-
Notifications
You must be signed in to change notification settings - Fork 514
[ROB-2694] Oauth #1900
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
[ROB-2694] Oauth #1900
Changes from all commits
Commits
Show all changes
73 commits
Select commit
Hold shift + click to select a range
f72b926
Add OAuth authorization_code support for MCP servers
Avi-Robusta 6ca8a8b
docs
Avi-Robusta e4641a9
Share OAuth tokens across MCP servers with same IdP, fix multi-audience
Avi-Robusta c3c08ad
Add CLI OAuth flow, auto-discovery, and Atlassian MCP support
Avi-Robusta 8d63fba
Fix CLI/frontend mode detection: use request_context presence not hea…
Avi-Robusta 4df8bdf
Defer DCR to runtime, send registration_endpoint to frontend
Avi-Robusta 0a8b00c
Accept client_id from frontend DCR in encrypted OAuth payload
Avi-Robusta e07a33e
Derive persistent OAuth keypair from signing_key
Avi-Robusta 08dff98
Persist OAuth keypair in CLI mode with machine-derived encryption
Avi-Robusta 41afc35
Fix CLI OAuth: perform DCR when client_id is missing
Avi-Robusta 6816441
Fix cache key mismatch after CLI DCR changes client_id
Avi-Robusta 117bead
Add CLI OAuth flow tests with mocked browser/callback/DCR
Avi-Robusta 7b3b305
Add cross-cluster OAuth token storage via DB
Avi-Robusta f87fb57
Handle read-only filesystem for DiskTokenStore gracefully
Avi-Robusta bd97823
Fix DB token lookup: use authorization_url as provider_name, not tool…
Avi-Robusta 7df6ef1
Store refresh token expiry in DB, update DB on token refresh
Avi-Robusta 028a723
Add user_id scoping to OAuth token storage and cache
Avi-Robusta d4e52e5
Add OAuth eval test (254_mcp_oauth) and consolidate OAuth unit tests
Avi-Robusta b00a2e7
Remove RSA encryption from OAuth flow, extract token management, add …
Avi-Robusta 8e0fe28
Deduplicate OAuth token exchange, unify storage, skip manual tests in CI
Avi-Robusta 68b2747
OAuth flow cleanup: move import to top-level, add OAuthCallback model…
Avi-Robusta 722a213
Use decision field for OAuth in tool approvals instead of encrypted_t…
Avi-Robusta 9e85d83
cleanup fixes
Avi-Robusta 4898a60
working both flows
Avi-Robusta 31d5b57
Remove dead code and clean up tool_executor OAuth naming
Avi-Robusta 2636f91
refactoring tools
Avi-Robusta e08a4b8
Clean up OAuth tool executor: remove dead code, deduplicate logic, im…
Avi-Robusta 39a1563
bugfix-approval not enabled param
Avi-Robusta 5d0dbf5
Move OAuth config to RemoteMCPToolset.get_oauth_config(), clean up sy…
Avi-Robusta e11e4dc
accidental commit
Avi-Robusta b40c014
fixes
Avi-Robusta 7ec91c9
refactoring
Avi-Robusta 839bf69
refactoring
Avi-Robusta 2e1d32d
refactoring
Avi-Robusta 23e1e39
Refactor OAuth code out of toolset_mcp.py into dedicated modules
Avi-Robusta 12721ef
Add error logging for OAuth callback 400/502 responses
Avi-Robusta 568977a
Add request logging to OAuth callback to debug field forwarding
Avi-Robusta 72063be
Debug: log token_url and redirect_uri in OAuth callback
Avi-Robusta 90496bf
refactoring
Avi-Robusta 319b13a
refactoring
Avi-Robusta 9d43ad4
refactoring
Avi-Robusta 597a19a
Replace OAuth section in remote-mcp-servers.md with link to dedicated…
Avi-Robusta 35e779c
Merge master into oauth branch
Avi-Robusta b4e0473
Fix CLI OAuth port race condition in parallel test runs
Avi-Robusta f6d21b9
refactoring
Avi-Robusta 1de70a8
Refactor OAuth: PR review fixes, per-user tool store, unified TokenStore
Avi-Robusta 0adffea
Fix OAuth token refresh, tool display, and log verbosity
Avi-Robusta 3ce3f14
Fix UI issue with missing toolset name for OAuth tools
Avi-Robusta 2a8dd5e
Fix docs: OAuth tokens are persisted, not session-only
Avi-Robusta cc85823
Avoid DiskTokenStore init in cluster, move imports to top
Avi-Robusta 7c07075
Remove redundant token check from prerequisites, clean up registratio…
Avi-Robusta dad9665
Merge master into oauth branch
Avi-Robusta 276ffce
Address PR review comments: signing_key_hash filter, sweep→refresh re…
Avi-Robusta 98e8520
Fix OAuth tools lost on toolset refresh — eager-load after executor r…
Avi-Robusta b481d81
Fix disk token file permissions race and guard toolset None in OAuth …
Avi-Robusta 495eb21
Fix CLI OAuth: set cli_user identity, evict revoked tokens from persi…
Avi-Robusta 835139e
Include oauth_config in toolset meta when syncing to DB
Avi-Robusta e168676
