+
    Q(i?                    ^   ^ RI Ht ^ RIt^ RIt^ RIHt ^ RIHt ^ RIH	t	 ^ RI
t
^ RIt^ RIHt ^ RIHt ^ RIHt ^ R	IHtHt ^ R
IHt ^ RIHtHtHt ^ RIHt ^ RIHt ^ RIH t  ^ RI!H"t"H#t# ^ RI$H%t% ^ RI&H't' R.t(]'! ])4      t* ! R R]+4      t,RR R llt- ! R R]4      t. ! R R]4      t/R# )    )annotationsN)AsyncGenerator)aclosing)Any)PydanticAdapter)AsyncKeyValue)MemoryStore)OAuthClientProviderTokenStorage)McpHttpClientFactory)OAuthClientInformationFullOAuthClientMetadata
OAuthToken)
AnyHttpUrl)override)Server)OAuthCallbackResultcreate_oauth_callback_server)find_available_port)
get_loggerOAuthc                      ] tR t^%tRtRtR# )ClientNotFoundErrorzARaised when OAuth client credentials are not found on the server. N)__name__
__module____qualname____firstlineno____doc____static_attributes__r       _/Users/agent/.openclaw/workspace/venv/lib/python3.14/site-packages/fastmcp/client/auth/oauth.pyr   r   %   s    Kr!   r   c               $    V ^8  d   QhRRRRRR/# )   mcp_urlstrhttpx_kwargsdict[str, Any] | Nonereturnboolr   )formats   "r"   __annotate__r,   )   s$       5	r!   c                  "   \         P                  ! R/ T;'       g    / B ;_uu_4       GRj  xL
 p VP                  V RR7      G Rj  xL
 pVP                  R9   d    RRR4      GRj  xL
  R# RVP                  9   d    RRR4      GRj  xL
  R#  RRR4      GRj  xL
  R#  L{ La LA L L  \         P
                   d     RRR4      GRj  xL 
  R# i ; i  + GRj  xL 
 '       g   i     R# ; i5i)	z
Check if the MCP endpoint requires authentication by making a test request.

Returns:
    True if auth appears to be required, False otherwise
Ng      @)timeoutTzWWW-AuthenticateFr   )i  i  )httpxAsyncClientgetstatus_codeheadersRequestError)r%   r'   clientresponses   &&  r"   check_if_auth_requiredr7   )   s        8L$6$6B888F	#ZZZ==H ##z1 988 "X%5%55 988  988 > 9  !! 	% 988 	! 9888s   -C?B+C?C"B5B-B5"C?-B/.C?4B5C?B1C?C?$B3%C?-B5/C?1C?3C?5C
C"C?CC?CC""C<	(C+)
C<	4C<	6	C?c                      ] tR t^Gt$ R]R&   R]R&   R]R&   R]R&   R	 R
 ltR R ltR R ltR R lt]	R R l4       t
]	R R l4       t]	R R l4       t]	R R l4       tRtR# )TokenStorageAdapterr&   _server_urlr   _key_value_storezPydanticAdapter[OAuthToken]_storage_oauth_tokenz+PydanticAdapter[OAuthClientInformationFull]_storage_client_infoc                    V ^8  d   QhRRRR/# )r$   async_key_valuer   
server_urlr&   r   )r+   s   "r"   r,    TokenStorageAdapter.__annotate__M   s     
 
