yera.tools.mcp.oauth_storage

Persistent secret storage for MCP OAuth protocol state.

Symbols

def decode_oauth_client_info — Decode OAuth client registration from an opaque secret.
def decode_oauth_tokens — Decode an OAuth token bundle from an opaque secret.
def encode_oauth_client_info — Encode OAuth client registration as an opaque secret.
def encode_oauth_tokens — Encode a complete OAuth token bundle as an opaque secret.
def oauth_client_info_identity — Build the secret identity for OAuth client registration.
def oauth_token_identity — Build the secret identity for one OAuth token bundle.
class SecretStoreOAuthStorage — Adapt Yera secret storage to the MCP SDK OAuth storage contract.

decode_oauth_client_info

decode_oauth_client_info(
    value: SecretValue,
) → OAuthClientInformationFull

Decode OAuth client registration from an opaque secret.

Parameters

value
type: SecretValue

Versioned opaque value read from the Yera secret store.

Returns

type: OAuthClientInformationFull

The validated OAuth client registration.

decode_oauth_tokens

decode_oauth_tokens(
    value: SecretValue,
) → OAuthToken

Decode an OAuth token bundle from an opaque secret.

Parameters

value
type: SecretValue

Versioned opaque value read from the Yera secret store.

Returns

type: OAuthToken

The validated OAuth token bundle.

encode_oauth_client_info

encode_oauth_client_info(
    client_info: OAuthClientInformationFull,
) → SecretValue

Encode OAuth client registration as an opaque secret.

Parameters

client_info
type: OAuthClientInformationFull

Registration returned by the authorization server.

Returns

type: SecretValue

A versioned opaque value suitable for the Yera secret store.

encode_oauth_tokens

encode_oauth_tokens(
    tokens: OAuthToken,
) → SecretValue

Encode a complete OAuth token bundle as an opaque secret.

Parameters

tokens
type: OAuthToken

Tokens returned by the OAuth authorization server.

Returns

type: SecretValue

A versioned opaque value suitable for the Yera secret store.

oauth_client_info_identity

oauth_client_info_identity(
    authorization_id: str,
) → SecretIdentity

Build the secret identity for OAuth client registration.

Parameters

authorization_id
type: str

Stable identity of the OAuth authorization.

Returns

type: SecretIdentity

Secret-store identity for registered client information.

oauth_token_identity

oauth_token_identity(
    authorization_id: str,
) → SecretIdentity

Build the secret identity for one OAuth token bundle.

Parameters

authorization_id
type: str

Stable identity of the OAuth authorization.

Returns

type: SecretIdentity

Secret-store identity for the authorization's tokens.

SecretStoreOAuthStorage

Adapt Yera secret storage to the MCP SDK OAuth storage contract.

Methods

get_tokens — Return stored OAuth tokens when present.
get_client_info — Return stored OAuth client registration when present.
set_tokens — Create or replace the stored OAuth token bundle.
set_client_info — Create or replace stored OAuth client registration.

SecretStoreOAuthStorage.get_tokens

get_tokens() → OAuthToken | None

Return stored OAuth tokens when present.

Returns

type: OAuthToken | None

The stored token bundle, or None before authorization.

SecretStoreOAuthStorage.get_client_info

get_client_info() → OAuthClientInformationFull | None

Return stored OAuth client registration when present.

Returns

type: OAuthClientInformationFull | None

Registered client information, or None when unavailable.

SecretStoreOAuthStorage.set_tokens

set_tokens(
    tokens: OAuthToken,
) → None

Create or replace the stored OAuth token bundle.

Parameters

tokens
type: OAuthToken

Complete token response supplied by the MCP SDK.

SecretStoreOAuthStorage.set_client_info

set_client_info(
    client_info: OAuthClientInformationFull,
) → None

Create or replace stored OAuth client registration.

Parameters

client_info
type: OAuthClientInformationFull

Registration supplied by the MCP SDK.