Fix shared MCPOAuthConfig.client_id mutation in OAuth callback
Avi-Robusta fde30a5
Fix test failures: rename sweep→refresh in tests, add oauth_connector…
Avi-Robusta 5a5d070
Fix missing oauth_connector on manually-constructed ToolExecutor clon…
Avi-Robusta 7aec83b
Merge branch 'master' into oauth
Avi-Robusta e60d1e4
Fix test ordering leak: reset singleton token manager store between t…
Avi-Robusta 23a86a7
Fix test_server_endpoints mock: set num_llm_calls to int for otel rec…
Avi-Robusta e2f8063
Fix remaining test_server_endpoints mocks: set num_llm_calls on all M…
Avi-Robusta 17da1b2
Fix read-only filesystem crash in OAuth callback: disable prerequisit…
Avi-Robusta f3b5d67
Remove cli_user: use __no_user__ fallback in connector instead
Avi-Robusta 96de97b
Remove dead get_config_meta_for_toolset call in toolset sync
Avi-Robusta c351ff2
Only delete revoked tokens from disk store, not shared DB
Avi-Robusta bf3d340
Centralize CLI user_id handling via require_user_id and DEFAULT_CLI_USER
Avi-Robusta 34e46fb
Remove unused get_config_meta_for_toolset function
Avi-Robusta 3d4bd71
Trigger CI
Avi-Robusta b4f5e46
require_user_id returns None in server mode instead of raising
Avi-Robusta a0f0eb4
Retrigger Netlify deploy
Avi-Robusta File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,90 @@ | ||
| # OAuth MCP Servers | ||
|
|
||
| !!! warning "Alpha Feature" | ||
| OAuth MCP server support is a new feature and will experience rapid improvements. Configuration and behavior may change between releases. | ||
|
|
||
| Some MCP servers support OAuth-based authentication natively — you only need to set `oauth.enabled: true` and Holmes handles the rest. When Holmes connects to an OAuth-enabled MCP server, it automatically discovers the server's OAuth endpoints, opens a browser for login, and persists the token for future use. | ||
|
|
||
| ## Setup | ||
|
|
||
| To add an OAuth MCP server, set `mode: streamable-http` and `oauth.enabled: true` in the server's config: | ||
|
|
||
| === "Robusta CLI" | ||
|
|
||
| Set the `CUSTOM_TOOLSET_LOCATION` environment variable pointing to a YAML file with your MCP server configuration: | ||
|
|
||
| ```bash | ||
| export CUSTOM_TOOLSET_LOCATION=/Users/.../custom_toolset.yaml | ||
| ``` | ||
|
|
||
| In that file, define your OAuth MCP servers: | ||
|
|
||
| ```yaml | ||
| toolsets: | ||
| # ... your toolsets | ||
|
|
||
| mcp_servers: | ||
| my-server: | ||
| description: "Description of the MCP server" | ||
| config: | ||
| mode: streamable-http | ||
| url: https://example.com/mcp | ||
| oauth: | ||
| enabled: true | ||
| ``` | ||
|
|
||
| === "Robusta Helm Chart with Platform" | ||
|
|
||
| Add the MCP servers to your `generated_values.yaml`. Make sure `enableHolmesGPT` is set to `true` and SaaS is enabled: | ||
|
|
||
| ```yaml | ||
| holmes: | ||
| mcp_servers: | ||
| my-server: | ||
| description: "Description of the MCP server" | ||
| config: | ||
| mode: streamable-http | ||
| url: https://example.com/mcp | ||
| oauth: | ||
| enabled: true | ||
| ``` | ||
|
|
||
| ```bash | ||
| helm upgrade robusta robusta/robusta --values=generated_values.yaml --set clusterName=<YOUR_CLUSTER_NAME> | ||
| ``` | ||
|
|
||
| ## Example: Atlassian | ||
|
|
||
| === "Robusta CLI" | ||
|
|
||
| ```yaml | ||
| mcp_servers: | ||
| atlassian: | ||
| description: "Atlassian Jira + Confluence MCP server" | ||
| config: | ||
| mode: streamable-http | ||
| url: https://mcp.atlassian.com/v1/mcp | ||
| oauth: | ||
| enabled: true | ||
| ``` | ||
|
|
||
| === "Robusta Helm Chart with Platform" | ||
|
|
||
| ```yaml | ||
| holmes: | ||
| mcp_servers: | ||
| atlassian: | ||
| config: | ||
| mode: streamable-http | ||
| url: https://mcp.atlassian.com/v1/mcp | ||
| oauth: | ||
| enabled: true | ||
| ``` | ||
|
|
||
| ## How It Works | ||
|
|
||
| 1. Holmes detects that the MCP server has `oauth.enabled: true` | ||
| 2. Holmes discovers the server's OAuth configuration automatically via the MCP protocol | ||
| 3. The user is prompted to authenticate via their browser | ||
| 4. After login, Holmes exchanges the authorization code for an access token | ||
| 5. The token is persisted and refreshed automatically — users only need to authenticate once |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.