33 Commits

Author SHA1 Message Date
pietrozullo ad42b4bb3e docs: noindex auto-generated Python API reference instead of searchable flag
The searchable: false approach on the API Reference tab was inert on
visible tabs. Switch to per-page noindex: true frontmatter, which keeps
pages in the sidebar but excludes them from search indexing (search
engines, internal docs search, and AI context) so generic queries like
"CLI" surface curated guides instead of the generated reference.

Applied to all 73 existing reference pages and emitted by the generator
on every regeneration.

Closes MCP-2398
2026-06-29 10:23:42 +02:00
Andrew Khadder efa7fe78b2 Canary (#1719)
* fix(cli): update EnvVariable type to allow null values for sensitive rows (#1717)

- Modified the `value` property in the `EnvVariable` interface to accept `null`, indicating write-only sensitive rows where the stored value is withheld by the API.
- Adjusted the `printEnvVar` function to handle cases where `value` is `null`, ensuring proper display of sensitive information.

* chore: enter canary prerelease mode

* chore(typescript): version packages (canary)

* feat(server): add outgoing notification logging (#1674)

* chore(typescript): version packages (canary)

* fix(server): mount RFC 8414 canonical well-known paths for path-suffix issuers (#1684)

* fix(server): mount RFC 8414 canonical well-known paths for path-suffix issuers

Construct upstream OAuth/OIDC metadata URLs per RFC 8414 and OIDC
Discovery, and mount canonical path-suffixed routes on the MCP server
when the upstream issuer includes a path component.

Fixes #1576

Co-authored-by: Andrew Khadder <khandrew1@users.noreply.github.com>

* fix(server): mount OIDC discovery at root only; stop leaking error detail

Remove the unreachable, malformed OIDC path-suffix local mount (OIDC
Discovery appends the well-known segment to the issuer, so there is no
canonical form under the openid-configuration prefix, and no client flow
reaches a path-suffixed local route). Keep the RFC 8414 OAuth path-suffix
mount. Return a generic error_description to clients and log the raw
exception server-side instead of echoing it.

* style: apply prettier formatting

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Andrew Khadder <khandrew1@users.noreply.github.com>

* chore(typescript): version packages (canary)

* fix(server/oauth): broker upstream OAuth callback through /oauth/callback (#1728)

In proxy mode the server was forwarding each MCP client's redirect_uri
straight to the upstream provider, which forced every client's callback
(Claude, ChatGPT, the inspector, ...) to be pre-registered on the
provider. Instead, /authorize now sends the upstream the server's own
/oauth/callback and packs the client's redirect_uri + state into the
upstream `state` (base64url JSON, stateless). A new GET /oauth/callback
restores them and forwards the code (or upstream error) to the client's
original callback. /token rewrites redirect_uri to the brokered callback
so it matches the authorize request (RFC 6749 §4.1.3). PKCE passes
through untouched.

Also: jwksVerifier now rejects opaque (non-JWT) access tokens with an
actionable message pointing at the missing `audience`, instead of jose's
cryptic "Invalid Compact JWS".

Only `<server-domain>/oauth/callback` needs registering upstream now.

Closes MCP-2170

* fix(inspector): route localhost MCP servers through client-side chat (MCP-2419) (#1736)

* fix(inspector): route localhost MCP servers through client-side chat (MCP-2419)

In hosted mode the Chat tab streams through the managed cloud backend
(chatApiUrl), which connects to the MCP server server-side and cannot reach a
user's localhost server. The request 502s and, lacking CORS headers, surfaces
in the browser as an opaque "Failed to fetch" / CORS error.

Loopback server URLs now fall back to client-side (in-browser) chat streaming,
which already holds a direct session to the localhost server. The configure-key
empty state shows an explanatory notice telling the user the managed key can't
reach their machine and that a personal API key is needed — only in hosted mode;
the local inspector is unchanged.

The localhost check is extracted into a shared serverUrl util (with IPv6 [::1]
bracket handling) plus unit tests, and e2e tests cover the hosted+localhost
fallback, the no-cloud-call guarantee, and the notice's presence/absence.

* fix(inspector): address PR review on MCP-2419 localhost chat fix

- serverUrl: detect the full 127.0.0.0/8 loopback range (not just
  127.0.0.1), anchored so "127.example.com" is not a false positive
- serverUrl tests: cover 127.0.0.0/8 and near-loopback negatives
- e2e: stub the hosted `/api/auth/get-session` endpoint in
  enableHostedChatMode so HostedUserMenu never hits the real cloud
  backend (avoids CI flakiness/slowness)
- changeset: fix grammar

* style(inspector): prettier formatting for e2e test helpers

* chore(typescript): version packages (canary)

* fix(cli): use authoritative GitHub repo-access check for deploy (MCP-2467) (#1737)

The `mcp-use deploy` pre-flight repo-access check listed an installation's
repos and matched the target locally. That only inspected the first page, so
repos on later pages were wrongly reported inaccessible (MCP-2467); fully
paginating it (the prior behavior) hung on very large orgs.

Replace it with a single authoritative question per installation via the new
backend `GET /github/installations/:installationId/repos/:owner/:repo/access`
endpoint (a `repos.get` probe). The installation whose account matches the repo
owner is checked first, falling back to the others, preserving the
across-installations fix from MCP-2358 without paginating.

* chore(typescript): version packages (canary)

* chore(deps): bump esbuild from 0.27.1 to 0.28.1 in /libraries/typescript (#1734)

* chore(deps): bump esbuild from 0.27.1 to 0.28.1 in /libraries/typescript

Bumps [esbuild](https://github.com/evanw/esbuild) from 0.27.1 to 0.28.1.
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)
- [Commits](https://github.com/evanw/esbuild/compare/v0.27.1...v0.28.1)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version: 0.28.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: add changeset for dependabot updates

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(typescript): version packages (canary)

* fix(typescript): silence dev widget logs when project has no widgets (#1730)

* chore(typescript): version packages (canary)

* feat : inspector add scroll-to-bottom button (#1538)

* inspector: add scroll-to-bottom button

* fix(inspector): center chat scroll button

---------

Co-authored-by: Andrew Khadder <andrew@manufact.com>

* chore(typescript): version packages (canary)

* fix(cli): cleanly unsubscribe on Ctrl+C (SIGINT) (#1687)

* fix(cli): add SIGINT handler to cleanly unsubscribe from resource

Addresses #1686

* chore: add cli changeset

---------

Co-authored-by: Andrew Khadder <andrew@manufact.com>

* chore(typescript): version packages (canary)

* fix(inspector): update emulate oauth callback (#1743)

* refactor: centralize screenshot handling and add REPL screenshot support (#1592)

* refactor: centralize screenshot handling and add REPL screenshot support

* chore: fix knip checks

* chore: drop knip version ignore

---------

Co-authored-by: Andrew Khadder <andrew@manufact.com>

* chore(typescript): version packages (canary)

* fix(api): update base URL for remote API calls to manufact.com (#1745)

* chore(config): add Langfuse Cloud API endpoints to exclusion list in lychee.toml

- Updated the `lychee.toml` configuration file to include Langfuse Cloud API endpoints in the exclusion list, preventing 403 errors from bot protection during CI processes. This change ensures valid defaults for API interactions.

* fix(workflow): remove unnecessary flag from pnpm install command in CI configuration

- Updated the `bump-mcp-use-reusable.yml` workflow file to remove the `--config.dangerously-allow-all-builds=true` flag from the `pnpm install` command, streamlining the installation process during CI runs.

* fix(api): update base URL for remote API calls to manufact.com

- Changed the default base URL from 'https://cloud.mcp-use.com' to 'https://cloud.manufact.com' across multiple files, including MCPAgent and RemoteAgent initializations, ensuring consistency in API endpoint references.

* chore(typescript): version packages (canary)

* feat(cli): add support for custom Dockerfile path in deployment options (#1746)

* chore(config): add Langfuse Cloud API endpoints to exclusion list in lychee.toml

- Updated the `lychee.toml` configuration file to include Langfuse Cloud API endpoints in the exclusion list, preventing 403 errors from bot protection during CI processes. This change ensures valid defaults for API interactions.

* fix(workflow): remove unnecessary flag from pnpm install command in CI configuration

- Updated the `bump-mcp-use-reusable.yml` workflow file to remove the `--config.dangerously-allow-all-builds=true` flag from the `pnpm install` command, streamlining the installation process during CI runs.

* feat(cli): add support for custom Dockerfile path in deployment options

- Introduced a new CLI option `--dockerfile` to specify a non-default Dockerfile path relative to the project root.
- Updated the `DeployOptions` interface to include the `dockerfile` property.
- Enhanced deployment command output to display the specified Dockerfile path, improving user feedback during deployment processes.

* refactor(cli): improve console log formatting for Dockerfile output

- Reformatted the console log statement for the Dockerfile option in the deploy command to enhance readability by breaking it into multiple lines. This change aims to maintain consistent code style and improve maintainability.

