Skip to content
This repository was archived by the owner on Sep 23, 2026. It is now read-only.

feat(mcp): add --scope option for OAuth and fix upstream auth flow issues - #1625

Open
4riel wants to merge 7 commits into
MoonshotAI:mainfrom
4riel:4riel/mcp-oauth-scopes
Open

4riel wants to merge 7 commits into
MoonshotAI:mainfrom
4riel:4riel/mcp-oauth-scopes

Conversation

@4riel

@4riel 4riel commented Mar 28, 2026 •

Copy link
Copy Markdown

Summary

Add repeatable OAuth scope support to MCP server configuration and authorization, carried forward onto the current upstream main.

Current upstream basis

This PR is based on origin/main 86f13642 (Kimi CLI 1.50.0) and FastMCP 3.2.4 / MCP SDK 1.27.1 from the current lockfile.

Current upstream already provides src/kimi_cli/mcp_oauth.py with persistent OAuth storage and already preserves the full MCP URL path. This update keeps that architecture and removes the old duplicate OAuth module from the original PR.

Implementation

  • Add repeatable kimi mcp add --scope/-s for OAuth HTTP servers.
  • Validate transport/auth combinations, persist scopes, and display configured scopes in kimi mcp list.
  • Forward scopes through the existing shared OAuth construction used by kimi mcp auth, kimi mcp test, and runtime MCP loading.
  • Retain the two compatibility workarounds still needed by FastMCP 3.2.4 for providers that use HTTP 400 during authorization-page handling or HTTP 201 for successful token exchange.
  • Keep canonical FastMCP config construction so omitted transport continues to use URL-based inference, including SSE endpoints.
  • Document the option in English and Chinese MCP guides/reference pages.

Validation

  • Ruff check and format check pass.
  • Pyright passes with 0 errors and 0 warnings using the checkout .venv interpreter.
  • 57 focused OAuth, MCP, toolset, and end-to-end tests pass.
  • OAuth edge cases use safe fixtures; no real provider authorization or secrets were used.

Checklist

  • Read CONTRIBUTING.
  • Added tests for the feature and compatibility behavior.
  • Updated user documentation.
  • Maintainer review and merge.
  • CI checks (none reported by GitHub for this PR yet).

…sues

Add --scope/-s repeatable option to `kimi mcp add` for OAuth servers that
require specific scopes. Validated to require --auth oauth and http transport,
following the existing --header/--auth guard pattern.

Refactor `kimi mcp auth` to use manual transport+OAuth construction so scopes
are forwarded. Add create_oauth() helper with _PatchedOAuthClient that works
around three upstream fastmcp/MCP SDK issues: URL path stripping breaking
RFC 8707 resource matching, redirect_handler pre-flight GET misinterpreting
400 responses, and token exchange rejecting HTTP 201.

Show configured scopes in `kimi mcp list` output and pass scopes through to
OAuth during runtime MCP tool loading in toolset.py.
Copilot AI review requested due to automatic review settings March 28, 2026 16:08
devin-ai-integration[bot]

This comment was marked as resolved.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds OAuth scope support to MCP server configuration and authorization, and applies upstream OAuth compatibility workarounds so OAuth flows work with providers that require scopes and/or have non-standard behaviors.

Changes:

  • Add repeatable --scope / -s to kimi mcp add, persist scopes in config, and display them in mcp list.
  • Refactor kimi mcp auth to construct transports manually so configured scopes are forwarded into OAuth.
  • Update runtime MCP loading to use the same OAuth construction path for scoped OAuth servers; add CLI-focused tests covering validation, persistence, and OAuth construction.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
src/kimi_cli/cli/mcp.py Adds --scope, persists/displays scopes, and introduces create_oauth() with upstream OAuth workarounds; updates mcp_auth() to use manual transport construction.
src/kimi_cli/soul/toolset.py Uses create_oauth() + manual transport when loading scoped OAuth MCP servers at runtime.
tests/core/test_mcp_cli.py New tests for --scope validation/persistence and for OAuth/transport construction behavior in mcp_auth().

