Commit graph

397 commits

Author SHA1 Message Date
Dale Seo
8700e5c920
chore: fix all clippy warnings across workspace (#746) 2026-03-11 14:12:00 -04:00
github-actions[bot]
3bd7522070
chore: release v1.2.0 (#736)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-11 10:28:11 -04:00
Dale Seo
27b00967f1
feat: transparent session re-init on HTTP 404 (#743) 2026-03-11 10:27:00 -04:00
Dale Seo
5322430772
fix: handle ping requests sent before initialize handshake (#745) 2026-03-11 10:09:10 -04:00
Dale Seo
3d2c951ca3
feat: add missing constructors for non-exhaustive model types (#739)
* feat: add constructors for Root and ListRootsResult

* feat: add constructors for UnsubscribeRequestParams and PromptReference
2026-03-10 13:13:53 -04:00
dependabot[bot]
9fbf91e021
chore(deps): update jsonwebtoken requirement from 9 to 10 (#737)
Updates the requirements on [jsonwebtoken](https://github.com/Keats/jsonwebtoken) to permit the latest version.
- [Changelog](https://github.com/Keats/jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](https://github.com/Keats/jsonwebtoken/compare/v9.0.0...v10.3.0)

---
updated-dependencies:
- dependency-name: jsonwebtoken
  dependency-version: 10.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-09 16:41:16 -04:00
Dale Seo
54bb522e7f
feat: include granted scopes in OAuth refresh token request (#731)
* fix: include granted scopes in OAuth refresh token request

* docs: document scope forwarding in token refresh flow
2026-03-09 16:30:19 -04:00
Axel
be248980f2
fix(rmcp-macros): use re-exported serde_json path in task_handler (#735)
* fix(rmcp-macros): use re-exported serde_json path in task_handler

Replace bare `::serde_json::` with `::rmcp::serde_json::` in
task_handler.rs to prevent compilation errors in crates that don't
directly depend on serde_json.

Fixes #487

* Update crates/rmcp-macros/src/task_handler.rs

---------

Co-authored-by: Dale Seo <5466341+DaleSeo@users.noreply.github.com>
2026-03-09 16:30:11 -04:00
Dale Seo
fc757d41ca
fix: allow deserializing notifications without params field (#729) 2026-03-09 15:56:27 -04:00
github-actions[bot]
1158cfe1b8
chore: release v1.1.1 (#732)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-09 11:15:31 -04:00
Dale Seo
8e5ebb4f5c
fix: accept logging/setLevel and ping before initialized notification (#730)
* fix: accept logging/setLevel and ping before initialized notification

* test: add server initialization tests for pre-init requests
2026-03-09 07:08:16 -04:00
nazq
9b507f5018
fix(rmcp-macros): replace deprecated *Param type aliases with *Params (#727)
The `#[task_handler]` macro generates code using deprecated type aliases
(`PaginatedRequestParam`, `CallToolRequestParam`, `GetTaskInfoParam`,
`GetTaskResultParam`, `CancelTaskParam`) that were renamed to `*Params`
in rmcp 0.13.0. This causes 5 deprecation warnings for every crate
using the macro.

Update all references to use the canonical `*Params` names:
- `PaginatedRequestParam` → `PaginatedRequestParams`
- `CallToolRequestParam` → `CallToolRequestParams`
- `GetTaskInfoParam` → `GetTaskInfoParams`
- `GetTaskResultParam` → `GetTaskResultParams`
- `CancelTaskParam` → `CancelTaskParams`

Also fix the corresponding doc examples in `lib.rs`.

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-07 15:13:54 -05:00
github-actions[bot]
53c86d5d9d
chore: release v1.0.1 (#722)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-03 20:57:31 -05:00
Dale Seo
bb6c8043bf
feat: implement OAuth 2.0 Client Credentials flow (#707)
* feat: implement OAuth 2.0 Client Credentials flow

* fix: address SEP-1046 review findings

* fix: validate HTTPS on JWT token endpoint
2026-03-03 20:53:51 -05:00
github-actions[bot]
e223b53812
chore: release v1.0.0 (#721)
* chore: release v1.0.0-alpha.1

* chore: version 1.0.0

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Alex Hancock <alexhancock@block.xyz>
2026-03-03 17:03:37 -05:00
Peter Siska
434ccb7812
fix(auth): pass WWW-Authenticate scopes to DCR registration request (#705)
* fix(auth): pass WWW-Authenticate scopes to DCR registration request

When an MCP server returns a 401 with `WWW-Authenticate: Bearer scope="..."`,
the scopes are parsed but never included in the Dynamic Client Registration
(DCR) request. Per RFC 7591, the DCR request should include a `scope` field
so the authorization server knows what scopes the client intends to use.
Servers that enforce scope-matching between registration and authorization
will reject the flow without this.

Changes:
- Add optional `scope` field to `ClientRegistrationRequest` with
  `skip_serializing_if` for backward compatibility
- Update `register_client()` to accept scopes parameter and include
  them in the DCR request body and returned `OAuthClientConfig`
- Thread scopes from `AuthorizationSession::new()` into both
  `register_client()` call sites
- Re-export `oauth2::TokenResponse` trait so consumers can extract
  scopes from token responses
- Add serialization tests for the new `scope` field

* refactor(auth): change register_client to accept &[&str] instead of &[String]

Avoids unnecessary Vec<String> allocation in callers that already have &[&str].

* fix(auth): make ClientRegistrationRequest crate-private

* refactor(auth): stop re-exporting oauth2 TokenResponse trait

* style(auth): merge TokenResponse into grouped oauth2 import

Fix nightly rustfmt check by consolidating the separate
`use oauth2::TokenResponse` into the existing `use oauth2::{...}` block.
2026-03-03 12:43:31 -05:00
Dale Seo
2d90b76501
fix: api ergonomics follow-up (#720)
* fix: builder with_* methods take T instead of Option<T>

* fix: emit conditional builder calls for optional fields in macros

* fix: convert with_task, with_stop_reason, with_logger, with_content to proper builders

* fix: update test callers for new builder signatures

* fix: simplify make_task helper and remove unused import

* fix: update sampling_stdio example for new with_stop_reason signature

* fix: make annotations and execution Option<Expr> consistent with other fields

* fix: remove unused none_expr import
2026-03-03 12:05:32 -05:00
Adam Kowalski
1fe5d1e1cd
fix(streamable-http): map stale session 401 to status-aware error (#709)
* fix(streamable-http): map stale session 401 to status-aware error

* test(streamable-http): expect 404 for stale session
2026-03-03 12:01:14 -05:00
github-actions[bot]
28beb9528b
chore: release v1.0.0-alpha (#719)
* chore: release v0.18.0

* chore: bump to 1.0.0-alpha

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jack Amadeo <jackamadeo@squareup.com>
2026-03-03 11:26:31 -05:00
Alex Hancock
6842f9cc3c
feat: docs update (#718) 2026-03-03 11:14:30 -05:00
Jack Amadeo
f63718d202
chore: add #[non_exhaustive] and mutation methods to improve compatibility (#715)
* chore: add #[non_exhaustive] to reduce backwards-incompatible changes going forward

* fix: remove ProtocolVersion import

* fix: add a few more with_ mutator methods

---------

Co-authored-by: Alex Hancock <alexhancock@block.xyz>
2026-03-03 10:38:01 -05:00
Guy Lichtman
78d959fcd4
feat(auth): support returning extra fields from token exchange (#700)
* feat(auth): support returning extra fields that may be returned from token generation

exchange_code_for_token and refresh_token now return a StandardTokenResponse which includes
any additionalfields which might have been sent by the vendor

BREAKING CHANGE: Return type of exchange_code_for_token and refresh_token has changed
and may require code changes.

