Repository navigation
Conversation
…sues Add --scope/-s repeatable option to `kimi mcp add` for OAuth servers that require specific scopes. Validated to require --auth oauth and http transport, following the existing --header/--auth guard pattern. Refactor `kimi mcp auth` to use manual transport+OAuth construction so scopes are forwarded. Add create_oauth() helper with _PatchedOAuthClient that works around three upstream fastmcp/MCP SDK issues: URL path stripping breaking RFC 8707 resource matching, redirect_handler pre-flight GET misinterpreting 400 responses, and token exchange rejecting HTTP 201. Show configured scopes in `kimi mcp list` output and pass scopes through to OAuth during runtime MCP tool loading in toolset.py.
There was a problem hiding this comment.
Pull request overview
Adds OAuth scope support to MCP server configuration and authorization, and applies upstream OAuth compatibility workarounds so OAuth flows work with providers that require scopes and/or have non-standard behaviors.
Changes:
- Add repeatable
--scope / -stokimi mcp add, persist scopes in config, and display them inmcp list. - Refactor
kimi mcp authto construct transports manually so configured scopes are forwarded into OAuth. - Update runtime MCP loading to use the same OAuth construction path for scoped OAuth servers; add CLI-focused tests covering validation, persistence, and OAuth construction.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
src/kimi_cli/cli/mcp.py |
Adds --scope, persists/displays scopes, and introduces create_oauth() with upstream OAuth workarounds; updates mcp_auth() to use manual transport construction. |
src/kimi_cli/soul/toolset.py |
Uses create_oauth() + manual transport when loading scoped OAuth MCP servers at runtime. |
tests/core/test_mcp_cli.py |
New tests for --scope validation/persistence and for OAuth/transport construction behavior in mcp_auth(). |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f8fb87b0f9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…tAI#1625) - Extract create_oauth() and _PatchedOAuthClient to kimi_cli/oauth.py - Fix layering violation: soul/toolset.py imports from kimi_cli.oauth instead of cli.mcp - Remove scopes gate: OAuth workarounds now apply to ALL OAuth servers, not just those with explicit scopes - Fix return type: create_oauth() now returns OAuth instead of Any - Add E2E tests for OAuth scopes support
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af9cf48b19
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Updated the PR on top of current upstream What remains from the original request:
The old duplicate Verification on the current lockfile (
GitHub has not reported CI checks for this PR yet; maintainer review/approval remains separate from code readiness. |
…/mcp-oauth-scopes # Conflicts: # src/kimi_cli/mcp_oauth.py
|
Follow-up: the final no-force-pushed PR head is now Final verification on the current upstream base:
All five previously unresolved review threads addressed by this update are resolved. GitHub CI still reports no checks for this PR; the PR is code-ready and currently awaiting maintainer review/approval. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The upstream OAuth flow overwrites configured scopes, while cached-token and refresh paths do not fully honor the new behavior.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 2
Open (2)
|
Follow-up on the new Copilot feedback: fixed both issues at head
Verification: Ruff, Pyright (0 errors), and the focused MCP/OAuth/toolset/end-to-end suite pass ( |

Summary
Add repeatable OAuth scope support to MCP server configuration and authorization, carried forward onto the current upstream
main.Current upstream basis
This PR is based on
origin/main86f13642(Kimi CLI 1.50.0) and FastMCP3.2.4/ MCP SDK1.27.1from the current lockfile.Current upstream already provides
src/kimi_cli/mcp_oauth.pywith persistent OAuth storage and already preserves the full MCP URL path. This update keeps that architecture and removes the old duplicate OAuth module from the original PR.Implementation
kimi mcp add --scope/-sfor OAuth HTTP servers.kimi mcp list.kimi mcp auth,kimi mcp test, and runtime MCP loading.transportcontinues to use URL-based inference, including SSE endpoints.Validation
.venvinterpreter.Checklist