yera.tools.mcp.oauth_interaction

Presentation-neutral interaction contracts for MCP OAuth.

Symbols

class OAuthAuthorizationRequest — Describe an OAuth authorization redirect for presentation.
class OAuthAuthorizationResult — Carry transient values captured from an OAuth callback.
class OAuthDeviceAuthorizationRequest — Describe a device-authorization verification step for presentation.
class OAuthDeviceInteraction — Present a device-authorization verification step to the user.
class OAuthInteraction — Present OAuth authorization and capture its callback result.

OAuthAuthorizationRequest

Describe an OAuth authorization redirect for presentation.

The authorization URL is transient protocol state and must not be persisted or written to logs.

Attributes

server_name
type: str

Yera name of the MCP connection.

server_url
type: str

Streamable HTTP endpoint being authorized.

authorization_server
type: str

Discovered authorization-server issuer.

resource
type: str

Protected OAuth resource requested by the MCP server.

scopes
type: tuple[str, ...]

OAuth scopes requested from the user.

authorization_url
type: str

Complete transient browser authorization URL.

OAuthAuthorizationResult

Carry transient values captured from an OAuth callback.

These values must remain in memory and must not be persisted or logged.

Attributes

code
type: str

Short-lived authorization code returned by the server.

state
type: str

State value returned for request-correlation validation.

issuer
type: str | None

Optional authorization-response issuer supplied under RFC 9207.

OAuthDeviceAuthorizationRequest

Describe a device-authorization verification step for presentation.

The device code is secret protocol state and is intentionally excluded.

Attributes

server_name
type: str

Yera name of the MCP connection.

server_url
type: str

Streamable HTTP endpoint being authorized.

authorization_server
type: str

Discovered authorization-server issuer.

scopes
type: tuple[str, ...]

OAuth scopes requested from the user.

verification_uri
type: str

Page at which the user enters the displayed code.

verification_uri_complete
type: str | None

Optional link containing the user code.

user_code
type: str

Short code displayed for user verification.

expires_in_seconds
type: int

Lifetime of the verification request.

OAuthDeviceInteraction

Inherits: Protocol

Present a device-authorization verification step to the user.

Methods

present_device_authorization — Present device verification instructions.

OAuthDeviceInteraction.present_device_authorization

present_device_authorization(
    request: OAuthDeviceAuthorizationRequest,
) → None

Present device verification instructions.

Parameters

request
type: OAuthDeviceAuthorizationRequest

Non-secret verification context to present.

OAuthInteraction

Inherits: Protocol

Present OAuth authorization and capture its callback result.

Methods

present_authorization — Present an authorization request to the user.
await_callback — Wait for the authorization server callback.

OAuthInteraction.present_authorization

present_authorization(
    request: OAuthAuthorizationRequest,
) → None

Present an authorization request to the user.

Parameters

request
type: OAuthAuthorizationRequest

Transient authorization context to present.

OAuthInteraction.await_callback

await_callback() → OAuthAuthorizationResult

Wait for the authorization server callback.

Returns

type: OAuthAuthorizationResult

The captured authorization code and state.