 
3 
r!   c                	    W n         Wn        \        \        ,          ! R V\        RR7      V n        \        \
        ,          ! RV\
        RR7      V n        R# )zmcp-oauth-tokenT)default_collection	key_valuepydantic_modelraise_on_validation_errorzmcp-oauth-client-infoN)r:   r;   r   r   r<   r   r=   )selfr?   r@   s   &&&r"   __init__TokenStorageAdapter.__init__M   sM    % /$3J$?0%%&*	%
! %44N$O6%5&*	%
!r!   c                   V ^8  d   QhRR/# r$   r)   r&   r   )r+   s   "r"   r,   rA   ]   s     , ,c ,r!   c                	     V P                    R 2# )z/tokensr:   rG   s   &r"   _get_token_cache_key(TokenStorageAdapter._get_token_cache_key]   s    ""#7++r!   c                   V ^8  d   QhRR/# rK   r   )r+   s   "r"   r,   rA   `   s     1 1C 1r!   c                	     V P                    R 2# )z/client_inforM   rN   s   &r"   _get_client_info_cache_key.TokenStorageAdapter._get_client_info_cache_key`   s    ""#<00r!   c                   V ^8  d   QhRR/# r$   r)   Noner   )r+   s   "r"   r,   rA   c   s     V VT Vr!   c                	   "   V P                   P                  V P                  4       R 7      G Rj  xL
  V P                  P                  V P	                  4       R 7      G Rj  xL
  R#  L8 L5i)keyN)r<   deleterO   r=   rS   rN   s   &r"   clearTokenStorageAdapter.clearc   sZ     ''..43L3L3N.OOO''..43R3R3T.UUU 	PUs!   .A-A)1A-"A+#A-+A-c                   V ^8  d   QhRR/# )r$   r)   zOAuthToken | Noner   )r+   s   "r"   r,   rA   h   s     T T"3 Tr!   c                	r   "   V P                   P                  V P                  4       R 7      G Rj  xL
 #  L5irY   )r<   r1   rO   rN   s   &r"   
get_tokensTokenStorageAdapter.get_tokensg   s.     ..22t7P7P7R2SSSS   .757c                    V ^8  d   QhRRRR/# )r$   tokensr   r)   rW   r   )r+   s   "r"   r,   rA   l   s     
 
z 
d 
r!   c                	z   "   V P                   P                  V P                  4       VRR7      G Rj  xL
  R#  L5i)<   rZ   valuettlNi3)r<   putrO   )rG   rd   s   &&r"   
set_tokensTokenStorageAdapter.set_tokensk   s<     
 ''++))+" , 
 	
 	
s   0;9;c                   V ^8  d   QhRR/# )r$   r)   z!OAuthClientInformationFull | Noner   )r+   s   "r"   r,   rA   w   s     
 
'H 
r!   c                	r   "   V P                   P                  V P                  4       R 7      G Rj  xL
 #  L5irY   )r=   r1   rS   rN   s   &r"   get_client_info#TokenStorageAdapter.get_client_infov   s9     ..22//1 3 
 
 	
 
rb   c                    V ^8  d   QhRRRR/# )r$   client_infor   r)   rW   r   )r+   s   "r"   r,   rA   }   s     

 

1K 

PT 

r!   c                	   "   R pVP                   '       d0   VP                   \        \        P                  ! 4       4      ,
          pV P                  P	                  V P                  4       VVR7      G R j  xL
  R #  L5i)Nrg   )client_secret_expires_atinttimer=   rj   rS   )rG   rr   ri   s   && r"   set_client_info#TokenStorageAdapter.set_client_info|   sf     ///66TYY[9IIC''++//1 , 
 	
 	
s   A3A>5A<6A>)r;   r:   r=   r<   N)r   r   r   r   __annotations__rH   rO   rS   r\   r   r`   rk   ro   rw   r    r   r!   r"   r9   r9   G   s    ##55EE
 ,1V T T 
 
 
 

 

 

r!   r9   c                     a  ] tR t^t$ RtR]R&   RR R lltR V 3R lltR V 3R	 lltR
 R lt	R R lt
R V 3R lltRtV ;t# )r   z
OAuth client provider for MCP servers with browser-based authentication.