* chore(typescript): version packages (canary)

* Remove obsolete OAuth proxy callback changeset

* chore(typescript): version packages (canary)

* docs: update canary changelogs

* fix(cli): allow empty env var updates (#1750)

* chore(config): add Langfuse Cloud API endpoints to exclusion list in lychee.toml

- Updated the `lychee.toml` configuration file to include Langfuse Cloud API endpoints in the exclusion list, preventing 403 errors from bot protection during CI processes. This change ensures valid defaults for API interactions.

* fix(workflow): remove unnecessary flag from pnpm install command in CI configuration

- Updated the `bump-mcp-use-reusable.yml` workflow file to remove the `--config.dangerously-allow-all-builds=true` flag from the `pnpm install` command, streamlining the installation process during CI runs.

* fix(cli): allow empty env var updates

* Add changeset for empty env value updates

---------

Co-authored-by: Enrico <2827496+tonxxd@users.noreply.github.com>

* chore(typescript): version packages (canary)

* chore(deps): bump tar from 7.5.11 to 7.5.16 in /libraries/typescript (#1744)

* chore(config): add Langfuse Cloud API endpoints to exclusion list in lychee.toml

- Updated the `lychee.toml` configuration file to include Langfuse Cloud API endpoints in the exclusion list, preventing 403 errors from bot protection during CI processes. This change ensures valid defaults for API interactions.

* fix(workflow): remove unnecessary flag from pnpm install command in CI configuration

- Updated the `bump-mcp-use-reusable.yml` workflow file to remove the `--config.dangerously-allow-all-builds=true` flag from the `pnpm install` command, streamlining the installation process during CI runs.

* chore(deps): bump tar from 7.5.11 to 7.5.16 in /libraries/typescript

Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.11 to 7.5.16.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.11...v7.5.16)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.16
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: add changeset for dependabot updates

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>
Co-authored-by: Enrico <2827496+tonxxd@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(typescript): version packages (canary)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>
Co-authored-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Dhruv Tiwari <144548881+dhruvtiwari6@users.noreply.github.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Andrew Khadder <khandrew1@users.noreply.github.com>
Co-authored-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: kalpchaniyara <kalpchaniyara.2006@gmail.com>
Co-authored-by: Neha Prasad <nehaa9863pd@gmail.com>
Co-authored-by: Arpit Maurya <arpitbabu802@gmail.com>
Co-authored-by: 落尘 <cuidong111@gmail.com>
2026-06-16 09:41:20 -07:00
Pietro Zullo 30b23271d5 fix(python): respect configured inspector path (#1176)
* fix(python): respect configured inspector path

* fix(python): treat inspector path as a base prefix

* fix(python): format inspector fixes for ruff

* fix(ci): run conformance with node 22

* fix(ci): fail conformance runs with empty results

* chore(ci): drop inline conformance result validation

* docs(python): clarify inspector path behavior
2026-03-09 14:24:53 +01:00
Pietro Zullo 0ac1c60a60 feat(python): add mcp_logs_only option to hide non-MCP HTTP access logs (#1164)
* feat(python/server): add mcp_logs_only option to suppress HTTP access logs

When mcp_logs_only=True, all uvicorn access logs are suppressed. MCP
protocol logs (printed directly by MCPLoggingMiddleware) continue to
show. This eliminates the duplicate INFO: lines for MCP requests and
hides non-MCP HTTP traffic (/docs, /inspector, static files).

The implementation is simple: MCPAccessFormatter returns an empty string
when the flag is set, since the middleware already handles MCP logging
via direct stdout prints.

Closes #1162

* fix(python/server): use filter instead of empty string to suppress access logs

Replace the formatter returning "" (which still outputs a blank line)
with a proper MCPLogsOnlyFilter that drops log records entirely.

* docs: update

* docs(python): document mcp_logs_only option in server logging docs
2026-03-06 14:39:21 +01:00
Vincenzo Reina d344233c50 feat(python): add create-mcp-use CLI with rich UI and dependency install (#1097)
* Add uvx create-mcp-use command

* Update docs

* Add docs

* feat(python/cli): improve create-mcp-use with rich UI, dependency install, and telemetry

- Use rich for colored output, spinner, and panel for get-started instructions
- Add ASCII logo matching the TypeScript CLI
- Prompt user to install dependencies after scaffolding (detects uv/pip)
- Add --install and --no-install flags for non-interactive use
- Capture install output to keep terminal clean
- Add CreateMCPUseEvent telemetry to track CLI usage
- Fix starter template pyproject.toml hatch build config for installability

* feat(python/server): auto-retry next available port when default is in use

Add port availability checking before starting uvicorn. When the
requested port is occupied, the server automatically tries the next
port (up to 10 retries) instead of crashing.

Refs #1161

* fix(python/cli): fix linting errors in create-mcp-use CLI

* Revert "feat(python/server): auto-retry next available port when default is in use"

This reverts commit baf3d3233e.

* fix(python/cli): address PR review feedback

- Fix ruff format issues in cli.py
- Fix "Cli" → "CLI" in docs title
- Fix "a MCP" → "an MCP" grammar in quickstart

* docs(python): regenerate API docs for CLI module

* docs: update

---------

Co-authored-by: pietrozullo <pietro.zullo@gmail.com>
2026-03-06 12:25:19 +01:00
Pietro Zullo e935514fc7 feat(python): add icons parameter to MCPServer constructor (#1147)
* fix(python/server): simplify tool JSON Schema for Optional parameters

Pydantic generates {"anyOf": [{"type": "T"}, {"type": "null"}]} for
Optional[T] tool parameters. While valid JSON Schema 2020-12, this
pattern breaks description rendering in the MCP Inspector UI and fails
Gemini API validation (requires top-level type field). MCP signals
optionality via the required array, making the anyOf/null wrapper
redundant.

- Add simplify_optional_schema() utility that collapses nullable anyOf
  into flat {"type": "T"} while preserving description, default, title
- Override MCPServer.add_tool() to apply simplification after Pydantic
  generates the schema
- Add 12 unit tests for the schema simplifier (test_json_schema.py)
- Add 23 unit tests for tool schema output (test_list_tool_format.py)
- Update server_example.py with representative parameter patterns
  including Literal enum types

* docs(python/server): add parameter types and JSON Schema section to tools docs

Document the Python-to-JSON-Schema type mapping, required/optional/nullable
parameter patterns, and Literal enum usage. Includes a note explaining the
anyOf/null simplification that mcp-use applies automatically.

* feat(python/server): add icons parameter to MCPServer constructor

Pass through the icons parameter to FastMCP so server-level icons can
be set directly in the MCPServer constructor.

* docs(python/server): document icons parameter in server overview

* docs(python): update server example with icons and Literal enum params

* style: format server_example.py

* test(python): add unit tests for icons constructor parameter

* docs: regenerate API reference for icons param
2026-03-05 10:17:58 +01:00
Pietro Zullo ccfb07a8ee fix(python): simplify tool JSON Schema for Optional parameters (#1141)
* fix(python/server): simplify tool JSON Schema for Optional parameters

Pydantic generates {"anyOf": [{"type": "T"}, {"type": "null"}]} for
Optional[T] tool parameters. While valid JSON Schema 2020-12, this
pattern breaks description rendering in the MCP Inspector UI and fails
Gemini API validation (requires top-level type field). MCP signals
optionality via the required array, making the anyOf/null wrapper
redundant.

- Add simplify_optional_schema() utility that collapses nullable anyOf
  into flat {"type": "T"} while preserving description, default, title
- Override MCPServer.add_tool() to apply simplification after Pydantic
  generates the schema
- Add 12 unit tests for the schema simplifier (test_json_schema.py)
- Add 23 unit tests for tool schema output (test_list_tool_format.py)
- Update server_example.py with representative parameter patterns
  including Literal enum types

* docs(python/server): add parameter types and JSON Schema section to tools docs

Document the Python-to-JSON-Schema type mapping, required/optional/nullable
parameter patterns, and Literal enum usage. Includes a note explaining the
anyOf/null simplification that mcp-use applies automatically.

* fix(python/server): address PR review comments on json_schema.py

- Fix _simplify_property docstring: says "in place" but returns new dict
- Fix simplify_optional_schema docstring: document fast-path return when
  no properties exist (returns original, not a copy)
- Wrap dict comprehension for line length

* style: format server_example.py

* docs: regenerate API reference for json_schema module
2026-03-05 09:24:46 +01:00
Pietro Zullo 869e56fcf4 fix(python): register debug routes when debug=True passed to run() (#1114)
* fix(python): register debug routes when debug=True passed to run()

When MCPServer was created with debug=False (default) and run(debug=True)
was called, debug routes (/docs, /inspector, /openmcp.json) were never
registered because _add_dev_routes() only ran during __init__.

Now run(debug=True) calls _add_dev_routes() and rebuilds the Starlette
app so routes are available. Also removes dead code in ServerRunner that
could never execute due to the same ordering issue.

