Spaces:
Running
Running
| --- | |
| title: auth | |
| sidebarTitle: auth | |
| --- | |
| # `fastmcp.server.auth.auth` | |
| ## Classes | |
| ### `AccessToken` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L28" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| AccessToken that includes all JWT claims. | |
| ### `AuthProvider` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L34" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| Base class for all FastMCP authentication providers. | |
| This class provides a unified interface for all authentication providers, | |
| whether they are simple token verifiers or full OAuth authorization servers. | |
| All providers must be able to verify tokens and can optionally provide | |
| custom authentication routes. | |
| **Methods:** | |
| #### `verify_token` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L56" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| ```python | |
| verify_token(self, token: str) -> AccessToken | None | |
| ``` | |
| Verify a bearer token and return access info if valid. | |
| All auth providers must implement token verification. | |
| **Args:** | |
| - `token`: The token string to validate | |
| **Returns:** | |
| - AccessToken object if valid, None if invalid or expired | |
| #### `get_routes` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L69" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| ```python | |
| get_routes(self) -> list[Route] | |
| ``` | |
| Get the routes for this authentication provider. | |
| Each provider is responsible for creating whatever routes it needs: | |
| - TokenVerifier: typically no routes (default implementation) | |
| - RemoteAuthProvider: protected resource metadata routes | |
| - OAuthProvider: full OAuth authorization server routes | |
| - Custom providers: whatever routes they need | |
| **Returns:** | |
| - List of routes for this provider | |
| #### `get_resource_metadata_url` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L83" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| ```python | |
| get_resource_metadata_url(self) -> AnyHttpUrl | None | |
| ``` | |
| Get the resource metadata URL for RFC 9728 compliance. | |
| ### `TokenVerifier` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L96" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| Base class for token verifiers (Resource Servers). | |
| This class provides token verification capability without OAuth server functionality. | |
| Token verifiers typically don't provide authentication routes by default. | |
| **Methods:** | |
| #### `verify_token` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L120" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| ```python | |
| verify_token(self, token: str) -> AccessToken | None | |
| ``` | |
| Verify a bearer token and return access info if valid. | |
| ### `RemoteAuthProvider` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L125" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| Authentication provider for resource servers that verify tokens from known authorization servers. | |
| This provider composes a TokenVerifier with authorization server metadata to create | |
| standardized OAuth 2.0 Protected Resource endpoints (RFC 9728). Perfect for: | |
| - JWT verification with known issuers | |
| - Remote token introspection services | |
| - Any resource server that knows where its tokens come from | |
| Use this when you have token verification logic and want to advertise | |
| the authorization servers that issue valid tokens. | |
| **Methods:** | |
| #### `verify_token` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L163" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| ```python | |
| verify_token(self, token: str) -> AccessToken | None | |
| ``` | |
| Verify token using the configured token verifier. | |
| #### `get_routes` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L167" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| ```python | |
| get_routes(self) -> list[Route] | |
| ``` | |
| Get OAuth routes for this provider. | |
| By default, returns only the standardized OAuth 2.0 Protected Resource routes. | |
| Subclasses can override this method to add additional routes by calling | |
| super().get_routes() and extending the returned list. | |
| ### `OAuthProvider` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L184" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| OAuth Authorization Server provider. | |
| This class provides full OAuth server functionality including client registration, | |
| authorization flows, token issuance, and token verification. | |
| **Methods:** | |
| #### `verify_token` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L251" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| ```python | |
| verify_token(self, token: str) -> AccessToken | None | |
| ``` | |
| Verify a bearer token and return access info if valid. | |
| This method implements the TokenVerifier protocol by delegating | |
| to our existing load_access_token method. | |
| **Args:** | |
| - `token`: The token string to validate | |
| **Returns:** | |
| - AccessToken object if valid, None if invalid or expired | |
| #### `get_routes` <sup><a href="https://github.com/jlowin/fastmcp/blob/main/src/fastmcp/server/auth/auth.py#L266" target="_blank"><Icon icon="github" style="width: 14px; height: 14px;" /></a></sup> | |
| ```python | |
| get_routes(self) -> list[Route] | |
| ``` | |
| Get OAuth authorization server routes and optional protected resource routes. | |
| This method creates the full set of OAuth routes including: | |
| - Standard OAuth authorization server routes (/.well-known/oauth-authorization-server, /authorize, /token, etc.) | |
| - Optional protected resource routes if resource_server_url is configured | |
| **Returns:** | |
| - List of OAuth routes | |