This class provides OAuth authentication for FastMCP clients by opening
a browser for user authorization and running a local callback server.
r*   _boundc               @    V ^8  d   QhRRRRRRRRR	R
RRRRRRRRRR/
# )r$   r%   z
str | Nonescopeszstr | list[str] | Noneclient_namer&   token_storagezAsyncKeyValue | Noneadditional_client_metadatar(   callback_portz
int | Nonehttpx_client_factoryzMcpHttpClientFactory | Noneclient_metadata_url	client_idclient_secretr   )r+   s   "r"   r,   OAuth.__annotate__   sn     3  3 3  '3  	3 
 ,3  %:3  "3  :3  (3  3  "3 r!   c                    W n         W0n        W@n        WPn        W`n        Wn        Wn        Wn        RV n        T;'       g    \        P                  V n        RV n        Ve   V P                  V4       R# R# )a  
Initialize OAuth client provider for an MCP server.

Args:
    mcp_url: Full URL to the MCP endpoint (e.g. "http://host/mcp/sse/").
        Optional when OAuth is passed to Client(auth=...), which provides
        the URL automatically from the transport.
    scopes: OAuth scopes to request. Can be a
    space-separated string or a list of strings.
    client_name: Name for this client during registration
    token_storage: An AsyncKeyValue-compatible token store, tokens are stored in memory if not provided
    additional_client_metadata: Extra fields for OAuthClientMetadata
    callback_port: Fixed port for OAuth callback (default: random available port)
    client_metadata_url: A CIMD (Client ID Metadata Document) URL. When
        provided, this URL is used as the client_id instead of performing
        Dynamic Client Registration. Must be an HTTPS URL with a non-root
        path (e.g. "https://myapp.example.com/oauth/client.json").
    client_id: Pre-registered OAuth client ID. When provided, skips dynamic
        client registration and uses these static credentials instead.
    client_secret: OAuth client secret (optional, used with client_id)
NF)_scopes_client_name_token_storage_additional_client_metadata_callback_port_client_metadata_url
_client_id_client_secret_static_client_infor/   r0   r   r{   _bind)rG   r%   r}   r~   r   r   r   r   r   r   r   s   &&&&&&&&&&&r"   rH   OAuth.__init__   so    L '++E(+$7!#+#' $8$M$ME<M<M!JJw r!   c                    V ^8  d   QhRRRR/# )r$   r%   r&   r)   rW   r   )r+   s   "r"   r,   r      s     L LS LT Lr!   c                  < V P                   '       d   R# VP                  R4      pV P                  ;'       g    \        4       V n        RV P                   R2p\        V P                  \        4      '       d   RP                  V P                  4      pM&V P                  e   \        V P                  4      pMRp\        RRV P                  R\        V4      .R	R
R.RR.RV/V P                  ;'       g    / B pV P                  '       d[   VP                  RR7      pRV9  d   V P                   '       d   RMRVR&   \#        RRV P                  RV P                   /VB V n        V P&                  ;'       g    \)        4       p\        V\(        4      '       d   ^ RIHp V! R^R7       \/        WaR7      V n        Wn        \4        SV `m  VVV P0                  V P8                  V P:                  V P<                  R7       RV n         R# )zBind this OAuth provider to a specific MCP server URL.

Called automatically when mcp_url is provided to __init__, or by the
transport when OAuth is used without an explicit URL.
N/zhttp://localhost:z	/callback  r~   redirect_urisgrant_typesauthorization_coderefresh_tokenresponse_typescodescopeT)exclude_nonetoken_endpoint_auth_methodclient_secret_postnoner   r   )warn)message
stacklevel)r?   r@   )r@   client_metadatastorageredirect_handlercallback_handlerr   r   zUsing in-memory token storage -- tokens will be lost when the client restarts. For persistent storage across multiple MCP servers, provide an encrypted AsyncKeyValue backend. See https://gofastmcp.com/clients/auth/oauth#token-storage for details.)r{   rstripr   r   redirect_port
isinstancer   listjoinr&   r   r   r   r   r   
model_dumpr   r   r   r   r	   warningsr   r9   token_storage_adapterr%   superrH   r   r   r   )	rG   r%   redirect_uri
scopes_strr   metadatar   r   	__class__s	   &&      r"   r   OAuth._bind   s    ;;;..%!00II4G4I*4+=+=*>iH dllD))$,,/J\\%T\\*JJ- 
))
%l34
 .?
 #8	