Closes #1099

* docs: regenerate API reference after removing debug from ServerRunner.run()

The debug parameter was removed from ServerRunner.run() since debug mode
is now fully handled in MCPServer.run() before the runner is invoked.
2026-02-27 15:32:04 +01:00
Pietro Zullo a9bc4db3ae feat(python): add protocol handlers for logging, completions, subscriptions, and DNS protection (#1004)
* feat(python): add protocol handlers for logging, completions, subscriptions, and DNS protection

Server SDK changes:
- logging/setLevel: stores client level, Context.log() filters by RFC 5424 severity
- completion/complete: default empty handler, overridable via mcp.completion()
- resources/subscribe + unsubscribe: tracks per-session subscriptions
- notify_resource_updated(): broadcasts to all subscribed sessions via WeakSet
- dns_rebinding_protection: explicit constructor parameter (default: False)
- Capabilities patch for subscribe=True

Middleware:
- Added hooks: on_set_logging_level, on_subscribe_resource, on_unsubscribe_resource, on_complete

Tests:
- 9 unit tests for log level filtering (RFC 5424)
- Updated DNS protection tests for explicit flag

Docs:
- logging.mdx: MCP protocol logging section with level filtering
- resources.mdx: subscription section with example
- middleware.mdx: new hooks documented

Refs:
- https://modelcontextprotocol.io/specification/2025-11-25/server/utilities/logging
- https://modelcontextprotocol.io/specification/2025-11-25/server/resources#subscriptions

* style: format adapter files for ruff 0.15
2026-02-14 18:53:30 -08:00
Pietro Zullo d789a92b4b feat(server): Bearer Token authentication for Python MCP server (#841)
* Fix DNS rebinding protection for cloud/proxy deployments

- Add host/port parameters to MCPServer.__init__() and pass to FastMCP
- Default host to "0.0.0.0" (cloud-friendly, disables DNS protection)
- "127.0.0.1" auto-enables DNS protection (handled by FastMCP)
- run() can override host/port, falls back to __init__ values
- Add comprehensive docstring to __init__() explaining parameters
- Update documentation

This fixes 421 Misdirected Request errors when running behind reverse
proxies (Cloudflare, nginx, etc.) where the Host header doesn't match
the auto-configured allowed_hosts for localhost.

* Fix DNS rebinding protection for cloud/proxy deployments

- Add host/port parameters to MCPServer.__init__() and pass to FastMCP
- Default host to "0.0.0.0" (cloud-friendly, disables DNS protection)
- "127.0.0.1" auto-enables DNS protection (handled by FastMCP)
- run() can override host/port and reconfigures DNS protection accordingly
- Rebuild app when host changes in run() to apply new security settings
- Add comprehensive docstring to __init__() explaining parameters
- Add unit tests for host/port configuration and run() overrides
- Update documentation

This fixes 421 Misdirected Request errors when running behind reverse
proxies (Cloudflare, nginx, etc.) where the Host header doesn't match
the auto-configured allowed_hosts for localhost.

* ruff lint

* Bump mcp minimum version to 1.23.0

Required for TransportSecuritySettings and DNS rebinding protection
auto-configuration feature that was added in v1.23.0.

* feat(server): add bearer token authentication for Python MCP server

Add HTTP-layer bearer token authentication that returns proper 401 responses.

- BearerAuthProvider: abstract base class with verify_token() method
- AccessToken: model with token, claims, and scopes fields
- AuthMiddleware: Starlette middleware returning HTTP 401 for invalid tokens
- get_access_token() / require_auth(): context helpers for tools

Usage:
```python
class MyAuth(BearerAuthProvider):
    async def verify_token(self, token: str) -> AccessToken | None:
        if token != "secret":
            return None
        return AccessToken(token=token, claims={"user": "alice"})

server = MCPServer(name="my-server", auth=MyAuth())
```

Closes #840

* autogenerate docs

* test(server): add unit and integration tests for bearer token auth

Unit tests:
- AccessToken model creation and serialization
- BearerAuthProvider abstract class and subclassing
- get_access_token/require_auth context helpers
- AuthMiddleware 401 responses, path exclusion, CORS

Integration tests:
- MCPClient connecting to bearer auth server with valid token
- Connection failure with invalid/missing token
- Tool access to user claims and scopes

* fix(server): address code review feedback for bearer auth

- Fix CORS security: allow_credentials=False with allow_origins=["*"]
- Remove dead try/except import for auth module
- Remove PII (email) from debug logs
- Add comment explaining broad exception handling in verify_token
- Add /openmcp.json to docs excluded paths list
- Remove set_access_token from public API (internal only)
- Create AuthenticationError instead of using ValueError
- Skip middleware tests on older httpx versions (TestClient compat)

* docs: update API documentation for auth module

* fix(server): address Copilot review feedback

- Fix bearer.mdx: require_auth raises AuthenticationError, not ValueError
- Fix API docs: claims and scopes are optional with defaults, not required
- Remove deprecated SSE transport from bearer_auth_server.py test server

* autogenerate docs

* fix(server): address renvins review feedback

- Improve bearer.mdx claims documentation with explanation and examples
- Remove unnecessary cast() for AuthMiddleware in server.py
- Refactor auth tests to use pytest fixtures for cleaner setup/teardown

* docs(auth): clarify that all MCP endpoints are automatically protected

- Add "What Gets Protected" section explaining automatic protection
- Clarify that get_access_token/require_auth are for accessing token data, not protection
- Update examples to show proper usage pattern
- Improve Note at bottom to be clearer

* fix(auth): prevent path prefix bypass in auth middleware

Security fix: Use exact path matching or segment-based prefix matching
instead of simple startswith() to prevent auth bypass attacks.

Before: /docs-secret would bypass auth because it starts with /docs
After: Only /docs and /docs/* bypass auth, /docs-secret requires auth

Added tests for path matching security edge cases.

* refactor(auth): update import paths for authentication components

- Changed import statements in multiple documentation files and source files to reflect the new structure, moving authentication-related imports to the `auth` submodule.
- Updated examples to ensure clarity and consistency in usage patterns for `BearerAuthProvider`, `AccessToken`, `get_access_token`, and `require_auth`.
2026-01-21 17:53:38 +01:00
Pietro Zullo 79d017bdc2 fix(python): DNS rebinding protection for cloud/proxy deployments (#825)
* Fix DNS rebinding protection for cloud/proxy deployments

- Add host/port parameters to MCPServer.__init__() and pass to FastMCP
- Default host to "0.0.0.0" (cloud-friendly, disables DNS protection)
- "127.0.0.1" auto-enables DNS protection (handled by FastMCP)
- run() can override host/port, falls back to __init__ values
- Add comprehensive docstring to __init__() explaining parameters
- Update documentation

This fixes 421 Misdirected Request errors when running behind reverse
proxies (Cloudflare, nginx, etc.) where the Host header doesn't match
the auto-configured allowed_hosts for localhost.

* Fix DNS rebinding protection for cloud/proxy deployments

- Add host/port parameters to MCPServer.__init__() and pass to FastMCP
- Default host to "0.0.0.0" (cloud-friendly, disables DNS protection)
- "127.0.0.1" auto-enables DNS protection (handled by FastMCP)
- run() can override host/port and reconfigures DNS protection accordingly
- Rebuild app when host changes in run() to apply new security settings
- Add comprehensive docstring to __init__() explaining parameters
- Add unit tests for host/port configuration and run() overrides
- Update documentation

This fixes 421 Misdirected Request errors when running behind reverse
proxies (Cloudflare, nginx, etc.) where the Host header doesn't match
the auto-configured allowed_hosts for localhost.

* ruff lint

* Bump mcp minimum version to 1.23.0

Required for TransportSecuritySettings and DNS rebinding protection
auto-configuration feature that was added in v1.23.0.
2026-01-19 15:32:58 +01:00
Pietro Zullo d8d319c940 fix(python/server): improve debug and pretty_print_jsonrpc behavior (#814)
* fix(python/server): improve debug and pretty_print_jsonrpc behavior

- Make pretty_print_jsonrpc work independently of debug_level
  (previously required DEBUG=2 environment variable)
- Rename run_debug to debug in server.run() for consistency
- Make run(debug=True) override server's debug_level if it was 0
- Remove aggressive signal handlers that broke thread compatibility
  (uvicorn handles SIGINT/SIGTERM gracefully)
- Update all documentation to use new debug parameter name

* refactor(python/server): remove unused lupo_tool function from server_example.py

* docs: update signals API reference after simplification

* refactor: remove unused signals.py module

uvicorn already handles SIGINT/SIGTERM gracefully, so custom signal
handlers are unnecessary. Removed the signals.py file and all references
to setup_signal_handlers().