* fix: doc links
2026-03-02 10:38:15 -05:00
Kristof Mattei
876da50271
fix: downgrade logging of message to TRACE to avoid spamming logs (#699) 2026-02-27 18:11:22 -05:00
github-actions[bot]
955186502d
chore: release (#697)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-02-27 15:32:46 -05:00
Dale Seo
e68b15e600
docs: add prose documentation for core features to meet conformance (#702)
* docs: add prose documentation for core features to meet conformance

* docs: remove static coverage badge and svg

* docs: rewrite Chinese README to match current English README
2026-02-27 13:33:53 -05:00
Thiago Mendes
d6703dad75
feat(streamable-http): add json_response option for stateless server mode (#683)
* feat(streamable-http): add json_response option for stateless server mode

Adds `json_response: bool` field to `StreamableHttpServerConfig`.
When true and `stateful_mode` is false, the server returns
`Content-Type: application/json` directly instead of `text/event-stream`,
eliminating SSE framing overhead for simple request-response patterns.

This completes server-side JSON response support (client-side was added
in #540) and contributes to the stateless server goals of SEP-1442 (#526).

Backwards-compatible: `json_response: false` (default) preserves all
existing SSE behaviour unchanged, and `stateful_mode: true` is unaffected.

Benchmark evidence (50 VUs, 5min, 2 CPUs):
- RPS: 770 → 1139 (+48%)
- get_user_cart latency: 41ms → 0.76ms (-98%)
- checkout latency: 41ms → 0.55ms (-99%)
- Zero regressions, zero errors

* fix(tower): add cancellation awareness and logging to JSON response path

* fix(test): add missing Default to StreamableHttpServerConfig in concurrent streams test

Made-with: Cursor
2026-02-26 22:23:05 -05:00
Alex Hancock
a7e4ae3203
feat: mcp sdk conformance (#687)
* adds conformance server and client
* adds results from initial run of https://github.com/modelcontextprotocol/conformance/tree/main/.claude/skills/mcp-sdk-tier-audit skill
* various small changes applied during the testing loop

Co-authored-by: Dale Seo <5466341+DaleSeo@users.noreply.github.com>
2026-02-26 13:33:18 -05:00
Dale Seo
b967c132ae
fix: improve error logging and remove token secret from logs (#685) 2026-02-26 10:05:43 -05:00
Dale Seo
93bfb4ac6b
feat: add default value support to string, number, and integer schemas (#686) 2026-02-26 10:02:11 -05:00
EvianZhang
6c336a90c1
feat: add trait-based tool declaration (#677)
* feat: add trait-based tool declaration

* fix: typo

* fix: add docs, make more idomatic patterns, allow for empty parameters and return types

* fix: format code

* fix: add default trait

* fix: docs typo
2026-02-25 12:23:37 -05:00
Alex Hancock
332fcbfb91
Fix/sse channel replacement conflict (#682)
* fix(streamable-http): return 409 Conflict when standalone SSE stream already active

LocalSessionWorker::resume() unconditionally replaced self.common.tx on
every GET request, orphaning the receiver the first SSE stream was
reading from. All subsequent server-to-client notifications were sent to
the new sender while the original client was still listening on the old,
now-dead receiver. notify_tool_list_changed().await returned Ok(())
silently.

This is triggered by VS Code's MCP extension which reconnects SSE every
~5 minutes with the same session ID.

Fix: Check tx.is_closed() before replacing the common channel sender.
If an active stream exists, return SessionError::Conflict which is
propagated as HTTP 409 Conflict. This matches the TypeScript SDK
behavior (streamableHttp.ts:423).

Signed-off-by: Mohammod Al Amin Ashik <maa.ashik00@gmail.com>

* fix(streamable-http): handle resume with completed request-wise channel

When a client sends GET with Last-Event-ID from a completed POST SSE
response, the request-wise channel no longer exists in tx_router.
Previously this returned ChannelClosed -> 500, causing clients like
Cursor to enter an infinite re-initialization loop.

Now falls back to the common channel when the request-wise channel is
completed, per MCP spec: "Resumption applies regardless of how the
original stream was initiated (POST or GET)."

* fix: allow SSE channel replacement instead of 409 Conflict

Per MCP spec §Streamable HTTP, "The client MAY remain connected to
multiple SSE streams simultaneously." Returning 409 Conflict when a
second GET arrives causes Cursor to enter an infinite re-initialization
loop (~3s cycle).

Instead of rejecting, replace the old common channel sender. Dropping
the old sender closes the old receiver, cleanly terminating the
previous SSE stream so the client can reconnect on the new stream.

This fixes both code paths:
- GET with Last-Event-ID from a completed POST SSE response
- GET without Last-Event-ID (standalone stream reconnection)

* fix: skip cache replay when replacing active SSE stream

When a client opens a new GET SSE stream while a previous one is
still active, the old sender is dropped (terminating the old stream)
and a new channel is created.  Previously, sync() replayed all cached
events to the new stream, but the client already received those events
on the old stream.  This caused an infinite notification loop:

1. Client receives notifications (e.g. ResourceListChanged)
2. Old SSE stream dies (sender replaced)
3. Client reconnects after sse_retry (3s)
4. sync() replays cached notifications the client already handled
5. Client processes them again → goto 2

Fix: check tx.is_closed() BEFORE replacing the sender.  If the old
stream was still alive, skip replay entirely — the client already has
those events.  Only replay when the old stream was genuinely dead
(network failure, timeout) so the client catches up on missed events.

* fix: use shadow channels to prevent SSE reconnect loops

When POST SSE responses include a `retry` field, the browser's
EventSource automatically reconnects via GET after the stream ends.
This creates multiple competing EventSource connections that each
replace the common channel sender, killing the other stream's receiver.
Both reconnect every sse_retry seconds, creating an infinite loop.

Instead of always replacing the common channel, check if the primary
is still active. If so, create a "shadow" stream — an idle SSE
connection kept alive by keep-alive pings that doesn't receive
notifications or interfere with the primary channel.

Also removes cache replay (sync) on common channel resume, as
replaying server-initiated list_changed notifications causes clients
to re-process old signals.

Signed-off-by: Myko Ash <myko@mcpmux.com>
Signed-off-by: Mohammod Al Amin Ashik <maa.ashik00@gmail.com>

* test: comprehensive shadow channel tests (15 cases)

Rewrite test suite for SSE channel replacement fix:
- Shadow creation: standalone GET returns 200, multiple GETs coexist
- Dead primary: replacement, notification delivery, repeated cycles
- Notification routing: primary receives, shadow does not
- Resume paths: completed request-wise, common alive/dead
- Real scenarios: Cursor leapfrog, VS Code reconnect
- Edge cases: invalid session, missing header, shadow cleanup

Fix Accept header bug (was missing text/event-stream for
notifications/initialized POST, causing 406 rejection).

* fix: use correct HTTP status codes for session errors per MCP spec

MCP spec (2025-11-25) section "Session Management" requires:
- Missing session ID header → 400 Bad Request (not 401)
- Unknown/terminated session → 404 Not Found (not 401)

Using 401 Unauthorized caused MCP clients (e.g. VS Code) to
trigger full OAuth re-authentication on server restart, instead
of simply re-initializing the session.