 
 //552
 ??? '11t1DH ,8;,0,?,?,?(V 56 (B (//("11( (D$ ++<<{}m[11%\ 	 ;N);
" +..!22!22 $ 9 9 	 	
 r!   c                   V ^8  d   QhRR/# rV   r   )r+   s   "r"   r,   r     s     	J 	J4 	Jr!   c                  <"   \         SV `  4       G Rj  xL
  V P                  eI   V P                  V P                  n        V P
                  P                  V P                  4      G Rj  xL
  V P                  P                  '       dZ   V P                  P                  P                  '       d2   V P                  P                  V P                  P                  4       R# R# R#  L L}5i)zBLoad stored tokens and client info, properly setting token expiry.N)
r   _initializer   contextrr   r   rw   current_tokens
expires_inupdate_token_expiry)rG   r   s   &r"   r   OAuth._initialize  s     g!#####/'+'?'?DLL$,,<<T=U=UVVV<<&&&4<<+F+F+Q+Q+QLL,,T\\-H-HI ,R& 	$ Ws.   C+C'AC++C),C+%C+26C+)C+c                    V ^8  d   QhRRRR/# )r$   authorization_urlr&   r)   rW   r   )r+   s   "r"   r,   r   "  s     + + + +r!   c                  "   V P                  4       ;_uu_4       GRj  xL
 pVP                  VRR7      G Rj  xL
 pVP                  R8X  d   \        R4      hVP                  R9  d   \	        RVP                   24      hRRR4      GRj  xL
  \
        P                  RV 24       \        P                  ! V4       R#  L L L8  + GRj  xL 
 '       g   i     LO; i5i)	zIOpen browser for authorization, with pre-flight check for invalid client.NF)follow_redirectsi  z8OAuth client not found - cached credentials may be stalez#Unexpected authorization response: zOAuth authorization URL: )   i.  i/  i3  i4  )	r   r1   r2   r   RuntimeErrorloggerinfo
webbrowseropen)rG   r   r5   r6   s   &&  r"   r   OAuth.redirect_handler"  s      ,,...&#ZZ(9EZRRH ##s*)N 
 ##+DD"9(:N:N9OP  /. 	/0A/BCD)*! /R /...s[   C&CC&C
CA	C
C&C5C&C
C&
C#	C
C#	C#	C&c                   V ^8  d   QhRR/# )r$   r)   ztuple[str, str | None]r   )r+   s   "r"   r,   r   7  s     %J %J(> %Jr!   c           	       "   \        4       p\        P                  ! 4       p\        V P                  V P
                  VVR7      p\        P                  ! 4       ;_uu_4       GRj  xL
 pVP                  VP                  4       \        P                  RV P                   24       Rp \        P                  ! V4      ;_uu_ 4        VP                  4       G Rj  xL
  VP                  '       d   VP                  hVP                  VP                  3uuRRR4       RVn        \        P"                  ! R4      G Rj  xL
  VP$                  P'                  4        uuRRR4      GRj  xL
  #  EL L L6 L  + '       g   i     M&; i  \(         d   p\)        RT R24      ThRp?ii ; i RTn        \        P"                  ! R4      G Rj  xL 
  TP$                  P'                  4        ME  RTn        \        P"                  ! R4      G Rj  xL 
  TP$                  P'                  4        i ; iRRR4      GRj  xL 
  M  + GRj  xL 
 '       g   i     M; i\+        R	4      h5i)
z4Handle OAuth callback and return (auth_code, state).)portr@   result_containerresult_readyNu7   🎧 OAuth callback server started on http://localhost:g     r@Tg?zOAuth callback timed out after z secondsz+OAuth callback handler could not be started)r   anyioEventr   r   r%   create_task_group
start_soonserver   r   
fail_afterwaiterrorr   stateshould_exitsleepcancel_scopecancelTimeoutErrorr   )rG   resultr   servertgTIMEOUTes   &      r"   r   OAuth.callback_handler7  s     %&{{} 6##||#%	
 **,,,MM&,,'KKI$J\J\I]^ G)%%g..&++---|||$ll*!;;4	 /. &*"kk#&&&&&() -,, . '' - /.
   "5gYhG / &*"kk#&&&&&( &*"kk#&&&&&() -,,,,,, HIIs   A$I2&E3'I2*A I+F	E<	E6E<	4#E<	
F! IE8
I I2-E:.I26E<	8I:I2<FFG4FF/F**F//G43 IG I4!H6H H66I9I2II2I$	I
I$	I$	I2c                    V ^8  d   QhRRRR/# )r$   requestzhttpx.Requestr)   z-AsyncGenerator[httpx.Request, httpx.Response]r   )r+   s   "r"   r,   r   ^  s     2 2$2	62r!   c           	    `  <"   V P                   '       g   \        R4      h \        \        SV `  V4      4      ;_uu_4       GRj  xL
 pRp  VP                  V4      G Rj  xL
 pV5x pK"   L( L  \         d     Mi ; iRRR4      GRj  xL 
  R#   + GRj  xL 
 '       g   i     R# ; i  \         d    T P                  e   \        R4      Rh\        P                  R4       RT n        T P                  P                  4       G Rj  xL 
  \        \        ST `  T4      4      ;_uu_4       GRj  xL 
 pRp  TP                  T4      G Rj  xL 
 pT5x pK#    \         d     Mi ; iRRR4      GRj  xL 
   R#   + GRj  xL 
 '       g   i      R# ; ii ; i5i)zHTTPX auth flow with automatic retry on stale cached credentials.