* chore: remove analysis files
2026-01-14 18:43:25 +01:00
Vincenzo Reina 4997674559 feat(python): Intercept MCP handshake with on_initialize middleware (#769)
* Wrap server session from MCP

* Update server and middleware

* Update middleware example

* Fix formatting and linting

* Update docs

* Fix monkeypatch for tests

* Update docs and remove comment

* feat(python): add tests, docs, and docstrings for on_initialize middleware

- Add 13 unit tests covering dispatch, chain order, rejection, and context enrichment
- Rewrite middleware.mdx documentation with Mintlify components (Tabs, Tips, Cards)
- Add comprehensive docstring to MiddlewareServerSession documenting single-server-per-process limitation
- Add docs/CLAUDE.md with documentation improvement guidelines
- Regenerate API documentation

* docs: highlight typed context feature in middleware docs

* example: add ClientCapabilitiesGuard demonstrating typed context

* style: fix linting in middleware example

* docs(examples): add comprehensive docstrings to middleware_example.py

- Add module docstring explaining key concepts and middleware hooks
- Document each middleware class with typed context details
- Organize code with section headers (CONNECTION, REQUEST, TOOL-SPECIFIC)
- Add ClientCapabilitiesGuard example showing typed context usage

---------

Co-authored-by: pietrozullo <pietro.zullo@gmail.com>
2026-01-14 16:47:57 +01:00
Inchara J c990faf76b fix(python): add timeout mechanism to ConnectionManager.stop() (#726)
* fix(python): add timeout mechanism to ConnectionManager.stop()

Add timeout parameter (default: 30s) to stop() method to prevent infinite hangs
during application shutdown. Resolves issue #562.

Changes:
- Add timeout parameter to stop() with 30 second default
- Wrap task wait with asyncio.wait_for() to enforce timeout
- Wrap cleanup event wait with asyncio.wait_for() to enforce timeout
- Force cleanup on timeout by clearing connection and setting done event
- Add appropriate warning/error logging on timeout

Tests:
- Add 10 comprehensive unit tests for timeout scenarios
- All 158 unit tests pass
- Manual end-to-end testing verified

This ensures graceful shutdown even when cleanup hangs in production.

* updated with copilot suggested edits

* ruff checks passed

* Improve timeout handling in ConnectionManager.stop()

- Move 'import time' to module level
- Use CancelledError consistently (Python 3.11+ style)
- Treat timeout <= 0 or None as infinite wait (no timeout)
- Add elapsed time to timeout warning logs
- Add tests for negative/zero/None timeout behavior

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: update ConnectionManager.stop() API reference with timeout parameter

---------

Co-authored-by: pietrozullo <pietro.zullo@gmail.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-12 18:04:08 +01:00
Luigi Pederzani b45d9663ec feat(python): introduce roots support in MCPClient and Server (#751)
* fix(python): expose client capabilities to MCP servers

Add list_roots_callback support to Python connectors to properly
advertise the roots capability during MCP initialization handshake.

Previously, the Python library was not exposing any client capabilities
because the list_roots_callback was not being passed to ClientSession.
This fix ensures the roots capability is always advertised, bringing
the Python library in line with the TypeScript implementation.

Changes:
- Add roots and list_roots_callback params to BaseConnector
- Add get_roots() and set_roots() methods for managing roots
- Pass list_roots_callback to ClientSession in all connectors
- Export Root type from connectors module
- Update unit tests to expect list_roots_callback parameter

Closes MCP-1063

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat(python): add roots and list_roots_callback params to connectors

- Add roots and list_roots_callback parameters to StdioConnector,
  HttpConnector, and SandboxConnector constructors
- Add comprehensive unit tests for client capabilities exposure
- Tests verify roots capability, get_roots(), set_roots(), and
  that all callbacks are correctly passed to ClientSession

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* chore: fix import sorting and update API documentation

- Fix import sorting in test_client_capabilities.py (ruff)
- Regenerate API documentation for updated connector classes

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat(python): add list_roots() method to server Context

Allow MCP servers to request the list of roots from connected clients
via ctx.list_roots(). This follows the same pattern as ctx.sample()
and ctx.elicit() for server-to-client requests.

* feat(python): add roots params to MCPClient and config

- Add roots and list_roots_callback parameters to MCPClient.__init__,
  from_dict(), and from_config_file() methods
- Update create_connector_from_config() to pass roots params to all
  connector types (Stdio, HTTP, Sandbox)
- Allows clients to configure roots at the MCPClient level and have
  them propagate to all sessions

* test(python): add get_client_roots tool to primitive server

Add a tool that demonstrates the roots capability by requesting and
returning the list of roots from the connected client. Used for
integration testing of the roots feature.

* test(python): add integration tests for roots capability

Add comprehensive integration tests for the roots feature:
- test_roots_capability: Verify server can request/receive roots
- test_roots_empty_by_default: Verify empty roots when not provided
- test_roots_with_custom_callback: Verify custom callback precedence
- test_set_roots_updates_server_view: Verify dynamic root updates

* test(python): update unit tests for roots parameters

Update mock assertions in test_client.py to expect the new roots
and list_roots_callback parameters in create_connector_from_config
calls.

* ci(python): add roots to primitive tests and README badge

- Add roots to CI workflow primitive test matrix
- Add roots to PR comment report primitives list
- Add Roots badge to README Primitives row

* feat(docs): enhance MCP client and server documentation for roots feature

- Added `roots` and `list_roots_callback` parameters to MCP client initialization documentation.
- Updated `create_connector_from_config` documentation to include new parameters.
- Introduced `list_roots` method documentation in server context, detailing its usage and return values.
- Improved overall clarity and completeness of API reference for better developer guidance.

* feat(python): add get_client_roots tool to context example

- Introduced a new tool, `get_client_roots`, to the context example, demonstrating how to retrieve and display the list of roots exposed by the client.
- Updated documentation to include the new tool and its functionality, enhancing the example's coverage of context features.

* feat(docs): add roots documentation for client and server

- Introduced new documentation for the `roots` feature, detailing how clients can expose file system roots to MCP servers and how servers can access these roots.
- Added examples for configuring roots in the MCP client and using the `list_roots()` method in the server context.
- Enhanced overall clarity and usability of the documentation to support developers in implementing the roots functionality.

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: pietrozullo <pietro.zullo@gmail.com>
2026-01-12 11:16:09 +01:00
Vincenzo Reina aca5f9c040 feat(python): Adapt OAuth to 2.1 version from new MCP spec (#518)
* feat: Add PRM in the metadata discovery

* fix: fallback anyway to PRM

* feat: Implement complete discovery logic

* feat: Final implementation of CIMD

* feat: Implement PKCE

* feat: Add scope from WWW-Authenticate

* feat: Add all URLs possible styles

* feat: Update tests and example

* docs: Update docs

* fix: linting

* docs: update API documentation

* fix: correct typos in OAuth metadata and error messages

- Updated the comment in ProtectedResourceMetadata to use the correct abbreviation (PRM).
- Fixed a typo in the OAuthAuthenticationError message regarding code challenge support.
- Corrected the comment for legacy client paths to use "pre-registered" instead of "pre-reggistered".

* feat: restructure authentication documentation and add new methods

- Updated the authentication section in  to group authentication methods under a new Authentication category with an icon.
- Removed the old  file and replaced it with new documentation files for Bearer Token, Custom Auth, and OAuth 2.1.
- Introduced an overview page for authentication methods, detailing usage and configuration for each method.
- Enhanced security best practices and examples for each authentication type to improve clarity and usability.

* refactor: improve debug logging for OAuth metadata discovery

- Updated debug messages to provide clearer context by specifying the issuer or host being queried during OAuth and OpenID Connect metadata discovery.
- Enhanced error logging to remove redundant information, focusing on the failure reason without repeating the URL.

* fix: correct abbreviation in ProtectedResourceMetadata documentation

- Updated the abbreviation from PRC to PRM in the ProtectedResourceMetadata section to ensure accuracy in the documentation.

* fix(oauth): correct RFC 8414 well-known URL construction for path-based issuers

  The OAuth metadata discovery was incorrectly constructing .well-known URLs
  by appending to the issuer instead of inserting between host and path.

  RFC 8414 specifies that for an issuer like https://github.com/login/oauth,
  the .well-known URL should be:
    https://github.com/.well-known/oauth-authorization-server/login/oauth

  We were incorrectly building:
    https://github.com/login/oauth/.well-known/oauth-authorization-server

  This fix:
  - Implements correct RFC 8414 URL construction (insert between host/path)
  - Supports OpenID Connect style as fallback (append to issuer)
  - Removes GitHub-specific hardcode since discovery now works correctly
  - Adds documentation comments explaining the two standards

  Ref: https://www.rfc-editor.org/rfc/rfc8414.html#section-3

* chore: oauth examples

* docs: enhance OAuth endpoint discovery documentation

- Updated the OAuth documentation to clarify how `mcp-use` discovers OAuth endpoints using both OAuth 2.0 and OpenID Connect standards.
- Added a table detailing the URL construction methods for each standard.
- Included examples for better understanding and a note on fallback behavior when the issuer has no path.

* response to bs codeql

* fix: update API URL Updated the GitHub API URL in the configuration to the correct endpoint for OAuth operations.

