Skip to content

auth: verify MCP HTTP clients against the API key - #181

Merged
tjbck merged 1 commit into
open-webui:mainfrom
Classic298:fix/mcp-http-auth
Sep 23, 2026
Merged

tjbck merged 1 commit into
open-webui:mainfrom
Classic298:fix/mcp-http-auth

Conversation

@Classic298

Copy link
Copy Markdown
Member

The MCP server now gates its HTTP transports with a token verifier that requires the connecting client to present the API key, compared with hmac.compare_digest to match the FastAPI layer. The stdio transport is local and does not pass through the HTTP auth layer, so it keeps working unchanged.

Raises the mcp extra's fastmcp floor to >=4.0.0, where the auth= verifier API used here is available (2.x exposed a different auth surface).

Verified against fastmcp 4.0.5 on the streamable-http transport: a client with no token and a client with a wrong token are both rejected, a client presenting the API key gets the full tool set, and stdio continues to list tools with no client token.

The MCP server now gates its HTTP transports with a token verifier that
requires the connecting client to present the API key, compared with
hmac.compare_digest to match the FastAPI layer. The stdio transport is
local and does not pass through the HTTP auth layer, so it keeps working
unchanged. Raises the fastmcp floor to >=4.0.0, where the auth API used
here is available.
@tjbck
tjbck merged commit 83bafdd into open-webui:main Sep 23, 2026
7 checks passed
@Classic298
Classic298 deleted the fix/mcp-http-auth branch September 23, 2026 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants