Repository navigation
fix(mcp): upgrade FastMCP OAuth storage - #2241
Conversation
There was a problem hiding this comment.
Pull request overview
This PR upgrades the MCP client stack to FastMCP 3.2.4 to eliminate Authlib deprecation warnings during MCP startup, and updates Kimi CLI’s MCP OAuth handling to use FastMCP 3’s persistent token storage (backed by a filetree store under ~/.kimi/mcp-oauth/).
Changes:
- Upgrade FastMCP to 3.2.4 (plus related dependency/lockfile updates) and refresh PyInstaller dist-info expectations.
- Introduce a Kimi-owned MCP OAuth storage helper and update MCP runtime + CLI commands to use persistent OAuth storage APIs.
- Add tests for token persistence and OAuth config preparation; update changelog and docs to reflect the new token cache location and migration behavior.
Reviewed changes
Copilot reviewed 19 out of 20 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
uv.lock |
Updates locked dependency set for FastMCP 3.2.4 and new transitive requirements. |
pyproject.toml |
Bumps FastMCP pin to 3.2.4. |
src/kimi_cli/mcp_oauth.py |
New helper module for persistent MCP OAuth storage + config preparation. |
src/kimi_cli/cli/mcp.py |
Updates mcp auth/reset-auth/test/list flows to use the new OAuth storage/config helper. |
src/kimi_cli/soul/toolset.py |
Updates runtime MCP loading to replace auth: "oauth" with a persistent OAuth object and check authorization via new helper. |
tests/cli/test_mcp_oauth.py |
Adds tests for token persistence, warning-free OAuth creation, and non-mutating config preparation. |
tests/utils/test_pyinstaller_utils.py |
Updates expected FastMCP dist-info paths for PyInstaller packaging tests. |
CHANGELOG.md |
Documents the FastMCP upgrade and new MCP OAuth token location. |
docs/en/release-notes/changelog.md |
Mirrors changelog entries for the release notes site. |
docs/en/release-notes/breaking-changes.md |
Adds migration note for MCP OAuth token cache location change. |
docs/en/reference/kimi-mcp.md |
Updates MCP command reference to mention new token cache location + migration note. |
docs/en/customization/mcp.md |
Notes token location and re-auth requirement after upgrade. |
docs/en/customization/wire-mode.md |
Updates comparison of OAuth storage locations (Rust vs Python). |
docs/en/configuration/data-locations.md |
Documents ~/.kimi/mcp-oauth/ as a new data directory. |
docs/zh/release-notes/changelog.md |
Chinese release note entries for the FastMCP upgrade + token location change. |
docs/zh/release-notes/breaking-changes.md |
Chinese migration note for MCP OAuth token cache move. |
docs/zh/reference/kimi-mcp.md |
Chinese MCP reference update for token cache location/migration. |
docs/zh/customization/mcp.md |
Chinese customization doc update for token cache location/migration. |
docs/zh/customization/wire-mode.md |
Chinese Wire mode doc update for OAuth storage location comparison. |
docs/zh/configuration/data-locations.md |
Chinese data locations update to include mcp-oauth/. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| storage = create_mcp_oauth_token_storage(server_url) | ||
| return await storage.get_tokens() is not None |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 333c293680
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| async def has_mcp_oauth_tokens(server_url: str) -> bool: | ||
| storage = create_mcp_oauth_token_storage(server_url) | ||
| return await storage.get_tokens() is not None |
There was a problem hiding this comment.
Guard OAuth token probe against storage failures
Wrap has_mcp_oauth_tokens in exception handling so token lookup degrades to “not authorized” instead of crashing callers. As written, any PermissionError/I/O error from creating or reading ~/.kimi/mcp-oauth (or an import/runtime error in the storage backend) now propagates and can abort flows like kimi mcp list and MCP tool loading, whereas the previous behavior treated lookup failures as missing tokens.
Useful? React with 👍 / 👎.
Related Issue
Resolve #2203
Description
Upgrade FastMCP from 2.12.5 to 3.2.4 to avoid the AuthlibDeprecationWarning triggered by the old FastMCP client import path when MCP servers are configured.
FastMCP 3.x removed
FileTokenStorage, so this PR also updates Kimi's MCP OAuth handling to use persistentOAuth(...)storage backed byFileTreeStoreunder~/.kimi/mcp-oauth/.Changes:
kimi mcp list/auth/reset-auth/testto use FastMCP 3 OAuth storage APIs.auth: "oauth"with a persistent OAuth auth object.Note: migration from the old FastMCP 2.x OAuth token cache is not included. Users with OAuth MCP servers may need to run
kimi mcp auth <name>once after upgrading.Verification performed:
prek run --all-filesmake checkmake test-kimi-clikimiuses FastMCP 3.2.4.kimi mcp listwith an OAuth MCP config underPYTHONWARNINGS=error.Checklist
gen-changelogprompt.gen-docsprompt.