. Otherwise, I will take this.
Hi @maxisbey !!
I've implemented this by adding an auth: httpx.Auth | None field to both SseServerParameters & StreamableHttpParameters,which gets passed through to the underlying sse_client() and create_mcp_http_client() calls. Will open a PR shortly.- addedneeds decisionIssue is actionable, needs maintainer decision on whether to implementIssue is actionable, needs maintainer decision on whether to implementand removedready for workEnough information for someone to start working onEnough information for someone to start working on
on Apr 17, 2026 Hi! I’m interested in implementing this. I traced the
ClientSessionGroupconnection path and propose adding optionalhttpx2.Authsupport directly onSseServerParametersandStreamableHttpParameters, propagating it intosse_clientandcreate_mcp_http_client. Existing header behavior remains 100% backward compatible, and authentication applies cleanly only to the relevant HTTP transports.I have implemented this with 100% test coverage, serialization safety (
ConfigDict(arbitrary_types_allowed=True, exclude=True)), per-server auth isolation, and updated documentation insession-groups.md.Would you like me to open the PR for review?
I'd like to take this.
The transports already accept an
httpx.Auth(sse_clienthasauth=, and the streamable-HTTP path goes throughcreate_mcp_http_client, which also hasauth=) — the missing piece is thatSseServerParameters/StreamableHttpParameterscan't carry one.My proposed approach is to add an optional
authfield to both parameter models and thread it through_establish_session. This should allowClientSessionGroupto use the same authentication flow already supported by the underlying transports.Does that approach look right?
Disclosure: I used AI assistance to investigate and draft this proposal; I've reviewed it and understand the proposed changes.
Description
It would be nice for the
ClientSessionGroupto be OAuth compatible by allowing us to specify the OAuthhttpx.Authprovider when passing in theServerParametersrather than passing the bearer tokens manually via theheadersfield. This will allow us to do the OAuth token exchange flow straight from theClientSessionGroup.References
Here is the singleton
ClientSessionexample of an OAuth flow: https://github.com/modelcontextprotocol/python-sdk/blob/main/examples/clients/simple-auth-client/mcp_simple_auth_client/main.pyIt would be nice to have an example of a
ClientSessionGroupusing that same flow.