yera.tools.mcp.auth

Authentication support for MCP HTTP connections.

Symbols

def build_mcp_oauth_auth — Build MCP SDK OAuth authentication from Yera configuration.
def mcp_connection_secrets — List the secrets an MCP connection owns in Yera's secret store.
def mcp_header_identity — Build the secret identity for one connection-owned MCP header.
def mcp_http_client — Provide an HTTP client configured for an MCP server.
class MCPAuthenticationProbe — Detect authentication challenges without performing authorization.
class MCPOAuthInteractionAdapter — Adapt Yera OAuth interaction to MCP SDK callback handlers.
def resolve_mcp_headers — Resolve configured MCP HTTP headers.

build_mcp_oauth_auth

build_mcp_oauth_auth(
    server_name: str,
    server: MCPServerConfig,
    store: SecretStore,
    client_metadata: OAuthClientMetadata,
    interaction: OAuthInteraction | None = None,
    client_metadata_url: str | None = None,
) → OAuthClientProvider

Build MCP SDK OAuth authentication from Yera configuration.

Parameters

server_name
type: str

Yera name of the MCP server connection.

server
type: MCPServerConfig

OAuth-authenticated MCP server configuration.

store
type: SecretStore

Secret store containing OAuth protocol state.

client_metadata
type: OAuthClientMetadata

OAuth client metadata used by the MCP SDK.

interaction
type: OAuthInteraction | None = None

Optional presentation and callback implementation.

client_metadata_url
type: str | None = None

Optional HTTPS CIMD identity for the OAuth client.

Returns

type: OAuthClientProvider

HTTP authentication backed by persisted OAuth state.

Raises

TypeError

If the server does not use OAuth authentication.

mcp_connection_secrets

mcp_connection_secrets(
    server: MCPServerConfig,
) → tuple[SecretIdentity, ...]

List the secrets an MCP connection owns in Yera's secret store.

Static headers own none, because their values belong to the user's credential group rather than the connection.

Parameters

server
type: MCPServerConfig

MCP server connection configuration.

Returns

type: tuple[SecretIdentity, ...]

Identities of the connection's header values or OAuth state.

mcp_header_identity

mcp_header_identity(
    secret_id: str,
    header: str,
) → SecretIdentity

Build the secret identity for one connection-owned MCP header.

Parameters

secret_id
type: str

Owner of the connection's header values.

header
type: str

HTTP header name.

Returns

type: SecretIdentity

Secret-store identity holding the header's value.

mcp_http_client

mcp_http_client(
    server: MCPServerConfig,
    http_client: httpx2.AsyncClient | None = None,
    server_name: str | None = None,
    secret_store: SecretStore | None = None,
    oauth_client_metadata: OAuthClientMetadata | None = None,
    oauth_interaction: OAuthInteraction | None = None,
    probe_authentication: bool = False,
    oauth_client_metadata_url: str | None = None,
) → AsyncIterator[httpx2.AsyncClient]

Provide an HTTP client configured for an MCP server.

Parameters

server
type: MCPServerConfig

MCP server connection configuration.

http_client
type: httpx2.AsyncClient | None = None

Optional caller-owned client used without closing it.

server_name
type: str | None = None

Optional configured connection name used in OAuth UX.

secret_store
type: SecretStore | None = None

Optional OAuth secret-store override.

oauth_client_metadata
type: OAuthClientMetadata | None = None

OAuth client metadata used by the MCP SDK.

oauth_interaction
type: OAuthInteraction | None = None

Optional interactive authorization implementation.

probe_authentication
type: bool = False

Whether HTTP 401 responses should be surfaced as MCP authentication challenges during explicit setup.

oauth_client_metadata_url
type: str | None = None

Optional HTTPS CIMD identity passed to the OAuth provider.

MCPAuthenticationProbe

Inherits: httpx2.Auth

Detect authentication challenges without performing authorization.

Methods

async_auth_flow — Send one request and report an authentication challenge.

MCPAuthenticationProbe.async_auth_flow

async_auth_flow(
    request: httpx2.Request,
) → AsyncGenerator[httpx2.Request, httpx2.Response]

Send one request and report an authentication challenge.

Parameters

request
type: httpx2.Request

Outbound MCP request.

Raises

MCPAuthenticationRequiredError

If the resource returns HTTP 401.

MCPOAuthInteractionAdapter

Adapt Yera OAuth interaction to MCP SDK callback handlers.

Methods

present_authorization — Present an SDK authorization redirect through Yera.
await_callback — Return Yera's captured callback in the MCP SDK representation.

MCPOAuthInteractionAdapter.present_authorization

present_authorization(
    authorization_url: str,
) → None

Present an SDK authorization redirect through Yera.

Parameters

authorization_url
type: str

Complete transient URL prepared by the SDK.

MCPOAuthInteractionAdapter.await_callback

await_callback() → AuthorizationCodeResult

Return Yera's captured callback in the MCP SDK representation.

Returns

type: AuthorizationCodeResult

Authorization callback values expected by the MCP SDK.

resolve_mcp_headers

resolve_mcp_headers(
    server: MCPServerConfig,
    secret_store: SecretStore | None = None,
) → dict[str, str]

Resolve configured MCP HTTP headers.

Connection-owned headers are read from the secret store. Static headers are read from the active credential group.

Parameters

server
type: MCPServerConfig

MCP server connection configuration.

secret_store
type: SecretStore | None = None

Optional secret-store override for connection-owned headers.

Returns

type: dict[str, str]

HTTP headers containing resolved values, or an empty mapping when the server does not authenticate with headers.