litellm/tests/test_litellm/proxy/_experimental/mcp_server
devin-ai-integration[bot] ce25856424
Some checks failed
CI Coverage / assert-ci-coverage (push) Waiting to run
CodeQL / Analyze (actions) (push) Waiting to run
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
CodSpeed Benchmarks / benchmarks (push) Waiting to run
Helm unit test / unit-test (push) Waiting to run
Publish basedpyright base counts / publish (push) Waiting to run
Scorecard supply-chain security / Scorecard analysis (push) Waiting to run
Code Quality Checks / code-quality (push) Waiting to run
Code Quality Checks / python-310-import-smoke (push) Waiting to run
UI Unit Tests / ui-unit-tests (push) Waiting to run
Postgres Tests / proxy-security (push) Waiting to run
Postgres Tests / schema-migration (push) Waiting to run
Postgres Tests / proxy-behavior (push) Waiting to run
LiteLLM Rust / rust-test (push) Waiting to run
LiteLLM Rust / rust-wheel (push) Waiting to run
LiteLLM Rust / rust-lint (push) Waiting to run
Unit Tests: Documentation Validation / documentation (push) Waiting to run
Unit Tests: Proxy DB Operations / assert-shard-coverage (push) Waiting to run
Unit Tests: Proxy DB Operations / auth-checks (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / budgets (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / custom-logging (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / db-and-spend (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / endpoints-and-responses (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / guardrails-hooks (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / jwt-and-keys (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / key-generation (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / logging-misc (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / proxy-runtime (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / proxy-server-core (push) Blocked by required conditions
Unit Tests: Proxy DB Operations / proxy-utils (push) Blocked by required conditions
Unit Tests / caching-local (push) Waiting to run
Unit Tests / core-utils (push) Waiting to run
Unit Tests / enterprise-package (push) Waiting to run
Unit Tests / enterprise-routing (push) Waiting to run
Unit Tests / integrations (push) Waiting to run
Unit Tests / All Other Providers (push) Waiting to run
Unit Tests / Vertex AI (push) Waiting to run
Unit Tests / mcp-integration (push) Waiting to run
Unit Tests / misc (push) Waiting to run
Unit Tests / proxy-auth (push) Waiting to run
Unit Tests / proxy-endpoints (push) Waiting to run
Unit Tests / proxy-extras (push) Waiting to run
Unit Tests / proxy-infra (push) Waiting to run
Unit Tests / proxy-server (push) Waiting to run
Unit Tests / responses-caching-types (push) Waiting to run
GitHub Actions Security Analysis / zizmor (push) Waiting to run
Terraform Provider / gofmt, vet, build, test (push) Has been cancelled
Terraform Provider / Provider endpoints vs proxy OpenAPI schema (push) Has been cancelled
feat(mcp): scan and pin upstream tool descriptions (#43283)
* feat(mcp): scan and pin upstream tool descriptions

Run every discovered MCP tool's description and input schema through the
pre_mcp_call guardrails before a listing reaches the client, drop the tools
a guardrail blocks, and serve the guardrail's masked text otherwise. Add
POST and DELETE /v1/mcp/server/{server_id}/pin so an admin can freeze a
server's tool names and descriptions; the gateway serves the pinned catalog
and raises a Slack alert with the diff when the upstream drifts.

* chore: sync schema.prisma copies from root

* fix(mcp): pin input schemas, scan before pinning, admin-only pin writes

* fix(mcp): apply overrides and the pin before the discovery scan, dedupe alerts before sending

The guardrail scan now runs on the text the client is about to see: description overrides are applied first, the pinned catalog next, and the scan last, so a masked pinned or override description is served masked and a pinned tool keeps serving its pinned text while the upstream's text is poisoned. The alert signature is recorded before the send and dropped only when that send fails, so a recovery during a slow send is never undone. A tool whose scan payload cannot be built is hidden alone instead of failing the listing. apply_tool_overrides shrinks to apply_display_name_overrides and the MagicMock servers in the MCP tests carry pinned_tools=None.

