feat(mcp): record auth_mode and upstream resource on MCP tool-call logs

Adds mcp_auth_mode and mcp_server_resource to StandardLoggingMCPToolCall so a
relayed passthrough/delegate request can be attributed in an audit to its mode
and its upstream target without logging any credential. Both are non-sensitive
metadata derived from the resolved server; the admission and upstream tokens
stay SecretStr and are never logged.
This commit is contained in:
Tin 2026-07-08 14:34:20 -07:00
parent 98818df418
commit 1693761a51
2 changed files with 16 additions and 0 deletions

View file

@ -3064,6 +3064,8 @@ if MCP_AVAILABLE:
mcp_server_logo_url=mcp_info.get("logo_url"),
namespaced_tool_name=namespaced_tool_name,
mcp_session_id=session_id,
mcp_auth_mode=mcp_server.auth_type,
mcp_server_resource=mcp_server.url,
)
else:
return StandardLoggingMCPToolCall(

View file

@ -2523,6 +2523,20 @@ class StandardLoggingMCPToolCall(TypedDict, total=False):
the client is driving a stateful session. Absent for stateless calls.
"""
mcp_auth_mode: Optional[str]
"""
The server's auth_type for this call (e.g. `true_passthrough`, `oauth_delegate`,
`oauth2`). For the client-forwarded token modes this records that the caller's own
upstream token was relayed, so an audit can attribute a relayed request to its mode
without logging any credential.
"""
mcp_server_resource: Optional[str]
"""
The upstream MCP server URL (the RFC 8707 resource) the tool call was forwarded to.
Records which upstream received a relayed request; never a credential.
"""
class StandardLoggingVectorStoreRequest(TypedDict, total=False):
"""