yera.tools.mcp.auth
Authentication support for MCP HTTP connections.
Symbols
build_mcp_oauth_auth
build_mcp_oauth_auth(
server_name: str,
server: MCPServerConfig,
store: SecretStore,
client_metadata: OAuthClientMetadata,
interaction: OAuthInteraction | None = None,
client_metadata_url: str | None = None,
) → OAuthClientProviderBuild MCP SDK OAuth authentication from Yera configuration.
Parameters
Yera name of the MCP server connection.
OAuth-authenticated MCP server configuration.
Secret store containing OAuth protocol state.
OAuth client metadata used by the MCP SDK.
Optional presentation and callback implementation.
Optional HTTPS CIMD identity for the OAuth client.
Returns
HTTP authentication backed by persisted OAuth state.
Raises
If the server does not use OAuth authentication.
mcp_connection_secrets
mcp_connection_secrets(
server: MCPServerConfig,
) → tuple[SecretIdentity, ...]List the secrets an MCP connection owns in Yera's secret store.
Static headers own none, because their values belong to the user's credential group rather than the connection.
Parameters
MCP server connection configuration.
Returns
Identities of the connection's header values or OAuth state.
mcp_header_identity
mcp_header_identity(
secret_id: str,
header: str,
) → SecretIdentityBuild the secret identity for one connection-owned MCP header.
Parameters
Owner of the connection's header values.
HTTP header name.
Returns
Secret-store identity holding the header's value.
mcp_http_client
mcp_http_client(
server: MCPServerConfig,
http_client: httpx2.AsyncClient | None = None,
server_name: str | None = None,
secret_store: SecretStore | None = None,
oauth_client_metadata: OAuthClientMetadata | None = None,
oauth_interaction: OAuthInteraction | None = None,
probe_authentication: bool = False,
oauth_client_metadata_url: str | None = None,
) → AsyncIterator[httpx2.AsyncClient]Provide an HTTP client configured for an MCP server.
Parameters
MCP server connection configuration.
Optional caller-owned client used without closing it.
Optional configured connection name used in OAuth UX.
Optional OAuth secret-store override.
OAuth client metadata used by the MCP SDK.
Optional interactive authorization implementation.
Whether HTTP 401 responses should be surfaced as MCP authentication challenges during explicit setup.
Optional HTTPS CIMD identity passed to the OAuth provider.
MCPAuthenticationProbe
httpx2.AuthDetect authentication challenges without performing authorization.
Methods
MCPAuthenticationProbe.async_auth_flow
async_auth_flow(
request: httpx2.Request,
) → AsyncGenerator[httpx2.Request, httpx2.Response]Send one request and report an authentication challenge.
Parameters
Outbound MCP request.
Raises
If the resource returns HTTP 401.
MCPOAuthInteractionAdapter
Adapt Yera OAuth interaction to MCP SDK callback handlers.
Methods
MCPOAuthInteractionAdapter.present_authorization
present_authorization(
authorization_url: str,
) → NonePresent an SDK authorization redirect through Yera.
Parameters
Complete transient URL prepared by the SDK.
MCPOAuthInteractionAdapter.await_callback
await_callback() → AuthorizationCodeResultReturn Yera's captured callback in the MCP SDK representation.
Returns
Authorization callback values expected by the MCP SDK.
resolve_mcp_headers
resolve_mcp_headers(
server: MCPServerConfig,
secret_store: SecretStore | None = None,
) → dict[str, str]Resolve configured MCP HTTP headers.
Connection-owned headers are read from the secret store. Static headers are read from the active credential group.
Parameters
MCP server connection configuration.
Optional secret-store override for connection-owned headers.
Returns
HTTP headers containing resolved values, or an empty mapping when the server does not authenticate with headers.