Skip to content

Releases: mcp-runtime/mcp-auth

MCP Auth v0.4.4

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 06 Oct 13:45
6402142

What's Changed

Full Changelog: v0.4.3...v0.4.4

MCP Auth v0.4.3

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 06 Oct 13:41
ead0599

What's Changed

  • Fix multi-resource token exchange and remove legacy resource config by @Agent-Hellboy in #20

Full Changelog: v0.4.2...v0.4.3

mcp-auth v0.4.2

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 06 Oct 13:18
182dc67

What's Changed

Full Changelog: v0.4.1...v0.4.2

mcp-auth v0.4.1

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 28 Sep 14:57

Docker Hub now displays the authorization flow as a rendered Mermaid PNG, with documentation links pinned to the published commit. README updates sync automatically from GitHub.

Release downloads include authorization server binaries for Linux, macOS, and Windows (amd64 and arm64), the Python SDK wheel and source distribution, the TypeScript SDK package, and SHA256SUMS. SDK packages retain version 0.3.0.

Container images are published for linux/amd64 and linux/arm64:

docker pull princekrroshan01/mcp-auth-server:0.4.1

The image is also tagged v0.4.1 and latest.

Validation: full CI and CodeQL passed; release packages built locally and all checksums verified; the diagram was verified in the live Docker Hub overview.

Full changelog

mcp-auth v0.4.0

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 23 Sep 16:52
d1aa775

What's Changed

Full Changelog: v0.3.1...v0.4.0

mcp-auth v0.3.1

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 22 Sep 16:17
5de56b8

Patch release for the validated Cursor + Databricks MCP OAuth flow.

  • Fix consent-page CSP blocking the redirect to the upstream identity provider.
  • Add an explicit per-connector id_token_nonce_policy: "disabled" compatibility setting for providers whose ID tokens do not carry a nonce claim; nonce verification remains required by default.
  • Document the compatibility setting and preserve one-time state plus S256 PKCE binding.

mcp-auth v0.3.0

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 18 Sep 15:09

Highlights

  • Ships the official TypeScript SDK alongside the existing Python and Go SDKs.
  • Adds runnable Python, Go, and TypeScript MCP resource-server examples.
  • Expands end-to-end authorization coverage across all three SDKs, including OAuth discovery, dynamic client registration, PKCE, token validation, insufficient-scope rejection, and authenticated MCP requests.
  • Fixes required-scope enforcement in the Python FastMCP integration and updates compatibility to FastMCP 4.
  • Adds CodeQL analysis, a security policy, dependency audits, image scanning, and expanded project/security/official-SDK badges.

Verification

The release commit passed the complete GitHub Actions suite, including the multi-SDK E2E matrix, production-mode Compose OAuth flow, Python/Go/TypeScript tests, dependency audits, Go vulnerability scans, Docker image scan, and CodeQL.

v0.2.0

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 18 Sep 07:52
8f6e880

Provider-neutral OAuth for MCP resource servers: authorization server plus Python and Go SDKs.

This release makes a real MCP client work end to end against a path-mounted issuer. Every fix below was found by a client failing where curl succeeded.

Breaking

MCP_AUTH_TRUST_PROXY_TLS defaults to false. X-Forwarded-Proto is set by the caller, so it was never evidence of TLS — anything able to reach the process satisfied MCP_AUTH_REQUIRE_HTTPS by sending one header. Verified against a live cluster, where an unrelated pod reached the authorization server and got 200.

A deployment behind a TLS-terminating proxy must now set MCP_AUTH_TRUST_PROXY_TLS=true, or every request is refused with https_required. The rejection names the setting. Treat it as a claim about your topology and enforce it with a NetworkPolicy or equivalent, so the proxy really is the only route in.

Authorization server

  • Serve RFC 8414 metadata at the path-insertion location for a path-mounted issuer. Clients request /.well-known/oauth-authorization-server/<path>, not <issuer>/.well-known/..., so discovery previously 404'd.
  • Post the consent form to the issuer-mounted path. A root-relative action 404'd before the upstream identity provider was ever reached.
  • /register echoes client_id_issued_at, grant_types, response_types, and scope (RFC 7591). Clients that cannot read back what they registered re-register on every attempt.
  • Advertise subject_types_supported and id_token_signing_alg_values_supported. Clients validating against the OpenID Connect Discovery schema rejected the whole document without them.
  • Protected resource metadata is served per resource. It previously answered the bare well-known path with resources[0] plus a non-standard resources member, handing multi-resource deployments an audience the client never asked for.

SDKs

  • ProtectedResourceMetadataHandler (Go) and protected_resource_metadata (Python) derive scopes_supported from the verifier's required scopes, so the advertised set cannot drift from the enforced one. A server that omits it leaves the client nothing to request; the token carries no scope and every call fails 403 with nothing explaining why.
  • unauthorized_headers_for_error (Python), matching Go's existing helper, so a Python resource server can emit insufficient_scope and let a client retry.
  • unauthorized_headers (Python) now comma-separates auth-params per RFC 9110 section 11.6.1. Lenient parsers accepted the old form; strict ones did not.
  • Discovery in both clients tries the RFC 8414 forms before the OIDC suffix forms.

Docs

New security model page. The README is now an index; its duplicated setup, commands and release sections were already in docs/development.md. The deliberate RFC 8252 private-use-scheme deviation from the spec's localhost-or-HTTPS rule is documented, since desktop MCP clients cannot work without it.

Verified

Full flow against a live deployment for both a Go and a Python resource server: discovery, DCR, PKCE S256, Keycloak login, token with bound audience, initialize, tools/list, tools/call. Cross-audience tokens rejected 401 both ways. Confirmed from Cursor as a real client.

Modules

  • github.com/Agent-Hellboy/mcp-auth/auth-server at auth-server/v0.2.0
  • github.com/Agent-Hellboy/mcp-auth/auth-client/go at auth-client/go/v0.2.0
  • Python mcp-auth-client 0.2.0

🤖 Generated with Claude Code

mcp-auth v0.1.2

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 17 Sep 13:30

Full Changelog: v0.1.1...v0.1.2

mcp-auth v0.1.1

Choose a tag to compare

@Agent-Hellboy Agent-Hellboy released this 17 Sep 12:26

Full Changelog: v0.1.0...v0.1.1