yera.setup.mcp
Presentation-independent setup operations for MCP servers.
Symbols
add_device_authorized_mcp_server
add_device_authorized_mcp_server(
server_name: str,
config: MCPServerConfig,
profile: Profile,
authorization_id: str,
client_profile: MCPOAuthClientProfile,
secret_store: SecretStore,
interaction: OAuthDeviceInteraction,
oauth_http_client: httpx2.AsyncClient,
mcp_http_client: httpx2.AsyncClient | None = None,
catalogue: SQLiteMCPCatalogue | None = None,
sleep: Callable[[float], Awaitable[None]] = anyio.sleep,
) → NoneAuthorize, import, and persist one device-authorized MCP server.
Parameters
Name used to expose and configure the server.
Validated Streamable HTTP server configuration.
Profile in which the server will be enabled.
Stable identity used for stored OAuth state.
Registered public device-authorization profile.
Protected store receiving issued OAuth tokens.
Presentation implementation showing verification details.
Client used for OAuth endpoint requests.
Optional caller-owned MCP transport client.
Optional caller-owned MCP catalogue.
Awaitable delay implementation used between token requests.
add_header_authorized_mcp_server
add_header_authorized_mcp_server(
server_name: str,
config: MCPServerConfig,
profile: Profile,
headers: Mapping[str, str],
secret_store: SecretStore,
catalogue: SQLiteMCPCatalogue | None = None,
) → NoneStore header secrets, then import, persist, and enable one MCP server.
The header values are owned by the connection rather than a credential group, so the server works in every project. Each attempt stores its values under a fresh owner, so a server being replaced keeps its own values until the new configuration is written; they are then deleted as stale. If anything fails, the new values are deleted and the previous connection is left untouched.
Parameters
Name used to expose and configure the server.
Validated Streamable HTTP server configuration.
Profile in which the server will be enabled.
Header values keyed by header name.
Protected store receiving the header values.
Optional caller-owned MCP catalogue.
add_mcp_server
add_mcp_server(
server_name: str,
config: MCPServerConfig,
profile: Profile,
catalogue: SQLiteMCPCatalogue | None = None,
http_client: httpx2.AsyncClient | None = None,
oauth_setup: MCPOAuthSetup | None = None,
secret_store: SecretStore | None = None,
) → NoneImport, persist, and enable one MCP server for a profile.
The live server is imported before configuration is changed, ensuring an unreachable server or unsupported schema cannot leave a new connection in the user's configuration.
Parameters
Name used to expose and configure the server.
Validated Streamable HTTP server configuration.
Profile in which the server will be enabled.
Optional caller-owned MCP catalogue.
Optional caller-owned HTTP client.
Optional dependencies for completing OAuth authorization.
Optional protected OAuth storage override.
authorize_mcp_device_setup
authorize_mcp_device_setup(
server_name: str,
server_url: str,
authorization_id: str,
client_profile: MCPOAuthClientProfile,
secret_store: SecretStore,
interaction: OAuthDeviceInteraction,
http_client: httpx2.AsyncClient,
sleep: Callable[[float], Awaitable[None]] = anyio.sleep,
) → MCPOAuthAuthAuthorize and persist an MCP OAuth device grant.
Parameters
Yera name of the MCP connection.
Streamable HTTP endpoint being authorized.
Stable identity used for stored OAuth state.
Registered public device-authorization profile.
Protected store receiving issued OAuth tokens.
Presentation implementation showing verification details.
Client used for OAuth endpoint requests.
Awaitable delay implementation used between token requests.
Returns
Persistable OAuth authentication configuration.
build_mcp_oauth_setup
build_mcp_oauth_setup(
authorization_id: str,
secret_store: SecretStore,
callback_session: OAuthCallbackSession,
browser_opener: Callable[[str], bool] = webbrowser.open,
fallback_handler: Callable[[OAuthAuthorizationRequest], Awaitable[None]] | None = None,
client_profile: str | None = 'yera',
) → MCPOAuthSetupCompose browser OAuth around an active callback session.
Parameters
Stable identity used for stored OAuth state.
Protected store receiving OAuth protocol secrets.
Active local or hosted callback session.
Function opening the transient authorization URL.
Optional presenter used when browser opening fails.
Optional predefined OAuth client profile name.
Returns
OAuth setup ready for MCP connection authorization.
delete_mcp_server
delete_mcp_server(
server_name: str,
secret_store: SecretStore,
catalogue: SQLiteMCPCatalogue | None = None,
) → boolRemove one MCP server from Yera, with its tools and stored secrets.
The server leaves global configuration and every profile first, then the tool catalogue, and its secrets are deleted last. A failure part-way can leave an unused secret, but never a configured server without its credentials. Credential-group values used by static headers are left alone, because they belong to the user's group.
Parameters
Name of the configured server to remove.
Protected store holding the connection's secrets.
Optional caller-owned MCP catalogue.
Returns
Whether a configured server with that name was removed.
Raises
If the global MCP configuration is invalid.
loopback_mcp_oauth_setup
loopback_mcp_oauth_setup(
authorization_id: str,
secret_store: SecretStore,
browser_opener: Callable[[str], bool] = webbrowser.open,
fallback_handler: Callable[[OAuthAuthorizationRequest], Awaitable[None]] | None = None,
timeout_seconds: float = 300,
client_profile: str | None = 'yera',
callback_host: str = '127.0.0.1',
callback_port: int = 0,
) → AsyncIterator[MCPOAuthSetup]Open the dependencies for one browser-based MCP OAuth attempt.
Parameters
Stable identity used for stored OAuth state.
Protected store receiving OAuth protocol secrets.
Function opening the transient authorization URL.
Optional presenter used when browser opening fails.
Maximum time to wait for the OAuth callback.
Predefined OAuth client profile, defaulting to Yera's
canonical public identity. Pass None to use DCR without CIMD.
Loopback interface receiving the OAuth redirect.
Fixed callback port, or 0 for an ephemeral port.
MCPOAuthSetup
Dependencies required to authorize one MCP connection.
Attributes
Stable identity used for stored OAuth state.
OAuth client declaration supplied to the MCP SDK.
Protected store receiving OAuth protocol secrets.
Optional user-facing authorization interaction.
Optional predefined OAuth client profile name.
popular_mcp_servers
popular_mcp_servers() → tuple[DiscoveredMCPServer, ...]Return Yera's curated remote MCP server suggestions.
Returns
Stable built-in choices in their intended presentation order.