From ffab631778d66c704d4226b04c41f893d1e3e7f8 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Fri, 13 Feb 2026 11:05:35 -0800 Subject: [PATCH] feat(mcp): add token exchange fields to MCPServer model Adds `token_exchange_endpoint`, `audience`, and `subject_token_type` fields plus `has_token_exchange_config` property to MCPServer for determining when OBO token exchange should be used. Co-Authored-By: Claude Opus 4.6 --- litellm/types/mcp_server/mcp_server_manager.py | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/litellm/types/mcp_server/mcp_server_manager.py b/litellm/types/mcp_server/mcp_server_manager.py index 2cd385c5bf6..ca63f33bb04 100644 --- a/litellm/types/mcp_server/mcp_server_manager.py +++ b/litellm/types/mcp_server/mcp_server_manager.py @@ -46,6 +46,10 @@ class MCPServer(BaseModel): authorization_url: Optional[str] = None token_url: Optional[str] = None registration_url: Optional[str] = None + # Token Exchange (OBO) fields — RFC 8693 + token_exchange_endpoint: Optional[str] = None + audience: Optional[str] = None + subject_token_type: str = "urn:ietf:params:oauth:token-type:access_token" # Stdio-specific fields command: Optional[str] = None args: Optional[List[str]] = None @@ -65,3 +69,12 @@ class MCPServer(BaseModel): def needs_user_oauth_token(self) -> bool: """True if this is an OAuth2 server that relies on per-user tokens (no client_credentials).""" return self.auth_type == MCPAuth.oauth2 and not self.has_client_credentials + + @property + def has_token_exchange_config(self) -> bool: + """True if this server is configured for OAuth2 token exchange (OBO / RFC 8693).""" + return ( + self.auth_type == MCPAuth.oauth2_token_exchange + and bool(self.client_id and self.client_secret) + and bool(self.token_exchange_endpoint or self.token_url) + )