Class: MCPClient::OAuthClient

Inherits:
Object
  • Object
show all
Defined in:
lib/mcp_client/oauth_client.rb

Overview

Utility class for creating OAuth-enabled MCP clients

Class Method Summary collapse

Class Method Details

.complete_oauth_flow(server, code, state, iss: nil) ⇒ Auth::Token

Complete OAuth authorization flow with authorization code

Parameters:

  • server (ServerHTTP, ServerStreamableHTTP) —

    The OAuth-enabled server

  • code (String) —

    Authorization code from callback

  • state (String) —

    State parameter from callback

  • iss (String, nil) (defaults to: nil) —

    the iss parameter of the authorization response (RFC 9207, MCP 2026-07-28), validated against the recorded issuer before the token exchange

Returns:

Raises:

  • (ArgumentError) —

    if server doesn't have OAuth provider



104
105
106
107
108
109
110
111
# File 'lib/mcp_client/oauth_client.rb', line 104

def self.complete_oauth_flow(server, code, state, iss: nil)
  oauth_provider = server.instance_variable_get(:@oauth_provider)
  raise ArgumentError, 'Server does not have OAuth provider configured' unless oauth_provider

  return oauth_provider.complete_authorization_flow(code, state) if iss.nil?

  oauth_provider.complete_authorization_flow(code, state, iss: iss)
end

.create_http_server(server_url:, **options) ⇒ ServerHTTP

Create an OAuth-enabled HTTP server

Parameters:

  • server_url (String) —

    The MCP server URL

  • options (Hash) —

    Configuration options

Options Hash (**options):

  • :redirect_uri (String) —

    OAuth redirect URI (default: 'http://localhost:8080/callback')

  • :scope (String, nil) —

    OAuth scope

  • :endpoint (String) —

    JSON-RPC endpoint path (default: '/rpc')

  • :headers (Hash) —

    Additional headers to include in requests

  • :read_timeout (Integer) —

    Read timeout in seconds (default: 30)

  • :retries (Integer) —

    Retry attempts on transient errors (default: 3)

  • :retry_backoff (Numeric) —

    Base delay for exponential backoff (default: 1)

  • :name (String, nil) —

    Optional name for this server

  • :logger (Logger, nil) —

    Optional logger

  • :storage (Object, nil) —

    Storage backend for OAuth tokens and client info

  • :client_id_metadata_url (String, nil) —

    HTTPS URL of this client's Client ID Metadata Document (SEP-991)

  • :application_type (String, nil) —

    'native' or 'web' for Dynamic Client Registration (MCP 2026-07-28; derived from the redirect URI when omitted)

Returns:



28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
# File 'lib/mcp_client/oauth_client.rb', line 28

def self.create_http_server(server_url:, **options)
  opts = default_server_options.merge(options)

  oauth_provider = Auth::OAuthProvider.new(
    server_url: server_url,
    redirect_uri: opts[:redirect_uri],
    scope: opts[:scope],
    logger: opts[:logger],
    storage: opts[:storage],
    client_id_metadata_url: opts[:client_id_metadata_url],
    application_type: opts[:application_type]
  )

  ServerHTTP.new(
    base_url: server_url,
    endpoint: opts[:endpoint],
    headers: opts[:headers],
    read_timeout: opts[:read_timeout],
    retries: opts[:retries],
    retry_backoff: opts[:retry_backoff],
    name: opts[:name],
    logger: opts[:logger],
    oauth_provider: oauth_provider
  )
end

.create_streamable_http_server(server_url:, **options) ⇒ ServerStreamableHTTP

Create an OAuth-enabled Streamable HTTP server

Parameters:

  • server_url (String) —

    The MCP server URL

  • options (Hash) —

    Configuration options (same as create_http_server)

Returns:



58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
# File 'lib/mcp_client/oauth_client.rb', line 58

def self.create_streamable_http_server(server_url:, **options)
  opts = default_server_options.merge(options)

  oauth_provider = Auth::OAuthProvider.new(
    server_url: server_url,
    redirect_uri: opts[:redirect_uri],
    scope: opts[:scope],
    logger: opts[:logger],
    storage: opts[:storage],
    client_id_metadata_url: opts[:client_id_metadata_url],
    application_type: opts[:application_type]
  )

  ServerStreamableHTTP.new(
    base_url: server_url,
    endpoint: opts[:endpoint],
    headers: opts[:headers],
    read_timeout: opts[:read_timeout],
    retries: opts[:retries],
    retry_backoff: opts[:retry_backoff],
    name: opts[:name],
    logger: opts[:logger],
    oauth_provider: oauth_provider
  )
end

.start_oauth_flow(server) ⇒ String

Perform OAuth authorization flow for a server This is a helper method that can be used to manually perform the OAuth flow

Parameters:

Returns:

  • (String) —

    Authorization URL to redirect user to

Raises:

  • (ArgumentError) —

    if server doesn't have OAuth provider



89
90
91
92
93
94
# File 'lib/mcp_client/oauth_client.rb', line 89

def self.start_oauth_flow(server)
  oauth_provider = server.instance_variable_get(:@oauth_provider)
  raise ArgumentError, 'Server does not have OAuth provider configured' unless oauth_provider

  oauth_provider.start_authorization_flow
end

.valid_token?(server) ⇒ Boolean

Check if server has a valid OAuth access token

Parameters:

Returns:

  • (Boolean) —

    true if server has valid access token



116
117
118
119
120
121
122
# File 'lib/mcp_client/oauth_client.rb', line 116

def self.valid_token?(server)
  oauth_provider = server.instance_variable_get(:@oauth_provider)
  return false unless oauth_provider

  token = oauth_provider.access_token
  !!(token && !token.expired?)
end