Signed-off-by: Mohammod Al Amin Ashik <maa.ashik00@gmail.com>

* fix: address review feedback — remove dead Conflict variant, restore sync on resume, rename test

- Remove unused SessionError::Conflict and dead string-matching in tower.rs
  (leftover from abandoned 409 approach)
- Restore sync() replay when replacing a dead primary common channel so
  server-initiated requests and cached notifications are not lost on reconnect
- Rename test from test_sse_channel_replacement_bug to test_sse_concurrent_streams
  per reviewer suggestion (describe what tests verify, not what triggered them)
- Add test for cache replay on dead primary replacement
- Use generic "MCP clients" in comments instead of specific client names

Signed-off-by: Mohammod Al Amin Ashik <maa.ashik00@gmail.com>

* fix: use minimal buffer for shadow streams and cap at 32

- Shadow streams only receive SSE keep-alive pings, so use capacity 1
  instead of full channel_capacity
- Cap shadow_txs at 32 to prevent unbounded growth from misbehaving
  clients, dropping the oldest shadow when the limit is reached
- Add test verifying primary works after exceeding shadow limit

Signed-off-by: Mohammod Al Amin Ashik <maa.ashik00@gmail.com>

* fix: remove redundant single-component `use reqwest` import

Fixes clippy::single_component_path_imports lint error in
test_sse_concurrent_streams.rs.

---------

Signed-off-by: Mohammod Al Amin Ashik <maa.ashik00@gmail.com>
Signed-off-by: Myko Ash <myko@mcpmux.com>
Co-authored-by: Mohammod Al Amin Ashik <maa.ashik00@gmail.com>
2026-02-24 17:16:42 -05:00
Wils Dawson
83808d3114
fix: refresh token expiry (#680) 2026-02-24 12:02:50 -05:00
Dale Seo
66c7000626
docs: document session management for streamable HTTP transport (#674) 2026-02-24 11:58:55 -05:00
Dale Seo
5fa012d163
feat: send and validate MCP-Protocol-Version header (#675) 2026-02-24 11:08:49 -05:00
Dale Seo
91e208efb7
fix: gate optional dependencies behind feature flags (#672) 2026-02-24 11:02:28 -05:00
Anish Athalye
98eef440c6
fix: allow empty content in CallToolResult (#681)
Per the MCP spec [1] and the TypeScript schema [2],
`CallToolResult.content` is typed as `ContentBlock[]`, so it is a
required array with no minimum length constraint.

MCP server libraries use such a representation in practice: for example,
FastMCP returns responses with no `structuredContent` and an empty
`content` array when tools return `None`.

[1]: https://modelcontextprotocol.io/specification/2025-11-25/server/tools
[2]: https://github.com/modelcontextprotocol/specification/blob/main/schema/2025-11-25/schema.ts
2026-02-24 11:09:57 +08:00
Mark Wotton
92b1459647
fix(schema): remove AddNullable from draft2020_12 settings (#664)
* fix(schema): remove AddNullable from draft2020_12 settings

The `nullable` keyword is an OpenAPI 3.0 extension, not part of
JSON Schema 2020-12. Using AddNullable with draft2020_12 settings
causes validation failures with strict JSON Schema validators.

JSON Schema 2020-12 represents nullable types using:
- {"type": ["string", "null"]} (type array with null)
- {"anyOf": [{"type": "string"}, {"type": "null"}]}

Fixes #663

* test(schema): update complex schema nullable expectation

* test(schema): align macro optional-field expectations with draft2020
2026-02-19 11:19:45 -05:00
github-actions[bot]
3df4c5bf5f
chore: release v0.16.0 (#652)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-02-17 13:51:44 -05:00
Dale Seo
021a431bef
chore: upgrade reqwest to 0.13.2 (#669) 2026-02-17 13:41:12 -05:00
EvianZhang
0b53bfd7b9
fix: remove unnecessary doc-cfg (#661) 2026-02-17 10:07:40 -05:00
Dale Seo
5a6ff1f74c
fix: duplicate meta serialization (#662) 2026-02-17 10:03:01 -05:00
Peter
61ffba84b5
fix: sort list_all() output in ToolRouter and PromptRouter for deterministic ordering (#665)
ToolRouter::list_all() and PromptRouter::list_all() iterate over a
HashMap, which returns items in non-deterministic order. Since list_all()
backs the tools/list and prompts/list MCP protocol responses, this causes
MCP clients to receive differently-ordered results across calls and
process restarts, leading to intermittent tool discovery failures.

Sort the output alphabetically by name to guarantee stable ordering.
2026-02-17 09:37:17 -05:00
Dale Seo
08a5b0551b
fix: align task response types with MCP spec (#658) 2026-02-13 17:56:44 -05:00
Rodolfo Olivieri
453032faed
chore: include LICENSE in final crate tarball (#657)
Required for packaging in distributions such as Fedora and others.

Verified with:
$ cargo package --list | grep LICENSE
2026-02-13 16:13:45 -05:00
Arc
016b7d3bfa
feat: add support for custom HTTP headers in StreamableHttpClient (#655)
* feat: add support for custom HTTP headers in StreamableHttpClient

* feat: implement reserved header checks for custom HTTP headers in StreamableHttpClient
2026-02-13 12:28:55 -05:00
dependabot[bot]
70f6380b48
chore(deps): update rand requirement from 0.9 to 0.10 (#650)
* chore(deps): update rand requirement from 0.9 to 0.10

Updates the requirements on [rand](https://github.com/rust-random/rand) to permit the latest version.
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rust-random/rand/compare/rand_core-0.9.1...0.10.0)

---
updated-dependencies:
- dependency-name: rand
  dependency-version: 0.10.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix: update rand import from Rng to RngExt for rand 0.10 compatibility

In rand 0.10, the Rng trait was renamed to RngExt. This updates the
imports in the example servers to use the new trait name.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alex Hancock <alexhancock@block.xyz>
2026-02-13 10:24:17 -05:00
Anar Azadaliyev
d9a5560953
feat(auth): add token_endpoint_auth_method to OAuthClientConfig (#648)
* feat(auth): add token_endpoint_auth_method to OAuthClientConfig

Some OAuth providers (e.g. HubSpot) require client credentials to be
sent as POST body parameters (client_secret_post) instead of via HTTP
Basic Auth header. The oauth2 crate defaults to BasicAuth, and rmcp
had no way to override this, causing TokenExchangeFailed errors.

Add an optional `token_endpoint_auth_method` field to OAuthClientConfig
that accepts "client_secret_post" (RequestBody) and "client_secret_basic"
(BasicAuth). Unknown values are silently ignored, preserving the default.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(auth): derive token_endpoint_auth_method from server metadata

Move auth method selection from per-client config to server's
AuthorizationMetadata, which is the correct OAuth 2.0 approach.
Servers like HubSpot advertise token_endpoint_auth_methods_supported
in their metadata; reading it from there avoids manual configuration
and prevents TokenExchangeFailed errors with non-BasicAuth providers.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(auth): read token_endpoint_auth_methods_supported from additional_fields

Move token_endpoint_auth_methods_supported out of AuthorizationMetadata
as an explicit field and read it from the serde(flatten) additional_fields
HashMap instead. This avoids serializing `null` when the field is absent,
which broke Zod validation in downstream consumers like MCP Inspector.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(auth): prefer basic auth when both methods supported and improve test assertions

When token_endpoint_auth_methods_supported contains both client_secret_post
and client_secret_basic, default to basic auth per RFC 6749 §2.3.1.
Update configure_client tests to assert actual AuthType instead of is_some().

