yera.tools.mcp.oauth_device
OAuth device-authorization support for MCP connections.
Symbols
authorize_mcp_device
authorize_mcp_device(
http_client: httpx2.AsyncClient,
server_name: str,
server_url: str,
authorization_server: str,
device_authorization_endpoint: str,
token_endpoint: str,
client_id: str,
scopes: tuple[str, ...],
interaction: OAuthDeviceInteraction,
sleep: Callable[[float], Awaitable[None]] = anyio.sleep,
clock: Callable[[], float] = monotonic,
) → OAuthTokenAuthorize an MCP connection using the OAuth device grant.
Parameters
Client used for OAuth endpoint requests.
Yera name of the MCP connection.
Streamable HTTP endpoint being authorized.
Issuer performing authorization.
Endpoint issuing the device code.
Endpoint polled for issued tokens.
Public identifier registered for Yera.
OAuth scopes requested for the MCP connection.
Presentation implementation showing verification details.
Awaitable delay implementation used between token requests.
Monotonic clock used to enforce local expiry.
Returns
Validated OAuth tokens issued after user approval.
authorize_mcp_device_profile
authorize_mcp_device_profile(
http_client: httpx2.AsyncClient,
profile: MCPOAuthClientProfile,
server_name: str,
server_url: str,
interaction: OAuthDeviceInteraction,
sleep: Callable[[float], Awaitable[None]] = anyio.sleep,
clock: Callable[[], float] = monotonic,
) → OAuthTokenAuthorize an MCP connection through a predefined device profile.
Parameters
Client used for OAuth endpoint requests.
Registered public device-authorization profile.
Yera name of the MCP connection.
Streamable HTTP endpoint being authorized.
Presentation implementation showing verification details.
Awaitable delay implementation used between token requests.
Monotonic clock used to enforce local expiry.
Returns
Validated OAuth tokens issued after user approval.
Raises
If the profile does not use device authorization.
If the profile has no deployed client ID.
OAuthDeviceAuthorizationResponse
BaseModelRepresent a validated OAuth device-authorization response.
Attributes
Secret polling credential issued to Yera.
Short code presented to the user.
Page at which the user enters the code.
Optional link containing the user code.
Lifetime of the device authorization in seconds.
Minimum polling interval in seconds.
poll_device_token
poll_device_token(
http_client: httpx2.AsyncClient,
endpoint: str,
client_id: str,
authorization: OAuthDeviceAuthorizationResponse,
sleep: Callable[[float], Awaitable[None]] = anyio.sleep,
clock: Callable[[], float] = monotonic,
) → OAuthTokenPoll an OAuth token endpoint for an approved device authorization.
Parameters
Client used to call the authorization server.
OAuth token endpoint.
Public identifier registered for Yera.
Device authorization containing the polling credential.
Awaitable delay implementation used between requests.
Monotonic clock used to enforce local expiry.
Returns
Validated OAuth tokens issued by the authorization server.
Raises
If the token endpoint rejects the request.
If the token response is invalid.
present_device_authorization
present_device_authorization(
interaction: OAuthDeviceInteraction,
server_name: str,
server_url: str,
authorization_server: str,
scopes: tuple[str, ...],
response: OAuthDeviceAuthorizationResponse,
) → NonePresent safe device-verification instructions to the user.
Parameters
Presentation implementation receiving the instructions.
Yera name of the MCP connection.
Streamable HTTP endpoint being authorized.
Issuer performing device authorization.
OAuth scopes requested for the MCP connection.
Validated device-authorization response.
request_device_authorization
request_device_authorization(
http_client: httpx2.AsyncClient,
endpoint: str,
client_id: str,
scopes: tuple[str, ...] = (),
) → OAuthDeviceAuthorizationResponseStart device authorization for a public OAuth client.
Parameters
Client used to call the authorization server.
Device-authorization endpoint.
Public identifier registered for Yera.
OAuth scopes requested for the MCP connection.
Returns
Validated device authorization and verification instructions.
Raises
If the authorization server rejects the request.
If the response does not follow RFC 8628.