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/kimi_cli/soul/toolset.py Outdated
Comment thread src/kimi_cli/cli/mcp.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f8fb87b0f9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/kimi_cli/cli/mcp.py Outdated
Comment thread src/kimi_cli/soul/toolset.py Outdated
…tAI#1625)

- Extract create_oauth() and _PatchedOAuthClient to kimi_cli/oauth.py
- Fix layering violation: soul/toolset.py imports from kimi_cli.oauth instead of cli.mcp
- Remove scopes gate: OAuth workarounds now apply to ALL OAuth servers, not just those with explicit scopes
- Fix return type: create_oauth() now returns OAuth instead of Any
- Add E2E tests for OAuth scopes support

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af9cf48b19

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/kimi_cli/cli/mcp.py Outdated
@4riel

4riel commented Sep 21, 2026

Copy link
Copy Markdown
Author

Updated the PR on top of current upstream main (86f13642) at head ae6f1b28.

What remains from the original request:

  • Added repeatable kimi mcp add --scope/-s for OAuth HTTP servers, with validation, persistence, and mcp list display.
  • Forwarded configured scopes through the existing shared mcp_oauth.py storage path used by mcp auth, mcp test, and runtime loading.
  • Retained the two compatibility workarounds still present in FastMCP 3.2.4: skip the authorization preflight GET and accept successful HTTP 201 token responses. FastMCP 3.2.4 already preserves the full MCP URL path, so the old URL-path workaround was not carried forward.
  • Kept canonical FastMCP config construction so omitted transport continues to use URL-based inference, including /sse endpoints.

The old duplicate src/kimi_cli/oauth.py path was removed because current upstream already provides src/kimi_cli/mcp_oauth.py with persistent storage.

Verification on the current lockfile (fastmcp==3.2.4, mcp==1.27.1):

  • 55 passed across the focused toolset, OAuth, scope, and MCP CLI suites.
  • 11 passed in the focused OAuth helper suite after the final validation/test additions.
  • Ruff check and format check pass for all affected Python files.
  • No real provider authorization was attempted; the OAuth edge cases use safe fixtures and browser/network calls are not performed.

GitHub has not reported CI checks for this PR yet; maintainer review/approval remains separate from code readiness.

@4riel

4riel commented Sep 21, 2026

Copy link
Copy Markdown
Author

Follow-up: the final no-force-pushed PR head is now 8a212018 (the earlier ae6f1b28 update was preserved as remote history, then the narrowed scope-validation fix was merged on top).

Final verification on the current upstream base:

  • Ruff check: pass
  • Ruff format check: pass
  • Pyright with the checkout’s .venv interpreter: 0 errors, 0 warnings
  • Focused MCP/OAuth/toolset/end-to-end suites: 57 passed, 1 existing Python 3.14 deprecation warning

All five previously unresolved review threads addressed by this update are resolved. GitHub CI still reports no checks for this PR; the PR is code-ready and currently awaiting maintainer review/approval.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The upstream OAuth flow overwrites configured scopes, while cached-token and refresh paths do not fully honor the new behavior.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)

Comment thread src/kimi_cli/cli/mcp.py Outdated
Comment thread src/kimi_cli/mcp_oauth.py Outdated
@4riel

4riel commented Sep 21, 2026

Copy link
Copy Markdown
Author

Follow-up on the new Copilot feedback: fixed both issues at head d8e8aed7.

  • mcp list now validates configured OAuth scopes before formatting them and reports malformed values as a clear [invalid scopes] configuration warning instead of raising TypeError.
  • The FastMCP compatibility subclass now normalizes HTTP 201 for both authorization-code token exchange and _handle_refresh_response, with a dedicated refresh-path regression test.

Verification: Ruff, Pyright (0 errors), and the focused MCP/OAuth/toolset/end-to-end suite pass (59 passed, one existing Python 3.14 deprecation warning). No real OAuth provider or secrets were used.

This branch has not been deployed

No deployments
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants