Skip to main content

Authed authentication integration for Model Context Protocol (MCP)

Project description

Authed MCP Integration

This package provides integration between Authed authentication and the Model Context Protocol (MCP).

Overview

The Authed MCP integration allows you to:

  1. Create MCP servers with Authed authentication
  2. Create MCP clients that can authenticate with Authed
  3. Register MCP servers as Authed agents
  4. Grant access permissions between MCP clients and servers

Installation

pip install authed-mcp

Usage

Server Example

import asyncio
import os
from dotenv import load_dotenv

from client.sdk import Authed
from integrations.mcp import AuthedMCPServer

async def main():
    # Load environment variables
    load_dotenv()
    
    # Initialize Authed client
    registry_url = os.getenv("AUTHED_REGISTRY_URL", "https://api.getauthed.dev")
    agent_id = os.getenv("AUTHED_AGENT_ID")
    agent_secret = os.getenv("AUTHED_AGENT_SECRET")
    private_key = os.getenv("AUTHED_PRIVATE_KEY")
    public_key = os.getenv("AUTHED_PUBLIC_KEY")
    
    # Create MCP server with Authed authentication
    server = AuthedMCPServer(
        name="example-server",
        registry_url=registry_url,
        agent_id=agent_id,
        agent_secret=agent_secret,
        private_key=private_key,
        public_key=public_key
    )
    
    # Register a resource handler
    @server.resource("/hello/{name}")
    async def hello_resource(name: str):
        return f"Hello, {name}!", "text/plain"
    
    # Register a tool handler
    @server.tool("echo")
    async def echo_tool(message: str):
        return {"message": message}
    
    # Register a prompt handler
    @server.prompt("greeting")
    async def greeting_prompt(name: str = "World"):
        return f"Hello, {name}! Welcome to the MCP server."
    
    # Run the server
    server.run()

if __name__ == "__main__":
    asyncio.run(main())

Client Example

import asyncio
import os
from dotenv import load_dotenv

from integrations.mcp import AuthedMCPClient

async def main():
    # Load environment variables
    load_dotenv()
    
    # Initialize client with Authed credentials
    registry_url = os.getenv("AUTHED_REGISTRY_URL", "https://api.getauthed.dev")
    agent_id = os.getenv("AUTHED_AGENT_ID")
    agent_secret = os.getenv("AUTHED_AGENT_SECRET")
    private_key = os.getenv("AUTHED_PRIVATE_KEY")
    public_key = os.getenv("AUTHED_PUBLIC_KEY")
    
    # Create MCP client with Authed authentication
    client = AuthedMCPClient(
        registry_url=registry_url,
        agent_id=agent_id,
        agent_secret=agent_secret,
        private_key=private_key,
        public_key=public_key
    )
    
    # Get server agent ID
    server_agent_id = os.getenv("MCP_SERVER_AGENT_ID")
    
    # Define server URL
    server_url = "http://localhost:8000/sse"
    
    try:
        # Call a tool
        result = await client.call_tool(
            server_url=server_url,
            server_agent_id=server_agent_id,
            tool_name="echo",
            arguments={"message": "Hello from MCP client!"}
        )
        print(f"Echo result: {result}")
        
        # List available resources
        resources = await client.list_resources(
            server_url=server_url,
            server_agent_id=server_agent_id
        )
        print(f"Available resources: {resources}")
    except Exception as e:
        print(f"Error: {str(e)}")

if __name__ == "__main__":
    asyncio.run(main())

Components

AuthedMCPServer

A wrapper around the MCP server that adds Authed authentication. It initializes both the Authed client and the MCP server, and registers the necessary middleware to handle authentication.

AuthedMCPClient

A client for making authenticated requests to MCP servers. It automatically:

  • Creates and attaches DPoP proofs to requests
  • Handles token management
  • Provides a simple interface for interacting with MCP servers
  • Includes improved URL normalization for consistent comparison
  • Provides robust error handling

Advanced Features

The Authed MCP integration includes several advanced features:

URL Normalization

Both the client and server use consistent URL normalization to prevent issues with port duplication and scheme differences:

  • Properly handles ports in URLs (omitting standard ports 80/443)
  • Consistently compares URLs for verification
  • Sorts query parameters for deterministic comparison

Utility Functions

register_mcp_server

Registers an MCP server as an agent in Authed:

from client.sdk import Authed
from integrations.mcp import register_mcp_server

async def setup():
    authed = Authed.initialize(...)
    
    server_info = await register_mcp_server(
        authed=authed,
        name="My MCP Server",
        description="MCP server with Authed authentication",
        capabilities={"tools": ["echo", "calculator"], "resources": ["hello"]}
    )
    
    # Save the resulting agent_id, private_key, etc.
    print(f"Server registered with ID: {server_info['agent_id']}")

grant_mcp_access

Grants an MCP client access to an MCP server:

from client.sdk import Authed
from integrations.mcp import grant_mcp_access

async def setup_permissions():
    authed = Authed.initialize(...)
    
    success = await grant_mcp_access(
        authed=authed,
        client_agent_id="client-agent-id",
        server_agent_id="server-agent-id",
        permissions=["mcp:call_tool", "mcp:list_resources"]
    )
    
    if success:
        print("Access granted successfully")
    else:
        print("Failed to grant access")

Requirements

  • Python 3.8+
  • Authed SDK
  • MCP SDK

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

authed_mcp-0.1.0.tar.gz (11.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

authed_mcp-0.1.0-py3-none-any.whl (12.3 kB view details)

Uploaded Python 3

File details

Details for the file authed_mcp-0.1.0.tar.gz.

File metadata

  • Download URL: authed_mcp-0.1.0.tar.gz
  • Upload date:
  • Size: 11.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.6

File hashes

Hashes for authed_mcp-0.1.0.tar.gz
Algorithm Hash digest
SHA256 c033d43f5cac55405ec47c297da2442ed58d7a2ac2a44729f102b4d4ff6d98d9
MD5 cb50e439745fc1247915cc229d4ece00
BLAKE2b-256 4b0984f1defff5aa6a8c1261a1a293f9e97db5279b3575ef6768790ed956c590

See more details on using hashes here.

File details

Details for the file authed_mcp-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: authed_mcp-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 12.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.6

File hashes

Hashes for authed_mcp-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 64fe2f6bf3722dafe3a6f03a4f0c5bb3532ac5bf2c20b798da181fdefe0536c7
MD5 9ab9ef9066a20300b54be94a088d0247
BLAKE2b-256 04f54c9823da660599aa0fffe7e811d9bbcfc7699aa8785efa25fa1ceb89eabc

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page