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style(auth): apply cargo fmt formatting

* style(auth): apply nightly cargo fmt import grouping

* revert: undo .gitignore change

---------

Co-authored-by: Anar Azadaliyev <anar.azadaliye@gmail.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 09:56:07 -05:00
Andrew Gazelka
bb534a7a68
refactor: remove unused axum dependency from server-side-http feature (#642)
* refactor: remove unused axum dependency from server-side-http feature

The `server-side-http` feature included `dep:axum` but axum was never
actually used in the rmcp library source code (0 references found).

The `StreamableHttpService` is a tower service that works with any
HTTP server framework. Users can choose to use:
- axum (via `Router::nest_service()` or `fallback_service()`)
- hyper directly (via `hyper_util::service::TowerToHyperService`)
- any other tower-compatible HTTP server

This change removes the unnecessary transitive dependency, giving users
more flexibility in their choice of HTTP server framework.

Examples that use axum already have their own explicit axum dependency
in their Cargo.toml, so they continue to work unchanged.

* refactor: move axum to dev-dependencies with minimal features

- Remove axum from library dependencies (not used in library source)
- Add axum to dev-dependencies for tests with minimal features:
  default-features = false, features = ["http1", "tokio"]
- Examples have their own axum dependency and are unaffected

This addresses review feedback from @ofek to use minimal features,
while ensuring axum is only bundled for running rmcp's own tests,
not for downstream users.
2026-02-12 12:00:47 -05:00
Wils Dawson
61845d61c4
11-25-2025 compliant Auth (#651)
* fix: correct discovery for AS metadata

* fix: add commitlint to dev container

* feat: add RFC 8707 support for resource parameter

* feat: pkce method verification

* feat(auth): implement SEP-835 scope handling and 403 upgrade flow

- add WWWAuthenticateParams for parsing scope and resource_metadata from headers
- add ScopeUpgradeConfig and scope tracking in AuthorizationManager
- add InsufficientScopeError and 403 handling in streamable HTTP client
- add scope union computation for progressive authorization
- export new public types: AuthClient, ScopeUpgradeConfig, WWWAuthenticateParams

Co-authored-by: fizy069 <fizy069@users.noreply.github.com>

* fix: reorg auth tests

* feat: add error to www-authenticate header parsing

* feat: consider protected resource metadata in scope selection

* fix: reorganize auth tests

* feat: add examples and docs for updated auth

---------

Co-authored-by: fizy069 <fizy069@users.noreply.github.com>
2026-02-12 11:30:13 -05:00
github-actions[bot]
9cfc905a9e
chore: release v0.15.0 (#636)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-02-10 09:00:28 -05:00
Dale Seo
07028bc0aa
Add optional description field to Implementation struct (#649)
* feat: add optional description field to Implementation struct

* test: update snapshots
2026-02-10 08:36:47 -05:00
Pavel Bezglasny
187597bf7e
feat(elicitation): add support URL elicitation. SEP-1036 (#605) 2026-02-07 21:39:30 -05:00
Dale Seo
edd5b1d7e9
feat: enforce SEP-1577 MUST requirements for sampling with tools (#646) 2026-02-07 20:57:00 -05:00
Dale Seo
8bd3fcb890
Implement SEP-1577: Sampling With Tools (#628)
* feat: implement SEP-1577 sampling with tools support

* feat: add TryFrom<Content> for backward-compatible migration
2026-02-06 12:51:26 +01:00
Jiho Park
be23334f9d
fix(tasks): avoid dropping completed task results during collection (#639)
* fix(tasks): avoid dropping completed task results during collection

* chore(tasks): make `task_result_receiver` required

* refactor(tasks): make `collect_completed_results` private
2026-02-05 09:00:09 +01:00
Guy Lichtman
f6ebc7af13
fix(auth): oauth metadata discovery (#641)
* fix(auth): oauth metadata discovery

* fix: format auth.rs
2026-02-04 17:57:52 +01:00
Rodolfo Olivieri
bfd9cc08d8
feat: add native-tls as an optional TLS backend (#631)
Add reqwest-native-tls feature flag to allow users to choose between
rustls (default) and native-tls for HTTP transports.

native-tls uses platform-native TLS implementations:
- OpenSSL on Linux
- Secure Transport on macOS
- SChannel on Windows

This is particularly useful for Linux distribution packagers who need
to link against system TLS libraries (e.g., OpenSSL) rather than
bundling a separate TLS implementation. Linking against system libs
ensures security updates are applied system-wide and satisfies
distribution packaging policies.

Updated documentation to explain the available TLS backend options.
2026-02-03 19:27:37 -05:00
Evgenii
53b64a9f87
fix: compilation with --no-default-features (#593) 2026-02-03 19:21:06 -05:00
Luca Chang
df6c3f0665
fix(tasks): expose execution.taskSupport on tools (#635)
* fix(tasks): expose execution.taskSupport on tools

* feat: implement taskSupport validation on server
2026-02-03 19:17:36 -05:00
Andrew Harvard
1794fe1548
feat(capabilities): add extensions field for SEP-1724 (#643)
Add support for MCP extension capabilities in both ClientCapabilities
and ServerCapabilities structs, as specified in SEP-1724.

Changes:
- Add ExtensionCapabilities type alias (BTreeMap<String, JsonObject>)
- Add 'extensions' field to ClientCapabilities struct
- Add 'extensions' field to ServerCapabilities struct
- Update builder macros and impl blocks for both structs
- Add comprehensive tests for extension capabilities
- Update JSON schema test fixtures

This enables clients to advertise extension support during initialize,
such as:

  {
    "capabilities": {
      "extensions": {
        "io.modelcontextprotocol/ui": {
          "mimeTypes": ["text/html;profile=mcp-app"]
        }
      }
    }
  }

Closes #530
2026-02-03 19:14:22 -05:00
apexlnc
32a68aa239
fix(tasks): correct enum variant ordering for deserialization (#634)
Move CustomRequest and CustomResult to end of their respective untagged
enums to ensure specific task variants match before catch-all custom types.
Add deny_unknown_fields to GetTaskInfoResult to prevent matching arbitrary
JSON objects.

Fixes issue where tasks/get, tasks/list, tasks/result, and tasks/cancel
incorrectly deserialized as CustomRequest instead of their typed variants.
2026-01-30 09:30:53 +08:00
github-actions[bot]
8d09f8813d
chore: release v0.14.0 (#623)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-01-23 13:09:02 -05:00
Alex Hancock
613eafbda8
fix(tasks): #626 model task capabilities correctly (#627) 2026-01-23 13:03:31 -05:00
Jonathan Hefner
e623f2acab
docs: show README content on docs.rs (#583)
Use `#![doc = include_str!("../README.md")]` to display README as crate
documentation on docs.rs for both `rmcp` and `rmcp-macros`.

