yera.tools.mcp.oauth_profiles

Predefined OAuth client behavior for MCP providers.

Symbols

def get_mcp_oauth_client_profile — Return a predefined MCP OAuth client profile.
class MCPOAuthClientProfile — Describe how Yera authenticates with one MCP provider.
def resolve_mcp_oauth_client_profile — Resolve the predefined profile referenced by OAuth configuration.
def yera_oauth_client_metadata_document — Return Yera's canonical public OAuth client metadata document.

get_mcp_oauth_client_profile

get_mcp_oauth_client_profile(
    name: str,
) → MCPOAuthClientProfile | None

Return a predefined MCP OAuth client profile.

Parameters

name
type: str

Stable profile name from MCP server configuration.

Returns

type: MCPOAuthClientProfile | None

The matching client profile, or None when it is unknown.

MCPOAuthClientProfile

Inherits: BaseModel

Describe how Yera authenticates with one MCP provider.

Attributes

name
type: str

Stable name persisted in MCP server configuration.

client_kind
type: Literal['public', 'confidential']

Whether the OAuth client can protect a client secret.

grant_type
type: Literal['authorization_code', 'device_code']

OAuth grant used to authorize the user.

registration_method
type: Literal['cimd', 'dcr', 'pre_registered']

How the provider recognizes Yera as a client.

callback_strategy
type: Literal['none', 'ephemeral_loopback', 'fixed_loopback', 'hosted']

How authorization results return to Yera.

availability
type: Literal['open', 'vendor_approval', 'internal_only']

Whether users may connect without provider approval.

supports_static_token
type: bool

Whether users may supply a token instead.

client_id
type: str | None

Optional public identifier assigned to Yera by the provider.

client_metadata_url
type: str | None

Optional HTTPS Client ID Metadata Document URL.

device_authorization_endpoint
type: str | None

Optional endpoint issuing device codes.

token_endpoint
type: str | None

Optional endpoint issuing OAuth tokens.

default_scopes
type: tuple[str, ...]

Provider-specific scopes requested by default.

Methods

require_client_id — Return the profile's deployed OAuth client identifier.

MCPOAuthClientProfile.require_client_id

require_client_id() → str

Return the profile's deployed OAuth client identifier.

Returns

type: str

Public OAuth client identifier configured for this Yera build.

Raises

MCPAuthenticationError

If the client has not been registered.

resolve_mcp_oauth_client_profile

resolve_mcp_oauth_client_profile(
    auth: MCPOAuthAuth,
) → MCPOAuthClientProfile | None

Resolve the predefined profile referenced by OAuth configuration.

Parameters

auth
type: MCPOAuthAuth

Persisted OAuth authentication configuration.

Returns

type: MCPOAuthClientProfile | None

The selected predefined profile, or None for generic OAuth.

Raises

MCPAuthenticationError

If an explicitly selected profile is unknown.

yera_oauth_client_metadata_document

yera_oauth_client_metadata_document() → dict[str, object]

Return Yera's canonical public OAuth client metadata document.

Returns

type: dict[str, object]

JSON-compatible CIMD metadata to publish at Yera's client ID URL.