If the OAuth flow fails due to invalid/stale client credentials,
clears the cache and retries once with fresh registration.
zOAuth provider has no server URL. Either pass mcp_url to OAuth() or use it with Client(auth=...) which provides the URL automatically.NzOAuth server rejected the static client credentials. Verify that the client_id (and client_secret, if provided) are correct and that the client is registered with the server.z@OAuth client not found on server, clearing cache and retrying...F)r{   r   r   r   async_auth_flowasendStopAsyncIterationr   r   r   debug_initializedr   r\   )rG   r   genr6   yielded_requestr   s   &&   r"   r   OAuth.async_auth_flow^  sr     {{{X %	 7 @AAAS03		(0C*C)8#8 B
 +D-  BAAAAA # 	 ''3)U 	 LLR !&D,,22444   7 @AAAS03		(0C*C*C)8#8-  BAAAAA%	s7  F.$B4 A/B4 
BA3#A1$	A3-B/B4 1A33B>B BBB4 BB4 F.B1	B 
B1	)B1	+B4 /F.1B4 4AF+D)F+<D?
=F+FE'E

E'%F'E5	2F4E5	5F8F+FF+	F.F'F
F'F' F+$F.'F++F.)r   r{   r   r   r   r   r   r   r   r   r   r   r%   r   r   )
NNzFastMCP ClientNNNNNNN)r   r   r   r   r   ry   rH   r   r   r   r   r   r    __classcell__)r   s   @r"   r   r      sD     L3 jL L\	J 	J+*%JN2 2r!   )N)0
__future__r   rv   r   collections.abcr   
contextlibr   typingr   r   r/   key_value.aio.adapters.pydanticr   key_value.aio.protocolsr   key_value.aio.stores.memoryr	   mcp.client.authr
   r   mcp.shared._httpx_utilsr   mcp.shared.authr   r   r   pydanticr   typing_extensionsr   uvicorn.serverr   fastmcp.client.oauth_callbackr   r   fastmcp.utilities.httpr   fastmcp.utilities.loggingr   __all__r   r   	Exceptionr   r7   r9   r   r   r!   r"   <module>r     s    "   *     ; 1 3 = 8 
   & ! 7 0)	H	L) L<@
, @
FF Fr!   