Changes to support this:
- Fix code examples to compile as doc tests (`rust,no_run`)
- Fix broken rustdoc links with explicit `crate::` paths
- Add "Structured Output" section and examples link to rmcp README
- Simplify rmcp-macros README to a summary table with doc links
- Fix grammar throughout
- Add CSS to hide GitHub badges when rendered as rustdoc

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-21 12:56:16 -05:00
Alex Hancock
2e08001f32
fix: don't treat non-success HTTP codes as transport errors (#618) 2026-01-19 09:42:12 +08:00
Dale Seo
9e881a645b
Implement SEP-1319: Decouple Request Payload from RPC Methods (#617)
* feat: implement SEP-1319 Decouple Request Payload from RPC Methods

* test: update tests

* fix: update handler trait methods to use new types

* fix: update examples

* fix: correct deprecation version

* fix: update wrapper macros to use new *Params type names
2026-01-16 12:16:52 -05:00
Alex Hancock
48e989b711
chore: release v0.13.0 (#620)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-01-15 13:24:30 -05:00
Pavel Bezglasny
e49aef65d1
chore(elicitation): improve enum schema builder, small changes of elicitation builder (#608) 2026-01-14 16:15:03 -05:00
Alex Hancock
9b629c609f
chore: add pre-commit hook for conventional commit verification (#619) 2026-01-14 16:01:28 -05:00
Xing
95d3e3f940
fix: use the json rpc error from the initialize response and bubble it up to the client (#569) 2026-01-14 11:28:54 -05:00
Taylor Ninesling
81f858836d
feat: provide blanket implementations for ClientHandler and ServerHandler traits (#609)
* feat!: implement ServerHandler for Box<H> and Arc<H> where H is a ServerHandler

* feat!: implement ClientHandler for Box<H> and Arc<H> where H is a ClientHandler

* test: test Box and Arc have blanket implementations for handler traits

* refactor: deduplicate blanket implementations with macros
2026-01-14 10:53:05 -05:00
Pavel Bezglasny
acb06ea819
fix(build): fix build of the project when no features are selected (#606) 2026-01-14 10:47:50 -05:00
Jack Amadeo
46e149ee8b
chore: clean up optional dependencies (#546) 2026-01-13 21:29:35 -05:00
Tyler Mailman
cc96f379ba
feat(service): add close() method for graceful connection shutdown (#588)
This PR primarily fixes #572 by enabling graceful shutdown without consuming self. While implementing this, I noticed delete_session() is spawned as a background task, which means close() may return before HTTP session cleanup completes. Since this is part of the same shutdown lifecycle and can cause resource leaks/races, I'm including a small, localized fix to ensure cleanup is completed before close() returns. If maintainers prefer, I can split the cleanup timing change into a follow-up PR.

Changes:
- Add close(&mut self) for graceful shutdown without consuming
- Add close_with_timeout() for bounded shutdown operations
- Add is_closed() to check connection state
- Move HTTP delete_session from background spawn to inline cleanup
- Add 5-second timeout on session cleanup to prevent indefinite hangs
- Add Drop impl with debug log if dropped without explicit close

Fixes #572
2026-01-13 16:25:06 -05:00
Maksim Madžar
c4a68295e0
fix: use Semaphore instead of Notify in OneshotTransport to prevent race condition (#611) 2026-01-13 16:15:19 -05:00
centdix
ce559f28e0
feat(auth): add StateStore trait for pluggable OAuth state storage (#614)
* feat(auth): add StateStore trait for pluggable OAuth state storage

* fix(examples): use CLI server_url for transport connection
2026-01-13 15:33:25 -05:00
Dale Seo
2286564f65
refactor: re-export ServerSseMessage from session module (#612) 2026-01-12 14:22:29 -05:00
Dale Seo
971c64c31f
Implement SEP-1699: Support SSE Polling via Server-Side Disconnect (#604)
* feat: implement SEP-1699 SSE polling via server-side disconnect

* test: add tests for priming behavior on stream start and close
2026-01-09 13:22:57 -05:00
Tanish Desai
61f7b7b99e
fix: add OpenID Connect discovery support per spec-2025-11-25 4.3 (#598)
* fix: add OpenID Connect discovery support per spec-2025-11-25 4.3

Previously only tried OAuth 2.0 endpoints. Now tries OAuth first, then
OpenID Connect Discovery 1.0 in the spec-mandated priority order.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* fix: format auth.rs test assertions

Reformat assert_eq! statements to satisfy rustfmt checks in CI.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

---------

Signed-off-by: tanish111 <tanishdesai37@gmail.com>
2026-01-09 12:20:32 -05:00
David Stern
63d89b1a4e
fix: only try to refresh access tokens if we have a refresh token or an expiry time (#594) 2026-01-06 09:34:42 +08:00
Pavel Bezglasny
e9029ccc99
feat(elicitation): implement SEP-1330 Elicitation Enum Schema Improvements (#539) 2025-12-24 13:54:20 -05:00
jokemanfire
621c9f619e
feat(task): add task support (SEP-1686) (#536)
Signed-off-by: jokemanfire <hu.dingyang@zte.com.cn>
2025-12-22 09:01:00 -05:00
Dale Seo
eeacd1375f
Add optional icons field to RawResourceTemplate (#589)
* feat: add optional icons field to RawResourceTemplate

* chore: update JSON schema for ResourceTemplate icons
2025-12-18 16:56:55 -05:00
github-actions[bot]
0d65822c38
chore: release v0.12.0 (#577)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-12-18 16:07:25 -05:00
Michael Bolin
e0faf1ed51
feat: add support for custom requests (#590)
#580 and #556 introduced support for custom notifications,
so this PR takes the next logical step and adds support for custom requests:

- Introduces `CustomRequest` and `CustomResult` model types, wires them into the client/server
  request and result unions, and allows `ClientRequest::method()` to return the dynamic method
  name.
- Implements serde and meta handling for `CustomRequest` so `_meta` is carried through
  extensions; adds default `on_custom_request` handlers that return `METHOD_NOT_FOUND` unless
  overridden.
- Updates JSON schema fixtures to include the new request/result shapes and `EmptyObject`
  strictness.
- Adds tests for custom request roundtrips and end-to-end client↔server handling.
- Focused integration test in `crates/rmcp/tests/test_custom_request.rs`.

For additional testing, I used this locally to update Codex to use a custom
request instead of a custom notification so that it gets an "ack" from the MCP
server to ensure it has processed the update before sending more messages:
https://github.com/openai/codex/pull/8142.
2025-12-18 12:41:06 -05:00
Michael Bolin
2e3cc4a973
feat: add support for custom server notifications (#580)
https://github.com/modelcontextprotocol/rust-sdk/pull/556 introduced support for
custom client notifications, so this PR makes the complementary change, adding
support for custom server notifications.

MCP clients, particularly ones that offer "experimental" capabilities,
may wish to handle custom server notifications that are not part of the
standard MCP specification. This change introduces a new
`CustomServerNotification` type that allows a client to process
such custom notifications.

