Skip to content

feat(mcp): add OAuth 2.0 Client Credentials support for MCP server connections - #3960

Open
SyedShahmeerAli12 wants to merge 3 commits into
deepset-ai:mainfrom
SyedShahmeerAli12:feat/mcp-oauth-client-credentials
Open

SyedShahmeerAli12 wants to merge 3 commits into
deepset-ai:mainfrom
SyedShahmeerAli12:feat/mcp-oauth-client-credentials

Conversation

@SyedShahmeerAli12

@SyedShahmeerAli12 SyedShahmeerAli12 commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Related Issues

Proposed Changes

Add OAuth 2.0 Client Credentials grant support for MCP server connections. Both SSEServerInfo and StreamableHttpServerInfo now accept an optional oauth_config field:

from haystack_integrations.tools.mcp import OAuthConfig, StreamableHttpServerInfo
from haystack.utils import Secret

server_info = StreamableHttpServerInfo(
    url="https://my-mcp-server.com/mcp",
    oauth_config=OAuthConfig(
        client_id="my-client-id",
        client_secret=Secret.from_env_var("MCP_CLIENT_SECRET"),
        token_endpoint="https://auth.example.com/oauth/token",
    ),
)

Tokens are cached in memory and refreshed automatically before expiry. Token endpoint discovery via /.well-known/oauth-authorization-server (RFC 8414) is supported when token_endpoint is not provided directly.

How did you test it

  • 37 unit tests with mocked HTTP covering all new classes and functions
  • 11 integration tests that spin up a real local HTTP server and exercise the full token-fetch and inject path

Notes for the reviewer

No new dependencies httpx is already a transitive dep of the MCP integration.

Checklist

…nnections

Implement OAuth 2.0 Client Credentials grant (RFC 6749 §4.4) for SSE and
StreamableHTTP MCP server connections, including token caching, automatic
refresh, and OAuth 2.0 Server Metadata discovery (RFC 8414).
@SyedShahmeerAli12
SyedShahmeerAli12 requested a review from a team as a code owner September 15, 2026 11:58
@SyedShahmeerAli12
SyedShahmeerAli12 requested review from davidsbatista and removed request for a team September 15, 2026 11:58
@github-actions github-actions Bot added integration:mcp type:documentation Improvements or additions to documentation labels Sep 15, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Heads-up for maintainers

This PR is from a fork and touches integrations whose integration tests require API keys.
Those tests are skipped in CI because fork PRs don't have access to repo secrets for security reasons.

Affected integrations:

  • mcp

Please run the integration tests locally (hatch run test:integration inside each folder) before approving.

@SyedShahmeerAli12
SyedShahmeerAli12 force-pushed the feat/mcp-oauth-client-credentials branch from c21f9b0 to cad12f3 Compare September 15, 2026 12:02
@github-actions

Copy link
Copy Markdown
Contributor

Coverage report (mcp)

Click to see where and how coverage changed

FileStatementsMissingCoverageCoverage
(new stmts)
Lines missing
  integrations/mcp/src/haystack_integrations/tools/mcp
  mcp_tool.py 646-647
  oauth.py 175-178
Project Total  

This report was generated by python-coverage-comment-action

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

integration:mcp type:documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

mcp: Implement OAuth 2.1 Grant Flows (Authorization Code + PKCE and Client Credentials)

1 participant