---------

Co-authored-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>
Co-authored-by: pietrozullo <pietro.zullo@gmail.com>
2026-01-11 18:09:34 +01:00
Pietro Zullo 4889c49821 fix(python): update docs (#774) 2026-01-10 16:40:27 +01:00
Salvatore Gabriele Karra 39e85c8c25 feat(python): pass files to agent (prompt_files) (#428)
* feat(python): accept HumanMessage queries and move file input into messages

* use image as example

* restore remote.py

Signed-off-by: Salvatore Gabriele Karra <86735558+gabrielekarra@users.noreply.github.com>

* lint

* fix example in docs - create example

* update docs

* remove tests

---------

Signed-off-by: Salvatore Gabriele Karra <86735558+gabrielekarra@users.noreply.github.com>
Co-authored-by: pietrozullo <pietro.zullo@gmail.com>
2025-12-15 14:58:21 +01:00
Pietro Zullo ebef017114 python/server/middleware&tel (#650)
* chore: add example server pretty print JSON RPC for transparency

* updated telemetry module

* chore: agent side tel - langchain adapter - client tel

* server side tel:

* update API reference

* python transports and primitive reports are publishes only if not skipped

* remove wrongly generate files

* properly typed middleware

* remove examples

* feat(docs): add middleware and session management documentation

- Introduced new documentation for middleware, detailing hooks, minimal examples, and best practices for integrating middleware in MCP servers.
- Added a session management guide explaining session ID handling, usage patterns, and examples for managing per-client state in MCP servers.
- Updated  to include links to the new middleware and session management pages.

* generate docs

* remove few events

* adapter tel

* adapter tel

* api ref docs update

* google adapter fix

* fix version

* fix event naming

* server example is streamable and echo tool fix

* removed initialize middleware hook, initialize requests are not passed thorugh normal handlers

* api ref

* beta on middleware
2025-12-10 17:02:08 +01:00
Pietro Zullo be9942a4d4 feat/python/server (#559)
* feat: server first implementation

* docs: docs for server and images

* chore: locked langchain dependencies in pyproject.toml (#321)

* python/release/1.3.13

* catch uvicorn logs && log session id

* fix debug logic

* docs: logging update

* fix: icon of elicitation

* fix installation paths for local clones

* docs: minor restructuring

* docs: reorganization, killed non existing pages

* docs: beta tag on server

* chore: example servers

* feat: inspector autopopulated and client only

* feat: enhance MCP logging system with customizable formats and improved middleware

* feat: implement weather alert and forecast tools in FastMCP example server

* mcp path configurable

* fix inspector

* export as FastMCP too

* chore: update fastmcp migration example

* lock inspector version

* type runner

* unhide docs and remove dangers

* migration diff

* docs and context example

* export context

* logging improvement

* pretty JSON RPC

* autoConnect url param in inspecotr

* move logging

* type check

* Server Router

* show response logs

* fallback tool name to function name in router registration

* compatibility export

* Introduced ty and prek as type checker and precommit engine respectively - moved ruff config in pyproject toml

* add ty check

* ty runs only on staged files

* ty configuration fix

* move startup info in logging

* remove bug from action

* update claude rules

* fix resource serialization

* comments on inspector errors

* abstracted runner transports

* remove redunant call for network

* fix ip getter

* add inspector mcp path

* response limit logging

* disable ty check in action

* moved transport type to types

* support sse

* show transport type in logs

* change default transport

* refactored tests to use mcp server

* removed fastmcp

* file restructuring

* test table

* sampling, elicitation, tool disabling enabling

* deprecte sse server side

* simplified report

* fix action

* remove sse deprecated test

* move tests files to allow for server integration tests

* docs

* reorg integration test files

* api-reference-doxs

* fix broken links

* telemetry

* remove feature useage from scarf
2025-12-01 14:12:16 +01:00
Enrico Toniato 266a445934 Canary (#524)
* chore: enter canary prerelease mode

* Improve search tool response structure (#508)

* Refactor search_tools to return metadata and results

Co-authored-by: tonxipad <tonxipad@gmail.com>

* docs: update API documentation

* feat: enhance search_tools display and filtering capabilities

- Introduced a new function to format search_tools results as a tree structure, including metadata such as total tools and namespaces.
- Updated the display logic to handle both new and old formats of search_tools results for backward compatibility.
- Enhanced filtering in MCPClient and CodeExecutor to include server name in search criteria, improving tool discoverability.

* format

* docs: update code-mode documentation to reflect changes in search_tools response structure

- Modified examples to use the new response format from search_tools, which includes metadata and results.
- Enhanced clarity in code snippets by adding print statements for tool discovery results.
- Updated TypeScript and Python documentation to ensure consistency across both languages.

* refactor: clean up whitespace in display.py for improved readability

- Removed unnecessary blank lines throughout the _format_search_tools_as_tree function to enhance code clarity and maintainability.
- Ensured consistent formatting in the display logic for better visual structure.

* refactor: streamline line wrapping in display.py for improved readability

- Consolidated parameters in the text wrapping function to enhance code clarity and maintainability.

* feat: enhance search_tools metadata for improved context

- Updated search_tools to return additional metadata (total_tools, namespaces, result_count) alongside results, enhancing the context for model decision-making.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: tonxipad <tonxipad@gmail.com>

* chore(typescript): version packages (canary)

* feat: Integrate official UI components in templates and enhance widget development experience (#517)

* feat: Add ecommerce widgets and OpenAI Apps SDK UI components

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Update MCP app templates and resources

- Added new fruit images to the public directory for enhanced visual content.
- Removed outdated weather and ecommerce carousel components to streamline the codebase.
- Updated the product search result component to utilize new UI components and improved error handling.
- Modified package dependencies to include react-router and updated @openai/apps-sdk-ui version.
- Enhanced the .gitignore file to include .mcp-use for better project management.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Introduce new lockfile and update dependencies

- Added a new bun.lock file to manage package dependencies for the TypeScript project.
- Updated pnpm-lock.yaml to include new dependencies such as @openai/apps-sdk-ui and react-router.
- Enhanced the CLI tool to support aborting fetch requests and improved error handling in widget building.
- Replaced outdated image assets with PNG versions for better compatibility and removed unused JPG files.
- Introduced new ErrorBoundary and Image components to improve error handling and image loading in the MCP app.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Enhance Vite server configuration and update dependencies

- Added a new plugin to Vite for watching the resources directory, ensuring hot module replacement (HMR) works seamlessly when widget source files change.
- Updated pnpm-lock.yaml to include new dependencies such as @openai/apps-sdk-ui, react-router, and various development tools like @tailwindcss/vite and typescript.
- Improved the Vite server configuration to explicitly watch files outside the root directory, enhancing the development experience.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Implement carousel component for product search results

- Added a new CarouselItem component to enhance the visual presentation of fruit items in the product search results.
- Introduced dynamic pointer tracking for interactive hover effects on carousel items, improving user engagement.
- Updated styles for carousel items and their backgrounds to create a visually appealing blur effect.
- Refactored the ProductSearchResult component to utilize the new carousel structure and improve layout responsiveness.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Update ProductSearchResult and OpenAIComponentRenderer for theme support

- Added WidgetDebugger to the ProductSearchResult component for enhanced debugging capabilities.
- Updated the product search result text to reflect a new template and improved context for users.
- Enhanced OpenAIComponentRenderer to handle theme changes, ensuring the correct theme is applied when the iframe loads.
- Modified shared-utils to include theme information in WidgetData, allowing for better theme management across components.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Refactor ProductSearchResult component and enhance WidgetFullscreenWrapper

- Replaced ThemeProvider and BrowserRouter with McpUseProvider in the ProductSearchResult component for improved context management.
- Removed unused getBasename function to streamline routing logic.
- Updated WidgetFullscreenWrapper to support viewControls prop, allowing conditional rendering of fullscreen and picture-in-picture buttons.
- Enhanced overall structure and readability of the ProductSearchResult component.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Update dependencies and enhance component functionality

- Added `react-router-dom` as a dependency to support routing features.
- Updated `detect-libc` to version 2.1.2 for improved compatibility.
- Refactored various components for better readability and structure, including the `ProductSearchResult` and `OpenAIComponentRenderer`.
- Introduced new auto-sizing functionality in `McpUseProvider` to notify OpenAI about container height changes.
- Removed deprecated `WidgetDebugger` and `WidgetFullscreenWrapper` components to streamline the codebase.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Enhance OpenAIComponentRenderer and ToolResultDisplay for performance and readability

- Memoized component to prevent unnecessary re-renders in OpenAIComponentRenderer.
- Introduced new state management for iframe height notifications and improved height handling logic.
- Refactored ToolResultDisplay to utilize memoization for args and result, optimizing rendering performance.
- Cleaned up unused state variables and streamlined event handling for better maintainability.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Improve logging and code readability in various components

- Enhanced logging statements in OpenAIComponentRenderer, McpUseProvider, and WidgetControls for better debugging and clarity.
- Refactored memoization in ToolResultDisplay to improve performance and prevent unnecessary re-renders.
- Cleaned up code formatting for improved readability across multiple components.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Update ProductSearchResult and shared routes for improved development experience

- Modified the ProductSearchResult component to change the FAQ question and enhance the autosize feature description.
- Simplified asset loading in shared routes to directly fetch from the dev server, improving development efficiency.
- Enhanced security headers in shared-utils to include dev server origins for better handling of HMR scripts and resource loading.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Integrate @tanstack/react-query and enhance fruits API in apps-sdk template

- Added @tanstack/react-query as a dependency to improve data fetching capabilities.
- Implemented a new API endpoint in the apps-sdk template to serve a list of fruits with their respective colors.
- Removed the outdated ProductSearchResult component to streamline the codebase and focus on the new API integration.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Clean up code formatting and improve readability in product search result components

- Removed unnecessary blank lines in various TypeScript files to enhance code clarity.
- Simplified function parameters in CarouselItem component for better readability.
- Streamlined the Accordion and AccordionItem components by removing excess whitespace.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* change set

* chore: Remove bun.lock file to streamline dependency management

- Deleted the bun.lock file to eliminate potential conflicts and simplify the dependency resolution process in the project.