- introduces `CustomServerNotification` to carry arbitrary methods/params while
  still preserving meta/extensions; wires it into the `ServerNotification` union
  and `serde` so `params` can be decoded with `params_as`
- allows client handlers to receive custom notifications via a new
  `on_custom_notification` hook
- adds integration coverage that sends a custom server notification end-to-end
  and asserts the client sees the method and payload

Test:

```shell
cargo test -p rmcp --features client test_custom_server_notification_reaches_client
```
2025-12-16 12:48:03 -05:00
Dale Seo
d7a05aa43f
fix: update process-wrap to v9.0 (#586) 2025-12-15 15:05:06 +08:00
Tanish Desai
f20ed202af
Add SEP-991 (CIMD) support for URL-based client IDs (#570)
* feat(auth): add cimd support for SEP-991

add cimd support for url-based client ids

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* test(auth): add unit tests for is_https_url helper

Add test coverage for is_https_url helper to validate HTTPS scheme, non-root paths,
and reject http, javascript, data schemes, and invalid inputs per SEP-991 requirements.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* feat(example): add CIMD OAuth server for SEP-991 testing

Implements a new server example (servers_cimd_auth_streamhttp) that
demonstrates CIMD (Client ID Metadata Document) support for URL-based
client IDs. The server validates client_id URLs, fetches and validates
client metadata documents, and provides OAuth 2.0 authorization endpoints
with MCP integration for end-to-end testing.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* fix(oauth): add CORS headers to token endpoint

Add CORS headers to token endpoint to allow cross-origin requests from browsers
during OAuth authorization code exchange flow.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* refactor: improve is_https_url function and consolidate tests

- Improve is_https_url function formatting and readability
- Merge all test cases into single test_is_https_url_scenarios function
- Add missing test case for "https://" URL

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* refactor: use map_err instead of match for error handling in auth.rs

Replace the verbose match statement with
map_err for more idiomatic

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* feat: add client-metadata.json

Add client metadata file for SEP-991 CIMD
authentication support

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

---------

Signed-off-by: tanish111 <tanishdesai37@gmail.com>
2025-12-10 08:55:38 -05:00
Dale Seo
8d33b155b6
refactor: merge cached_schema_for_type into schema_for_type (#581) 2025-12-09 20:04:52 -05:00
jokemanfire
bce0555068
fix(oauth): rfc8414 should judement the response_types (#485)
response_types_supported should be judement while try to do 'Authorization Code Flow'

Signed-off-by: jokemanfire <hu.dingyang@zte.com.cn>
2025-12-09 11:18:18 -05:00
dependabot[bot]
ad608f080e
chore(deps): update darling requirement from 0.21 to 0.23 (#574)
Updates the requirements on [darling](https://github.com/TedDriggs/darling) to permit the latest version.
- [Release notes](https://github.com/TedDriggs/darling/releases)
- [Changelog](https://github.com/TedDriggs/darling/blob/master/CHANGELOG.md)
- [Commits](https://github.com/TedDriggs/darling/compare/v0.21.0...v0.23.0)

---
updated-dependencies:
- dependency-name: darling
  dependency-version: 0.23.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: jokemanfire <hu.dingyang@zte.com.cn>
2025-12-09 09:15:05 +08:00
github-actions[bot]
4c87f7f163
chore: release v0.11.0 (#568)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-12-08 16:42:02 -05:00
Dale Seo
df84555065
Implements outputSchema validation (#566)
* feat: implement output schema validation

* fix: calculator example comply MCP spec

* refactor: merge cached_schema_for_output into schema_for_output
2025-12-08 16:13:19 -05:00
Pavel Bezglasny
81411fc12d
feat(meta): add _meta field to prompts, resources and paginated result (#558) 2025-12-04 09:38:47 +08:00
adam jones
eb5a7f7408
feat!: remove SSE transport support (#562)
SSE transport has been removed from the MCP specification in favor of
streamable HTTP. This removes all SSE-specific transport code:

- Remove `transport-sse-client` and `transport-sse-server` features
- Remove `SseClientTransport` and `SseServer` types
- Remove SSE-specific examples (`counter_sse`, `counter_sse_directly`)
- Migrate auth examples from SSE to streamable HTTP
- Update tests to remove SSE transport usage
- Update documentation

BREAKING CHANGE: The following have been removed:
- `transport-sse-client` feature
- `transport-sse-client-reqwest` feature
- `transport-sse-server` feature
- `SseClientTransport` type
- `SseServer` type
- `sse_client` and `sse_server` modules

Users should migrate to streamable HTTP transport which provides
equivalent functionality. See `StreamableHttpClientTransport` and
`StreamableHttpService` for the replacement APIs.

Ref: https://github.com/modelcontextprotocol/rust-sdk/pull/561#issuecomment-3576551699
2025-12-01 20:40:13 -05:00
Jonson Petard
3dee024325
fix(streamable-http): gracefully shutdown while client connected (#494)
* fix(streamable-http): gracefully shutdown while client connected

* fix: adviced comments

* fix: windows test build
2025-12-02 09:22:52 +08:00
github-actions[bot]
57d1ac94a0
chore: release v0.9.2 (#567)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-12-01 16:06:44 -05:00
Michael Bolin
4ef1a163f4
feat: add support for custom client notifications (#556)
MCP servers, particularly ones that offer "experimental" capabilities,
may wish to handle custom client notifications that are not part of the
standard MCP specification. This change introduces a new
`CustomClientNotification` type that allows a server to process
such custom notifications.

- introduces `CustomClientNotification` to carry arbitrary methods/params while
  still preserving meta/extensions; wires it into the `ClientNotification` union
  and `serde` so `params` can be decoded with `params_as`
- allows server handlers to receive custom notifications via a new
  `on_custom_notification` hook
- adds integration coverage that sends a custom client notification end-to-end
  and asserts the server sees the method and payload

Test:

```shell
cargo test -p rmcp --features client test_custom_client_notification_reaches_server
```
2025-12-01 15:58:18 -05:00
Tanish Desai
b6dcb282d9
chore: replace paste with pastey for macros feature (#564)
Signed-off-by: tanish111 <tanishdesai37@gmail.com>
2025-12-01 13:11:03 -05:00
github-actions[bot]
2b60f8af0f
chore: release v0.9.1 (#548)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-11-24 13:01:48 -05:00
Tanish Desai
97ef6c97e4
Implementation of SEP-986: Specify Format for Tool Names (#551)
* feat: implement SEP-986 tool name validation and error reporting

Adds validation for MCP tool naming conventions as specified in SEP-986.
Ensures Rust SDK enforces standardized tool name formats, provides clear
errors for invalid names, and improves consistency across implementations.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* fix(doctests): correct import paths in tool_name_validation

Update doctest examples to use the correct module path
rmcp::handler::server::tool_name_validation instead of
rmcp::model::tool_name_validation.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* fix: only warn when warnings exist

Prevent empty warnings array from triggering warning output.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* fix: remove internal check

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* refactor: remove doc comments from validation functions

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* refactor: remove doc comments from add_route functions

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

* refactor: make tool name validation helpers private

Made ToolNameValidationResult and its functions and fields private.
Made validate_tool_name and issue_tool_name_warning private.

