Skip to content
This repository was archived by the owner on Sep 23, 2026. It is now read-only.

fix(mcp): upgrade FastMCP OAuth storage - #2241

Merged
7Sageer merged 4 commits into
MoonshotAI:mainfrom
7Sageer:fix/fastmcp-3.2.4-oauth
May 12, 2026
Merged

7Sageer merged 4 commits into
MoonshotAI:mainfrom
7Sageer:fix/fastmcp-3.2.4-oauth

Conversation

@7Sageer

@7Sageer 7Sageer commented May 12, 2026

Copy link
Copy Markdown
Collaborator

Related Issue

Resolve #2203

Description

Upgrade FastMCP from 2.12.5 to 3.2.4 to avoid the AuthlibDeprecationWarning triggered by the old FastMCP client import path when MCP servers are configured.

FastMCP 3.x removed FileTokenStorage, so this PR also updates Kimi's MCP OAuth handling to use persistent OAuth(...) storage backed by FileTreeStore under ~/.kimi/mcp-oauth/.

Changes:

  • Add a Kimi-owned MCP OAuth storage helper.
  • Update kimi mcp list/auth/reset-auth/test to use FastMCP 3 OAuth storage APIs.
  • Update runtime MCP loading to replace auth: "oauth" with a persistent OAuth auth object.
  • Refresh PyInstaller FastMCP dist-info expectations and lockfile dependencies.
  • Add tests for persistent MCP OAuth storage and config preparation.
  • Update changelog, migration notes, and MCP OAuth documentation.

Note: migration from the old FastMCP 2.x OAuth token cache is not included. Users with OAuth MCP servers may need to run kimi mcp auth <name> once after upgrading.

Verification performed:

  • prek run --all-files
  • make check
  • make test-kimi-cli
  • Installed this branch into a temporary virtualenv and verified the installed kimi uses FastMCP 3.2.4.
  • Ran installed kimi mcp list with an OAuth MCP config under PYTHONWARNINGS=error.

Checklist

  • I have read the CONTRIBUTING document.
  • I have linked the related issue, if any.
  • I have added tests that prove my fix is effective or that my feature works.
  • I have updated the changelog following the gen-changelog prompt.
  • I have updated the user documentation following the gen-docs prompt.

Copilot AI review requested due to automatic review settings May 12, 2026 06:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR upgrades the MCP client stack to FastMCP 3.2.4 to eliminate Authlib deprecation warnings during MCP startup, and updates Kimi CLI’s MCP OAuth handling to use FastMCP 3’s persistent token storage (backed by a filetree store under ~/.kimi/mcp-oauth/).

Changes:

  • Upgrade FastMCP to 3.2.4 (plus related dependency/lockfile updates) and refresh PyInstaller dist-info expectations.
  • Introduce a Kimi-owned MCP OAuth storage helper and update MCP runtime + CLI commands to use persistent OAuth storage APIs.
  • Add tests for token persistence and OAuth config preparation; update changelog and docs to reflect the new token cache location and migration behavior.

Reviewed changes

Copilot reviewed 19 out of 20 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
uv.lock Updates locked dependency set for FastMCP 3.2.4 and new transitive requirements.
pyproject.toml Bumps FastMCP pin to 3.2.4.
src/kimi_cli/mcp_oauth.py New helper module for persistent MCP OAuth storage + config preparation.
src/kimi_cli/cli/mcp.py Updates mcp auth/reset-auth/test/list flows to use the new OAuth storage/config helper.
src/kimi_cli/soul/toolset.py Updates runtime MCP loading to replace auth: "oauth" with a persistent OAuth object and check authorization via new helper.
tests/cli/test_mcp_oauth.py Adds tests for token persistence, warning-free OAuth creation, and non-mutating config preparation.
tests/utils/test_pyinstaller_utils.py Updates expected FastMCP dist-info paths for PyInstaller packaging tests.
CHANGELOG.md Documents the FastMCP upgrade and new MCP OAuth token location.
docs/en/release-notes/changelog.md Mirrors changelog entries for the release notes site.
docs/en/release-notes/breaking-changes.md Adds migration note for MCP OAuth token cache location change.
docs/en/reference/kimi-mcp.md Updates MCP command reference to mention new token cache location + migration note.
docs/en/customization/mcp.md Notes token location and re-auth requirement after upgrade.
docs/en/customization/wire-mode.md Updates comparison of OAuth storage locations (Rust vs Python).
docs/en/configuration/data-locations.md Documents ~/.kimi/mcp-oauth/ as a new data directory.
docs/zh/release-notes/changelog.md Chinese release note entries for the FastMCP upgrade + token location change.
docs/zh/release-notes/breaking-changes.md Chinese migration note for MCP OAuth token cache move.
docs/zh/reference/kimi-mcp.md Chinese MCP reference update for token cache location/migration.
docs/zh/customization/mcp.md Chinese customization doc update for token cache location/migration.
docs/zh/customization/wire-mode.md Chinese Wire mode doc update for OAuth storage location comparison.
docs/zh/configuration/data-locations.md Chinese data locations update to include mcp-oauth/.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/kimi_cli/mcp_oauth.py Outdated
Comment on lines +44 to +45
storage = create_mcp_oauth_token_storage(server_url)
return await storage.get_tokens() is not None

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 333c293680

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/kimi_cli/mcp_oauth.py Outdated
Comment on lines +43 to +45
async def has_mcp_oauth_tokens(server_url: str) -> bool:
storage = create_mcp_oauth_token_storage(server_url)
return await storage.get_tokens() is not None

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Guard OAuth token probe against storage failures

Wrap has_mcp_oauth_tokens in exception handling so token lookup degrades to “not authorized” instead of crashing callers. As written, any PermissionError/I/O error from creating or reading ~/.kimi/mcp-oauth (or an import/runtime error in the storage backend) now propagates and can abort flows like kimi mcp list and MCP tool loading, whereas the previous behavior treated lookup failures as missing tokens.

Useful? React with 👍 / 👎.

@7Sageer
7Sageer merged commit 83cfb5d into MoonshotAI:main May 12, 2026
34 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

AuthlibDeprecationWarning printed on every startup when MCP servers are configured

2 participants