* feat: Update documentation and components for improved clarity and organization

- Added new pages for MCP UI resources and widget components in the documentation.
- Enhanced the migration guide to specify applicability for version 1.5.0 and later.
- Updated the ErrorBoundary component icon for better representation.
- Removed outdated template comparison section to streamline the templates documentation.

* fix: Correct indentation in documentation JSON for better readability

- Adjusted the indentation of the "apps-sdk-resources" entry in the documentation JSON to maintain consistent formatting.
- Removed unnecessary blank lines to enhance overall clarity in the documentation structure.

* chore: Update dependencies and clean up code for improved performance

- Updated react-router-dom to version 7.9.5 for enhanced functionality.
- Removed commented-out code in ProductSearchResult component to improve clarity.
- Cleaned up logging statements in OpenAIComponentRenderer for better debugging.
- Refactored height notification logic in McpUseProvider to optimize performance.
- Adjusted useWidget to avoid dependency issues with URL parameters.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* chore: Update dependencies and clean up code for improved performance

- Updated react-router-dom to version 7.9.5 for enhanced functionality.
- Removed commented-out code in ProductSearchResult component to improve clarity.
- Cleaned up logging statements in OpenAIComponentRenderer for better debugging.
- Refactored height notification logic in McpUseProvider to optimize performance.
- Adjusted useWidget to avoid dependency issues with URL parameters.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Clean up code formatting and improve readability in OpenAIComponentRenderer and useWidget

- Adjusted formatting of variable declarations for better consistency and readability.
- Simplified the handleError function in OpenAIComponentRenderer for clarity.
- Ensured consistent indentation in useWidget for improved code structure.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: tonxipad <tonxipad@gmail.com>

* chore(typescript): version packages (canary)

* feat: Add JSON-RPC message logging to Inspector tabs (MCP-536) (#519)

* feat: Add ecommerce widgets and OpenAI Apps SDK UI components

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Update MCP app templates and resources

- Added new fruit images to the public directory for enhanced visual content.
- Removed outdated weather and ecommerce carousel components to streamline the codebase.
- Updated the product search result component to utilize new UI components and improved error handling.
- Modified package dependencies to include react-router and updated @openai/apps-sdk-ui version.
- Enhanced the .gitignore file to include .mcp-use for better project management.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Introduce new lockfile and update dependencies

- Added a new bun.lock file to manage package dependencies for the TypeScript project.
- Updated pnpm-lock.yaml to include new dependencies such as @openai/apps-sdk-ui and react-router.
- Enhanced the CLI tool to support aborting fetch requests and improved error handling in widget building.
- Replaced outdated image assets with PNG versions for better compatibility and removed unused JPG files.
- Introduced new ErrorBoundary and Image components to improve error handling and image loading in the MCP app.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Enhance Vite server configuration and update dependencies

- Added a new plugin to Vite for watching the resources directory, ensuring hot module replacement (HMR) works seamlessly when widget source files change.
- Updated pnpm-lock.yaml to include new dependencies such as @openai/apps-sdk-ui, react-router, and various development tools like @tailwindcss/vite and typescript.
- Improved the Vite server configuration to explicitly watch files outside the root directory, enhancing the development experience.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Implement carousel component for product search results

- Added a new CarouselItem component to enhance the visual presentation of fruit items in the product search results.
- Introduced dynamic pointer tracking for interactive hover effects on carousel items, improving user engagement.
- Updated styles for carousel items and their backgrounds to create a visually appealing blur effect.
- Refactored the ProductSearchResult component to utilize the new carousel structure and improve layout responsiveness.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Update ProductSearchResult and OpenAIComponentRenderer for theme support

- Added WidgetDebugger to the ProductSearchResult component for enhanced debugging capabilities.
- Updated the product search result text to reflect a new template and improved context for users.
- Enhanced OpenAIComponentRenderer to handle theme changes, ensuring the correct theme is applied when the iframe loads.
- Modified shared-utils to include theme information in WidgetData, allowing for better theme management across components.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Refactor ProductSearchResult component and enhance WidgetFullscreenWrapper

- Replaced ThemeProvider and BrowserRouter with McpUseProvider in the ProductSearchResult component for improved context management.
- Removed unused getBasename function to streamline routing logic.
- Updated WidgetFullscreenWrapper to support viewControls prop, allowing conditional rendering of fullscreen and picture-in-picture buttons.
- Enhanced overall structure and readability of the ProductSearchResult component.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Update dependencies and enhance component functionality

- Added `react-router-dom` as a dependency to support routing features.
- Updated `detect-libc` to version 2.1.2 for improved compatibility.
- Refactored various components for better readability and structure, including the `ProductSearchResult` and `OpenAIComponentRenderer`.
- Introduced new auto-sizing functionality in `McpUseProvider` to notify OpenAI about container height changes.
- Removed deprecated `WidgetDebugger` and `WidgetFullscreenWrapper` components to streamline the codebase.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Enhance OpenAIComponentRenderer and ToolResultDisplay for performance and readability

- Memoized component to prevent unnecessary re-renders in OpenAIComponentRenderer.
- Introduced new state management for iframe height notifications and improved height handling logic.
- Refactored ToolResultDisplay to utilize memoization for args and result, optimizing rendering performance.
- Cleaned up unused state variables and streamlined event handling for better maintainability.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Improve logging and code readability in various components

- Enhanced logging statements in OpenAIComponentRenderer, McpUseProvider, and WidgetControls for better debugging and clarity.
- Refactored memoization in ToolResultDisplay to improve performance and prevent unnecessary re-renders.
- Cleaned up code formatting for improved readability across multiple components.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Update ProductSearchResult and shared routes for improved development experience

- Modified the ProductSearchResult component to change the FAQ question and enhance the autosize feature description.
- Simplified asset loading in shared routes to directly fetch from the dev server, improving development efficiency.
- Enhanced security headers in shared-utils to include dev server origins for better handling of HMR scripts and resource loading.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Integrate @tanstack/react-query and enhance fruits API in apps-sdk template

- Added @tanstack/react-query as a dependency to improve data fetching capabilities.
- Implemented a new API endpoint in the apps-sdk template to serve a list of fruits with their respective colors.
- Removed the outdated ProductSearchResult component to streamline the codebase and focus on the new API integration.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: Clean up code formatting and improve readability in product search result components

- Removed unnecessary blank lines in various TypeScript files to enhance code clarity.
- Simplified function parameters in CarouselItem component for better readability.
- Streamlined the Accordion and AccordionItem components by removing excess whitespace.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Integrate JsonRpcLoggerView into PromptsTab, ResourcesTab, and ToolsTab for enhanced logging

- Added JsonRpcLoggerView component to PromptsTab, ResourcesTab, and ToolsTab to facilitate RPC logging.
- Adjusted ResizablePanel default sizes for better layout consistency across tabs.
- Implemented keyboard shortcut handling in ToolExecutionPanel for executing tools with Cmd/Ctrl + Enter.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* format

* chore: changeset

* docs: add rpc docs

* chore: Remove bun.lock file and clean up pnpm-lock.yaml

- Deleted the bun.lock file to streamline dependency management and eliminate potential conflicts.
- Removed outdated dependencies from pnpm-lock.yaml, including entries for test_app and its associated packages, to simplify the lockfile and improve clarity.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: tonxipad <tonxipad@gmail.com>

* chore(typescript): version packages (canary)

* docs: update API documentation

* docs: api update docs

* trigger release

* chore: Clean up pnpm-lock.yaml and remove bun.lock file for streamlined dependency management

* chore(typescript): version packages (canary)

* chore(inspector): update package.json with homepage, repository, and bugs information

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: tonxipad <tonxipad@gmail.com>
2025-11-24 20:59:22 +01:00
Pietro Zullo fe27691947 feature: mcp 116 when the mcp use tries to call a tool with a wrong action (#520)
* fix typing annotation

* tool retry logic in agent

* removed retryable flag

* docs

* update docs
2025-11-24 17:56:23 +01:00
Pietro Zullo 8d4cb4719b Feature/mcp 799 python client integration of code mode (#498)
* initial commit

* update to code mode

* Squash all commits: Add CLI deploy functionality, server tool inspector, and various improvements (#467)

* chore(release): exit prerelease mode and version packages (#473)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Docs/tunnel docs (#474)

* chore: add tunnelling docs

* chore: add tunnelling docs

* docs: enhance tunneling documentation with link to @mcp-use/tunnel package

* docs: update tunneling documentation with improved code examples and formatting

* feat: Add verify parameter to MCPClient and connectors (#478)

* feat: add verify parameter to MCPClient and connectors

- Introduced a new optional `verify` parameter in `MCPClient`, `HttpConnector`, and configuration functions to control SSL certificate verification.
- Updated relevant methods to utilize the `verify` parameter, ensuring consistent handling of SSL verification across the client and connectors.
- Enhanced the SSE and Streamable HTTP connection managers to accept a custom HTTPX client factory for improved flexibility in connection handling.

