Skip to main content

3tears-mcp

Shared MCP (Model Context Protocol) framework. Per-product MCP servers compose this framework instead of reimplementing stdio transport, JWT auth, error mapping, and per-tool RBAC.

What's in here

Module Responsibility
server McpServer -- wraps the official mcp.server.Server. Owns tool registration, RBAC gating before handler dispatch, structured error mapping per the MCP spec.
tool McpTool dataclass (name, description, input_schema, required_permission, handler) and register_tool decorator.
http_client PlatformHttpClient -- typed httpx client with JWT login + refresh-on-401. Used by both MCP server tool handlers (calling /api/v1/...) and CLI scripts. One HTTP-client implementation, two transports.
auth Identity dataclass + IdentityProvider Protocol + EnvVarIdentityProvider (stdio impl). Authorizer Protocol + LocalGrantAuthorizer (default impl backed by McpToolGrantCollection).
rbac McpToolGrantCollection -- BaseCollection over mcp_tool_grants. Exposes the in-memory grant cache that LocalGrantAuthorizer consults.
migrations/ v01_create_mcp_tool_grants -- platform-scope DDL. Consumers register via MigrationRunner.register(epoch_pkg) (same shape as threetears.epoch).

RBAC model

Per-tool, default-deny. Each McpTool declares a required_permission string (e.g. "conversations.read", "audit.read"). On every dispatch:

  1. The framework calls Authorizer.allows(identity, required_permission).
  2. LocalGrantAuthorizer checks whether the caller's identity matches an active grant in McpToolGrantCollection for the requested permission.
  3. If denied, the framework returns a structured MCP error to the client (not a Python exception in the response body).

The configured admin identity (env-var creds in the stdio impl) is auto-granted in memory at server startup. The grant is logged but NOT written to mcp_tool_grants. This keeps the table truthful (only operator-added grants live there).

Grant changes propagate cross-pod via the mcp.rbac epoch broadcast. LocalGrantAuthorizer subscribes to Subjects.mcp_rbac_epoch() via an EpochListener; on bump it reloads the grant cache from L3. Cold-start primes from EpochClient.current(...). Missed broadcasts recover via the standard pull-on-stale path.

Identity in v1

EnvVarIdentityProvider returns one fixed Identity for the lifetime of the server, derived from env-var credentials. v2 (HTTP transport + per-call bearer-token identity) plugs in by adding a BearerTokenIdentityProvider; the rest of the framework is unchanged. The Authorizer.allows(identity, permission) interface is unchanged between v1 and v2.

Stdio transport discipline

Every byte on stdout/stderr from a stdio MCP server confuses the client. The framework configures logging to a file or to NATS; no module under threetears.mcp should write to sys.stdout / sys.stderr. An AST enforcement test guards this.

Postgres backing

CREATE TABLE IF NOT EXISTS mcp_tool_grants (
    grant_id UUID PRIMARY KEY,
    principal_type TEXT NOT NULL,   -- 'user' | 'group' | 'role'
    principal_id UUID NOT NULL,
    tool_name TEXT NOT NULL,
    permission TEXT NOT NULL,
    date_created TIMESTAMPTZ NOT NULL DEFAULT now()
);

Mutation paths (admin POST /admin/mcp/grants, DELETE /admin/mcp/grants/{id}) bump Subjects.mcp_rbac_epoch() after the row commit; sibling pods reload via the epoch listener.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

3tears_mcp-0.31.0.tar.gz (56.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

3tears_mcp-0.31.0-py3-none-any.whl (35.8 kB view details)

Uploaded Python 3

File details

Details for the file 3tears_mcp-0.31.0.tar.gz.

File metadata

  • Download URL: 3tears_mcp-0.31.0.tar.gz
  • Upload date:
  • Size: 56.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for 3tears_mcp-0.31.0.tar.gz
Algorithm Hash digest
SHA256 a30b8967e8cd741bac0e12cc15de807f7c29ab2ef8ef7a9723c7f46f9947d6ae
MD5 a0d0366abda723234c9de87c6ccb02d1
BLAKE2b-256 b92ee5fe551dc43b5f4a8f13df7036cb64a1c94737393fa583cc705fc58c5daa

See more details on using hashes here.

Provenance

The following attestation bundles were made for 3tears_mcp-0.31.0.tar.gz:

Publisher: release.yml on pacepace/3tears

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file 3tears_mcp-0.31.0-py3-none-any.whl.

File metadata

  • Download URL: 3tears_mcp-0.31.0-py3-none-any.whl
  • Upload date:
  • Size: 35.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for 3tears_mcp-0.31.0-py3-none-any.whl
Algorithm Hash digest
SHA256 ab1bbe19d911de3ded006d472f7ef0c8ee5f8a0a3b3fa52f6d63668ce24bb80f
MD5 ba89fc41ab476c363e6dcb8699a6a54e
BLAKE2b-256 aeb2f3933b5eab9b9d4da0f427bb6bc3fb48b4e1c58f9616600ecc0ac478c6e7

See more details on using hashes here.

Provenance

The following attestation bundles were made for 3tears_mcp-0.31.0-py3-none-any.whl:

Publisher: release.yml on pacepace/3tears

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.35.1

2 files

0.35.0

2 files

0.34.0

2 files

0.33.0

2 files

0.32.1

2 files

0.32.0

2 files

This release

0.31.0 This release

2 files

0.30.1

2 files

0.30.0

2 files

0.29.0

2 files

0.28.0

2 files

0.27.0

2 files

0.26.1

2 files

0.26.0

2 files

0.25.0

2 files

0.24.7

2 files

0.24.6

2 files

0.24.5

2 files

0.24.4

2 files

0.24.3

2 files

0.24.2

2 files

0.24.1

2 files

0.24.0

2 files

0.23.11

2 files

0.23.10

2 files

0.23.9

2 files

0.23.8

2 files

0.23.7

2 files

0.23.6

2 files

0.23.5

2 files

0.23.3

2 files

0.23.2

2 files

0.23.1

2 files

0.23.0

2 files

0.22.5

2 files

0.22.4

2 files

0.22.3

2 files

0.22.2

2 files

0.22.1

2 files

0.22.0

2 files

0.21.0

2 files

0.20.0

2 files

0.19.4

2 files

0.19.3

2 files

0.19.2

2 files

0.19.1

2 files

0.19.0

2 files

0.18.0

2 files

0.17.9

2 files

0.17.8

2 files

0.17.7

2 files

0.17.6

2 files

0.17.5

2 files

0.17.4

2 files

0.17.3

2 files

0.17.2

2 files

0.17.1

2 files

0.17.0

2 files

0.16.1

2 files

0.16.0

2 files

0.15.0

2 files

0.14.1

2 files

0.14.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page