Signed-off-by: tanish111 <tanishdesai37@gmail.com>

---------

Signed-off-by: tanish111 <tanishdesai37@gmail.com>
2025-11-24 10:40:03 -05:00
Xijun Dai
cf45070ce7
feat(streamable-http): support both SSE and JSON response formats (#540)
What this enables:

- Clients can accept either Server-Sent Events (SSE) or JSON responses
- Flexible content negotiation based on server preferences
- Improved interoperability with different MCP server implementations
2025-11-21 15:47:29 +08:00
Jack Amadeo
da57ee7697
fix: don't block on creating the SSE stream (#553) 2025-11-19 17:20:00 -08:00
jokemanfire
76cdf48b68
fix(shemars): use JSON Schema 2020-12 as Default Dialect (#549)
TODO: Not fully compatible with 2020-12 yet.
2025-11-19 09:55:39 +08:00
Måns
b6cbd39503
fix(oauth): let OAuth discovery skip to next well-known URL candidate on JSON parse error. (#545) 2025-11-18 09:21:25 +08:00
github-actions[bot]
9cba162071
chore: release v0.9.0 (#535)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-11-17 10:31:01 -05:00
Alex Hancock
31be9b25b5
feat(auth): implement CredentialStore trait (#542) 2025-11-17 10:17:08 -05:00
Dylan Anthony
03040f8b0b
feat(tool): add _meta to tool definitions (#534) 2025-11-11 09:27:52 +08:00
github-actions[bot]
941300acbe
chore: release v0.8.5 (#512)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-11-05 09:25:44 -05:00
Gabriel Peal
82f9b0976a
fix(oauth): respect oauth-protected-resource discovery (#511) 2025-11-05 09:19:13 -05:00
github-actions[bot]
101b8ad84f
chore: release v0.8.4 (#506)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-11-04 16:39:13 -05:00
Gabriel Peal
dcbeb9b9bc
fix(oauth): fix oauth credential refresh (#509)
auth.rs was using an in-memory expires-at which is only set on initial token exchange.
Instead, this PR switches it to use the expires-at set in the credentials that are passed in.
2025-11-04 16:17:11 -05:00
Alex Hancock
d3ddc09e52
fix: do not manually construct fallback authorization metadata (#507) 2025-11-03 12:08:32 -05:00
github-actions[bot]
9012709079
chore: release v0.8.3 (#498)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-10-22 16:21:26 -04:00
Gabriel Peal
3822d9d39c
fix: accept 204 in addition to 202 on initialize (#497) 2025-10-22 15:08:33 -04:00
github-actions[bot]
44129e496d
chore: release v0.8.2 (#480)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-10-20 20:52:35 -04:00
Gabriel Peal
e98e0d05df
fix(oauth): three oauth discovery and registration issues (#489) 2025-10-20 20:49:43 -04:00
sktrpathi
11093bc830
feat: add type-safe elicitation schema support (#465) (#466)
* feat: add type-safe elicitation schema support (#465)

Implement type-safe schema definitions for MCP elicitation requests,
replacing generic `JsonObject` with strongly-typed primitive schemas
per the [MCP 2025-06-18 specification](https://spec.modelcontextprotocol.io/specification/2025-06-18/server/elicitation/).

Features:
- Type-safe schema hierarchy (`StringSchema`, `NumberSchema`, `IntegerSchema`, `BooleanSchema`)
- Builder pattern with fluent API and 20+ convenience methods
- Build-time validation ensuring required fields exist in properties
- Private fields enforcing invariants through validated constructors
- Comprehensive validation support (range, length, format, enums)
- Typed property methods for cleaner schema construction

Benefits:
- Compile-time type safety prevents invalid schema construction
- 60-70% reduction in boilerplate through convenience methods
- Enforces MCP specification requirement for primitive-only properties
- Better IDE autocomplete and type inference
- Runtime validation catches schema errors early

Breaking changes:
- `CreateElicitationRequestParam.requested_schema` changed from `JsonObject` to `ElicitationSchema`
- `ElicitationSchemaBuilder::build()` now returns `Result` instead of direct value

Fixes #465

* fix: fix RMCP compliance

* feat: add conversion methods to ElicitationSchema

Add from_json_schema() and from_type() methods to ElicitationSchema
for easier type-to-schema conversion. This addresses feedback about
improving ergonomics when working with generated schemas.

Also make all struct fields public for better flexibility.

* chore: change `StringFormat` to enum
2025-10-15 17:55:10 +08:00
jokemanfire
6cd779c5d7
fix(oauth): dynamic client registration should be optional (#463)
Signed-off-by: jokemanfire <hu.dingyang@zte.com.cn>
2025-10-14 09:30:29 +08:00
4t145
75a7e48441
docs(macro): fix visibility attribute's usage of handler macro (#481) 2025-10-13 11:21:39 +08:00
Honsun Zhu
b749e3c9b4
feat(SEP-973): following change Icon.sizes from string to string array (#479)
Ref:
https://github.com/modelcontextprotocol/modelcontextprotocol/pull/1531
2025-10-10 19:23:04 +08:00
Min Wei
aeeff75e12
Streamable HTTP: drain SSE frames until the initialize response, ignoring early notifications to prevent handshake timeouts (#467)
Co-authored-by: Min Wei <minwei@microsoft.com>
2025-10-10 18:49:22 +08:00
Loocor
87fcc7c5cb
fix(sse-client): consume control frames; refresh message endpoint (#448) 2025-10-09 18:45:56 +08:00
github-actions[bot]
c86883b81c
chore: release v0.8.1 (#473)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-10-07 15:51:03 -04:00
Gabriel Peal
923145afdc
fix(oauth): pass bearer token to all streamable http requests (#476)
* fix(oauth): attach bearer token to all streaming http requests

* fix(typo): fix an unrelated typo

There was an errant typo in the CHANGELOG that is breaking CI
2025-10-07 15:35:06 -04:00
Alex Hancock
34f482375c
fix: fix spellcheck on intentional typo in CHANGELOG (#470) 2025-10-06 09:33:42 -04:00
github-actions[bot]
a4def1100d
chore: release v0.7.1 (#454)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-10-03 21:16:55 -04:00
Gabriel Peal
6011f34ddf
feat: allow clients to override client_name (#469)
Many MCP Servers use client_name for a variety of things including:
* Whitelisting
* Logos
* Copy shown directly on the page
* etc

As a result, it's important for MCP Clients to be able to override the client name.
2025-10-03 21:03:31 -04:00
Huabing (Robin) Zhao
0566d132ea
fix(oauth): support suffixed and preffixed well-knonw paths (#459)
Signed-off-by: Huabing Zhao <zhaohuabing@gmail.com>
2025-09-30 15:41:16 +08:00
V
717ec56e23
fix: generate default schema for tools with no params (#446)
* fix: generate default schema for tools with no params
2025-09-26 18:16:08 +08:00
Jack Amadeo
57fc428c57
chore: bump to rust 1.90.0 (#453) 2025-09-24 12:58:54 -04:00
Jack Amadeo
aff82ed0c4
chore: release v0.7.0 (#452) 2025-09-24 09:15:58 -04:00
Jack Amadeo
5216ab2bbd
fix: return auth errors (#451) 2025-09-23 15:58:00 -04:00
rliang
a11c4de332
fix(macros): support #[doc = include_str!(...)] for macros (#444)
Add tests and return syn::Result from extract_doc_line to propagate parsing errors.
2025-09-23 16:49:43 +08:00
Takeshi Yoneda
4c8f5ba7b3
fix(oauth): do not treat empty secret as valid for public clients (#443)
Signed-off-by: Takeshi Yoneda <t.y.mathetake@gmail.com>
2025-09-22 09:08:07 +08:00
Rob Jellinghaus
ddef4ce529
fix(clippy): add doc comment for generated tool attr fn (#439)
This change makes the `tool` macro's output safe for the `missing_docs` lint, by
emitting a doc comment for the generated `[tool]_tool_attr` function. This doc
comment is emitted regardless of whether the tool function is public, for simplicity.

We are building an MCP server using `rmcp` and discovered that the current crate
was not compatible with the `#![deny(missing_docs)]` lint which we use everywhere.