* fix: linting and docs

* fix: http connector test

* Update docs/python/api-reference/mcp_use_client_config.mdx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>

* fix: docs

---------

Signed-off-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Co-authored-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Canary release (#476)

* Implement iframe log console for inspector (#475)

* Docs/tunnel docs (#474)

* chore: add tunnelling docs

* chore: add tunnelling docs

* docs: enhance tunneling documentation with link to @mcp-use/tunnel package

* docs: update tunneling documentation with improved code examples and formatting

* feat: Add iframe console logging and UI

Implement a system to capture and display console logs from iframes. This includes injecting a script into iframes to intercept console messages and a UI component to display them in the parent window.

Co-authored-by: tonxipad <tonxipad@gmail.com>

* feat: Conditionally inject console interceptor for same-origin iframes

Co-authored-by: tonxipad <tonxipad@gmail.com>

* refactor: update IframeConsole component for improved UI and styling

- Removed unused XIcon import.
- Adjusted LogLevelBadge styling for better visual consistency.
- Renamed "Iframe Console" to "Widget Console Logs" for clarity.
- Modified button styling for better alignment and spacing.

* feat: add HTMLIFrameElement and MessageEvent to ESLint config

- Updated ESLint configuration to include HTMLIFrameElement and MessageEvent as readonly types, enhancing type safety for iframe-related code.

* feat: implement auto-scroll functionality in IframeConsole component

- Added useRef and useEffect hooks to enable auto-scrolling to the bottom of the console when logs change or the console opens.
- Updated the console's container div to use the scrollContainerRef for managing scroll position.

* chore: lint & format

* chore: changeset

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: tonxipad <tonxipad@gmail.com>

* chore: enter canary prerelease mode

* chore(typescript): version packages (canary)

* Feat/consistent sub for tunnel (#480)

* Docs/tunnel docs (#474)

* chore: add tunnelling docs

* chore: add tunnelling docs

* docs: enhance tunneling documentation with link to @mcp-use/tunnel package

* docs: update tunneling documentation with improved code examples and formatting

* Refactor CLI tunnel functionality to support optional subdomain and save to manifest

- Updated `startTunnel` function to accept an optional subdomain parameter.
- Enhanced subdomain extraction from the tunnel URL and updated the manifest file with the subdomain.
- Cleaned up commented-out code related to tunnel handling in the CLI.
- Improved logging for tunnel establishment and subdomain saving.

* chore: changeset

* format

* chore(typescript): version packages (canary)

* Refactor tunnel argument handling in CLI to streamline subdomain flag usage and improve logging

* remove console log

* [typescript][server] Fix tools with async calls (#481)

* fix tools with async calls

* FORMAT

* chore(typescript): version packages (canary)

* fix/minor fix post canary (#482)

* fix server async call

* wrap all handle request calls in wait function

* changeset

* chore(typescript): version packages (canary)

* window.openai emulation and ChatGPT Integration debugging (#469)

* feat: Add WidgetFullscreenWrapper component

Co-authored-by: tonxipad <tonxipad@gmail.com>

* Docs/tunnel docs (#474)

* chore: add tunnelling docs

* chore: add tunnelling docs

* docs: enhance tunneling documentation with link to @mcp-use/tunnel package

* docs: update tunneling documentation with improved code examples and formatting

* feat: Enhance OpenAIComponentRenderer with tool call handling and display mode management

- Implemented tool call handling with error management and response formatting for OpenAI API compatibility.
- Added support for follow-up messages and localStorage fallback for pending follow-ups.
- Introduced display mode management (inline, pip, fullscreen) with dynamic iframe resizing and a close button for fullscreen mode.
- Updated TypeScript configuration to include .tsx files for better component support.

* fix: maintain subdomain across builds

* remove console

* refactor: replace direct serverBaseUrl usage with getServerBaseUrl method for improved consistency

* refactor: enhance WidgetFullscreenWrapper with hoverable icon buttons for fullscreen and pip modes

* feat: implement dev widget proxy and asset handling for improved development experience

* refactor: update OpenAIComponentRenderer to handle global updates for display mode and theme, enhancing iframe communication

* feat: add WidgetDebugger export to enhance debugging capabilities in the React package

* chore: fix type

* format

* chore: changeset

* remove irrelevant content

* chore: add changeset for MCP-747-fix-apps-sdk-fullscreen-close-button-9e35

* refactor: improve tunnel shutdown handling and output suppression for better user experience

* format

* remove console log

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: tonxipad <tonxipad@gmail.com>

* chore(typescript): version packages (canary)

* Fix/settings button servers dropdown (#485)

* feat: Add server connection management in Layout and ServerDropdown components

- Introduced ServerConnectionModal for editing connection settings in the Layout component.
- Updated ServerDropdown to handle connection options and display selected server status.
- Enhanced MCPConnection interface to include transportType and proxyConfig for better connection management.
- Implemented connection update logic with success notifications.

* add gear also to home

* chore: changeset and format

* chore(typescript): version packages (canary)

* feat: Enhance ConnectionSettingsForm layout and add utility styles (#486)

- Updated ConnectionSettingsForm component to improve layout responsiveness with new utility classes.
- Added a new CSS utility for flex column and row layout.
- Cleaned up imports for better organization.

* chore(typescript): version packages (canary)

* Update libraries/typescript/packages/cli/CHANGELOG.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>

* Update libraries/typescript/packages/cli/src/index.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>

* Update libraries/typescript/packages/cli/src/index.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>

* Update libraries/typescript/.changeset/clear-wombats-juggle.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>

* Feature/mcp 743 tool argument autoformats and moves the cursor (#487)

* refactor(ToolsTab, ToolInputForm): enhance JSON handling for object/array types

- Updated ToolsTab to initialize object and array types as empty JSON strings to preserve formatting.
- Improved argument parsing in ToolsTab to handle JSON strings for object/array types before tool execution.
- Modified ToolInputForm to display objects/arrays as formatted JSON strings, ensuring user input is preserved.

* chore: changeset

* chore(typescript): version packages (canary)

* Fix/remove console button from chat (#488)

* remove mcp url console log

* feat(OpenAIComponentRenderer): add showConsole prop to control console visibility

* Feature/mcp 837 load list of models for providers (#489)

* remove mcp url console log

* Enhance ConfigurationDialog with model fetching and caching

- Added functionality to fetch models from OpenAI, Anthropic, and Google APIs based on the selected provider.
- Implemented caching for fetched models using localStorage to improve performance and reduce API calls.
- Updated the UI to display loading states and errors when fetching models.
- Refactored API key handling to support provider-specific storage in localStorage.
- Improved user experience by debouncing API calls and dynamically updating the model selection based on the provider.

* fix: reorder imports in useConfig.ts for better clarity

* chore(typescript): version packages (canary)

---------

Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: tonxipad <tonxipad@gmail.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* chore(release): exit prerelease mode and version packages (#490)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Update Dockerfile

Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>

* fix: x icon light mode

* docs: Improve typescript server docs (#491)

* fix: update installation commands and enhance quickstart documentation

- Changed `pnpm run dev` to `pnpm dev` in installation instructions across multiple files for consistency.
- Improved the quickstart guide by clarifying the MCP server framework's capabilities and updating the project structure details.
- Added a base URL configuration for the MCP server in the configuration documentation to ensure proper functionality of UI widgets.

* minor

* add fallback

---------

Signed-off-by: Luigi Pederzani <luigipederzani@gmail.com>

* Docs/inspector (#492)

* refactor: reorganize documentation structure for Inspector and Dev Tools

- Updated the docs.json file to consolidate Inspector and Tunneling pages under a new "Dev Tools" group.
- Removed redundant entries for Inspector and Tunneling from the documentation structure.
- Added a sidebar title for the Inspector page to enhance navigation.

* docs: enhance Inspector documentation and add new CLI usage guides

- Updated `docs.json` to include new pages for CLI usage, connection settings, keyboard shortcuts, command palette, integration, debugging ChatGPT apps, and development under the Inspector section.
- Expanded the Inspector documentation to cover new features, including CLI usage and detailed guides for keyboard shortcuts and integration.
- Improved the `self-hosting` documentation to reference the new CLI usage guide.
- Enhanced the `apps-sdk-resources` documentation with additional details on widget state and testing procedures using the Inspector.

* fix broken links

* chore: remove unuseful docs

* Feat/python/pretty display (#497)

* pretty display implementation

* docs update

* initial commit

* docs

* fix tests

* example streams and uses anthropic

* docs

* docs image

* fix type checking mock

* add rich to requirements

* enable pretty pritns in all examples

---------

Signed-off-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Signed-off-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>
Signed-off-by: Luigi Pederzani <luigipederzani@gmail.com>
Co-authored-by: Enrico Toniato <2827496+tonxxd@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Vincenzo Reina <vincenzoreinaa05@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: tonxipad <tonxipad@gmail.com>
Co-authored-by: Luigi Pederzani <luigipederzani@gmail.com>
2025-11-20 16:26:23 +01:00
Pietro Zullo bcbca53709 Feat/python/pretty display (#497)
* pretty display implementation

* docs update
2025-11-20 11:04:01 +01:00
Vincenzo Reina c35f37435a feat: Add verify parameter to MCPClient and connectors (#478)
* feat: add verify parameter to MCPClient and connectors

- Introduced a new optional `verify` parameter in `MCPClient`, `HttpConnector`, and configuration functions to control SSL certificate verification.
- Updated relevant methods to utilize the `verify` parameter, ensuring consistent handling of SSL verification across the client and connectors.
- Enhanced the SSE and Streamable HTTP connection managers to accept a custom HTTPX client factory for improved flexibility in connection handling.

* fix: linting and docs

* fix: http connector test

* Update docs/python/api-reference/mcp_use_client_config.mdx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>

* fix: docs

---------

Signed-off-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Co-authored-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-11-18 20:06:38 +01:00
Vincenzo Reina 326842511a fix: add list handling in fix_schema (#417) 2025-11-02 17:32:04 +01:00
Luigi Pederzani f08e870e09 feat: Upgrade to Langchain 1.0.0 (#393)
* chore: update imports

* refactor(mcpagent): update agent creation logic and imports

- Replaced `create_tool_calling_agent` with `create_agent` for improved agent instantiation.
- Simplified the `_create_agent` method by removing the `AgentExecutor` and directly returning the created agent.
- Adjusted type annotations for `_agent_executor` to initialize as `None` instead of using a union type.

* feat(mcpagent): migrate to LangChain 1.0.0 and simplify agent methods

- Updated MCPAgent to utilize LangChain 1.0.0's `create_agent()` for improved agent instantiation.
- Introduced new methods `astream_simplified()` and `run_v2()` that leverage the built-in `astream()` for internal agent loop handling.
- Retained legacy methods `stream()` and `run()` for backward compatibility with manual execution.
- Enhanced documentation to reflect changes and provide clearer usage examples.

* feat(mcpagent): implement dynamic tool updates during agent execution

- Enhanced the MCPAgent to support dynamic tool updates when using server_manager mode.
- Implemented logic to check for tool changes before and during execution, allowing for immediate updates and safe restarts.
- Introduced a maximum restart limit to prevent infinite loops during tool updates.
- Updated documentation to reflect the new behavior and usage of dynamic tool management.

* refactor(mcpagent): clean up imports and streamline logging

- Removed unused imports and organized existing ones for better clarity in `mcpagent.py`.
- Simplified logging statements for consistency and improved readability.
- Enhanced the overall structure of the code by eliminating unnecessary whitespace.
- Updated unit tests to reflect changes in imports and ensure compatibility with the refactored code.

* feat(mcpagent): enhance agent execution with step tracking and middleware

- Introduced `ModelCallLimitMiddleware` to enforce a maximum number of model calls during agent execution.
- Updated the `_consume_and_return` method to return a tuple of the final result and the number of steps taken.
- Enhanced telemetry tracking to include steps taken and execution time for better performance insights.
- Simplified agent creation logic by integrating middleware directly into the `create_agent` function.
- Improved logging for agent execution details, including steps and tool usage.

* fix(mcpagent): add null check for node output messages extraction

- Updated the MCPAgent to include a null check for `node_output` before attempting to access the "messages" key, preventing potential errors during message extraction.

* minor

* feat(mcpagent): filter out ToolMessage from history

- Updated the MCPAgent to exclude ToolMessage instances from being added to the message history, ensuring that only relevant messages are recorded.
- This change helps maintain a cleaner history by avoiding intermediate tool execution details.

* fix(mcpagent): set max_steps assignment

* ruff

* docs

* e2e tests for agent

* key in tests

* fix manager test and split ci tests

* telemetry off for tests

* fix server manager test

* feat(mcpagent): delegate query streaming to remote agent in remote mode

- recreated functionality to the MCPAgent to yield results from a remote agent when operating in remote mode, enhancing the agent's capability to handle queries efficiently.

* fix: agent unit tests

* Print inputs

* rollback, wrong repo

* fix streaming output

* stricter streaming test

* pass observability callbacks

* fix tests mock

---------

Co-authored-by: pietrozullo <pietro.zullo@gmail.com>
2025-10-27 14:26:01 +01:00
pietrozullo 6aecf7c5a2 chore:docs: remove stale docs 2025-10-22 17:45:04 +02:00
Vincenzo Reina 7d3a3040a9 feat: Adapter integrations (#325)
* feat: openai, anthropic, google adapters

* feat: adapters examples and documentation

* feat: update imports

* fix: release drafter action

* docs: header change

* chore: locked langchain dependencies in pyproject.toml (#321)

* python/release/1.3.13

* feat: Update langchain adapter

* feat: Update MCPAgent

* feat: General fixes

* feat: Correct naming

* feat: Fix formatting

* feat: Add genai dependency

* feat: Fix documentation

* feat: Fix imports

* logo

* icons

* Update docs/python/integration/google.mdx

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>

* feat: Critical bug fixes

* chore: local logos

* chore: moved icons

* fix: Lambda closure issue

* docs: Add steps

* docs: Fix documentation

* fix docs action

* fix attempt 2

* docs: update

* chore: google optional dependency

* chore: minor docs changes

* fix generate docs script

* fix: lint

* import guard in __init__ file

* ci: install google-genai in docs workflow

* chore: print diffs

* chore: fix action checkout ref

---------

Signed-off-by: Vincenzo Reina <vincenzoreinaa05@gmail.com>
Signed-off-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Co-authored-by: pietrozullo <pietro.zullo@gmail.com>
Co-authored-by: Pietro Zullo <62951181+pietrozullo@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-10-22 07:37:29 +02:00
Pietro Zullo 1cae240ca2 feat/docs (#340)
* Check out feat/server/python branch with latest docs

* feat: structure v1

* feat: product navigation

* stubs

* emtpy pages

* feat: home page

* autogenerate docs updated

* side bar on home page with redirects

* theme adaptation of welcome cards

* cleanup logos

* cleanup

* WIP disclosure in Python Server

* feat: add initial documentation and images for MCP server framework

* feat: add TypeScript documentation for mcp agent and mcp client + remove typescript reference from python files

* fix: update sandbox documentation for Python and TypeScript clients

- Adjusted Python sandbox documentation for clarity in API key usage.
- Added a warning in TypeScript documentation indicating that sandbox execution is not yet supported, with a reference to the Python version for users needing this functionality.

* feat: enhance TypeScript SDK documentation with new icons and structured navigation

* fix

* feat: update getting started guide

* refactor: remove sandboxed execution section from TypeScript connection types documentation

- Deleted the Sandboxed Execution section, including installation instructions and characteristics.
- Updated the Choosing the Right Connection Type section to reflect the removal of sandboxed execution details.

* feat: add observability documentation for MCP agents

* feat: add comprehensive documentation for MCP server framework

* feat: expand TypeScript server documentation with new templates, prompts, and UI widgets sections

* fix

* color hover

* remove inspector

* feat: remove claude code review

* fix: broken links

---------

Co-authored-by: Luigi Pederzani <luigipederzani@gmail.com>
2025-10-20 14:35:55 +02:00
Pietro Zullo be89397fe8 fix: python: docs: astream removed (#320) 2025-10-17 20:16:07 +02:00
Pietro Zullo 18f51eddb8 Feat: python/restructure (#318)
* move: session

* move: client

* move:config

* move: exceptions

* move: connectors -> client.connectors

* move: task_managers -> client.task_managers

* move: observability -> agents.observability

* move: middleware -> client.middleware

* move: managers -> agents.managers

* move: auth -> client.auth

* move: adapters -> agents.adapters

* test: bc test

* test: bc test

* chore: remove relative imports

* fix tests

* chore: update docs

* chore: deprecation warnings

* chore: fix dangerous non absolute import

* fix: remove legacy imports

* telemetry
2025-10-17 20:09:19 +02:00
Luigi Pederzani 3ff31be303 move docs 2025-10-15 19:23:46 +02:00