Tested by modifying the `test_tool_macros.rs` test to use `#![deny(missing_docs)]`
and adding doc comments to all pub fns and structs in that file.

None.

Fixes #438.

Co-authored-by: RobJellinghaus <rjellinghaus@live.com>
2025-09-17 15:02:56 +08:00
Peter Nehrer
4ee2add899
bugfix: Non-empty paths in OAuth2 Authorization Server Metadata URLs (#441)
* fix: support non-empty paths in OAuth2 Authorization Server Metadata URLs

* fix: address formatting errors
2025-09-17 15:02:37 +08:00
David Stern
271cf0b232
fix(oauth): require CSRF token as part of the OAuth authorization flow. (#435)
* Require CSRF token as part of the authorization flow.

* Update auth example.

* Update docs/OAUTH_SUPPORT.md.
2025-09-12 09:27:11 +08:00
github-actions[bot]
83ce13c331
chore: release v0.6.4 (#426)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-11 14:08:13 -04:00
Alex Hancock
b57aa47693
feat(SEP-973): add support for icons and websiteUrl across relevant types (#432) 2025-09-11 11:49:03 -04:00
fucktx
6fbd941a32
fix:crates/rmcp/src/handler/client/progress.rs dispacher-> dispatcher (#429) 2025-09-10 17:03:35 -04:00
sktrpathi
926cb33845
fix: build issue due to missing struct field (#427)
Commit 452fe2c broke `Reference::for_prompt` where it missed
the field `title` for `struct PromptReference`, which broke
the build.

This commit fixes that.
2025-09-08 15:36:36 +08:00
Quang Luong
a2fc90af49
Skip notification in initialization handshake (#421)
* fix: handle logging and ping in handshake

We handle the initialization process more robustly.
- Allow logging and ping
- For other messages, we simply ignore it instead of rejecting right away

* fix: inject context to notification handler
2025-09-08 15:18:14 +08:00
Andrei G
452fe2c50f
feat: implement context-aware completion (MCP 2025-06-18) (#396)
* feat: implement MCP completion specification 2025-06-18

Complete implementation of MCP completion specification with performance optimizations:

Core Features:
- Add CompletionContext for context-aware completion with previously resolved arguments
- Implement CompletionProvider trait with async support and dyn compatibility
- Create DefaultCompletionProvider with optimized fuzzy matching algorithm
- Add comprehensive validation and helper methods to CompletionInfo
- Update ServerHandler to handle completion/complete requests
- Add client convenience methods for prompt and resource completion

Performance Optimizations:
- Zero-allocation fuzzy matching using index-based scoring
- Top-k selection with select_nth_unstable instead of full sorting
- Pre-allocated vectors to avoid reallocations during matching
- Char-based case-insensitive matching to minimize string operations
- 5-8x performance improvement for large candidate sets

API Design:
- Context-aware completion supporting multi-argument scenarios
- Type-safe validation with MAX_VALUES limit (100 per MCP spec)
- Helper methods: with_all_values, with_pagination, validate
- Reference convenience methods: for_prompt, for_resource
- Client methods: complete_prompt_argument, complete_resource_argument

Testing:
- 17 comprehensive tests covering all functionality
- Schema compliance tests for MCP 2025-06-18 specification
- Performance tests with <100ms target for 1000 candidates
- Edge case and validation tests

Schema Updates:
- Add CompletionContext to JSON schema
- Update CompleteRequestParam with optional context field
- Maintain backward compatibility with existing API

* test: add comprehensive fuzzy matching tests for completion

Add three new test cases to enhance coverage of fuzzy matching algorithm:

- test_fuzzy_matching_with_typos_and_missing_chars: Tests subsequence matching
  with real-world scenarios including abbreviated patterns, case-insensitive
  matching, and complex file/package name completion

- test_fuzzy_matching_scoring_priority: Validates scoring system prioritizes
  exact matches > prefix matches > substring matches > subsequence matches

- test_fuzzy_matching_edge_cases: Covers boundary conditions including
  single character queries, oversized queries, and repeated characters

These tests ensure robust fuzzy search functionality for MCP completion
specification implementation with proper handling of user typos and
incomplete input patterns.

* feat: improve completion algorithms, add comprehensive tests and example

- Enhance fuzzy matching algorithm with acronym support for multi-word entries
- Add comprehensive scoring system for better relevance ranking
- Implement multi-level matching: exact, prefix, word prefix, acronym, substring
- Add context-aware completion scoring with proper priority ordering
- Optimize performance through efficient character-by-character matching
- Support case-insensitive acronym matching
- Improve code quality with clippy fixes and async fn syntax
- Add comprehensive test suite covering edge cases and acronym matching
- Create completion example server demonstrating weather-related prompts

* fix(test): typos

* refactor: improve completion API and replace example with SQL query builder

- Remove DefaultCompletionProvider from library core
- Move completion logic to examples following review feedback
- Update CompletionContext.argument_names() to return Iterator for better performance
- Replace tech search example with SQL query builder demonstrating progressive completion
- Add context-aware completion that adapts based on filled arguments
- Use proper Option types for optional SQL fields (columns, where_clause, values)
- Demonstrate real-world value of argument_names() method for dynamic completion flow

The SQL query builder showcases:
• Progressive field availability based on operation type
• Context validation using argument_names()
• Proper Optional field handling
• Smart completion that guides user through multi-step form

* fix: fmt
2025-09-08 14:44:49 +08:00
Dale Seo
b482cfc4bb
fix: generate simple {} schema for tools with no parameters (#425) 2025-09-08 14:40:02 +08:00
4t145
1b70f5b032
feat: add title field for data types (#410)
* feat(model): add title field to various structs

* fix(test): fix test json schema

* fix(model): allow boxed type  in `ts_union` macro
2025-09-08 09:15:22 +08:00
github-actions[bot]
b88dab547c
chore: release v0.6.3 (#420)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-04 17:23:18 -04:00
David Soria Parra
9105ba7963
fix: change JSON-RPC request ID type from u32 to i64 (#416)
The JSON-RPC 2.0 specification allows the ID field to be any JSON number,
including negative integers and large values. The previous u32 implementation
was limited to 0-4,294,967,295 and couldn't handle negative IDs.

Changes:
- Changed NumberOrString::Number from u32 to i64 to support full JSON number range
- Updated deserializer to handle both signed and unsigned integers
- Modified AtomicU32Provider to use AtomicU64 internally with i64 conversion
- Fixed progress token handling in meta.rs for i64 values
- Added comprehensive test for negative and large request IDs

This ensures full compliance with the JSON-RPC 2.0 specification.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-09-04 15:22:44 -04:00
github-actions[bot]
ccbd7f0674
chore: release v0.6.2 (#407)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-04 15:06:19 -04:00
Andrew Harvard
4eb413b6c6
Spec conformance: meta support and spec updates (#415)
* feat: add _meta to content blocks and embedded resources; update schemas

* feat: set default protocol version; add _meta to content blocks/resources; update schemas

* chore: format content.rs via rustfmt

* chore(protocol): keep LATEST at 2025-03-26 per review until full 2025-06-18 compliance

* feat(prompt): add constructors with optional meta for image and resource

- Keep text helper; meta is currently ignored for text until schema supports it.

* refactor(prompt): simplify constructors so meta is optional; remove duplicate non-meta variants

* fix: modify code comment about version

* refactor(prompt): rename meta parameters in new_resource function for clarity
2025-09-04 14:23:36 -04:00