* fix(mcp): snapshot the pin through the REST module's unpinned catalog helper

* fix(mcp): pin the raw upstream catalog so an override never hides upstream description drift

* refactor(mcp): trim the tool catalog guard docstrings to one line

* test(mcp): cover guarded discovery boundaries and response definitions

* fix(mcp): bound discovery guardrail concurrency per catalog

* fix(mcp): scan tool catalogs in bounded parallel batches

* fix(mcp): hide pinned catalogs from restricted management views

---------

Co-authored-by: mateo-berri <277851410+mateo-berri@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Joshua Valluru <326636767+joshua-berri@users.noreply.github.com>
2026-09-28 18:38:49 -07:00
..
auth feat(mcp): allow ["*"] wildcard in mcp_tool_permissions to grant all current and future tools (#43108) 2026-09-24 21:34:57 -07:00
faults test(mcp): update MCP suites for SDK 2 APIs 2026-09-18 22:13:18 +00:00
guardrail_translation feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
outbound_credentials test(mcp): update MCP suites for SDK 2 APIs 2026-09-18 22:13:18 +00:00
conftest.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_byok_credential_cache.py fix(caching): propagate auth cache invalidation over Redis Cluster via a node-level pub/sub client (#43110) 2026-09-25 07:56:46 -07:00
test_byok_oauth_endpoints.py fix(proxy): revoke UI session tokens on logout and password change (#42463) 2026-09-23 10:31:38 +02:00
test_callback_oauth_error_responses.py Litellm oss staging 250526 (#28770) 2026-05-26 11:57:39 -07:00
test_capabilities.py feat(mcp): configure protocol versions and capability discovery (#43169) 2026-09-25 13:13:52 -07:00
test_client_allowlist.py feat(mcp): give each allowed MCP client an alias and a value 2026-09-18 22:29:17 +00:00
test_contracts.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_db_credentials.py feat(mcp): let proxy admins force-close live MCP sessions and revoke stored user credentials 2026-09-18 01:01:26 +00:00
test_discoverable_endpoints.py fix(mcp): preserve credential authority in DCR bridge authentication (#42563) 2026-09-22 18:09:52 -07:00
test_gateway_dcr_flow.py fix(proxy): answer 503 temporarily_unavailable when the token exchange cannot verify the subject token 2026-09-17 16:39:02 -07:00
test_idp_token_exchange.py fix(proxy): word the token exchange's 503 by whether the database fault can clear 2026-09-17 17:20:17 -07:00
test_is_tool_name_prefixed.py style: run black formatter on files from main merge 2026-04-17 13:02:59 -07:00
test_jwt_mcp_enforcement.py fix(mcp): resolve team.access_group_ids → MCP servers (#28997) 2026-05-27 12:36:50 -07:00
test_jwt_mcp_simple.py fix(mcp): resolve team.access_group_ids → MCP servers (#28997) 2026-05-27 12:36:50 -07:00
test_mcp_block_recording.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_cost_calculator.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_mcp_custom_fields.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_mcp_debug.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_mcp_discovery.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_mcp_elicitation_handler.py test(mcp): update MCP suites for SDK 2 APIs 2026-09-18 22:13:18 +00:00
test_mcp_env_vars.py fix(mcp): report reachability without stored credentials (#43240) 2026-09-26 16:44:49 -07:00
test_mcp_guardrail_usage_monitor.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_header_alias_utils.py feat(mcp): use x-mcp-<access_group>-* headers as default upstream credentials for group members (#39717) 2026-09-04 12:45:24 -07:00
test_mcp_hook_extra_headers.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_mcp_max_concurrent_requests.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_mcp_metadata_preservation.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_mcp_oauth_passthrough.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_mcp_oauth_passthrough_cold_start.py test: drop the cwd-relative sys.path.insert calls from the test suite (#37802) 2026-08-22 09:25:58 -07:00
test_mcp_oauth_passthrough_tools.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_partial_update.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_proxy_mode.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_sampling_completion_flow.py test(mcp): update MCP suites for SDK2 handler signatures and ctx var 2026-09-18 23:34:30 +00:00
test_mcp_sampling_model_access.py test(mcp): update MCP suites for SDK 2 APIs 2026-09-18 22:13:18 +00:00
test_mcp_sampling_model_resolution.py Litellm oss staging 040626 (#29671) 2026-06-04 11:07:20 -07:00
test_mcp_sampling_priority_selection.py Litellm oss staging 040626 (#29671) 2026-06-04 11:07:20 -07:00
test_mcp_sampling_request_builder.py Litellm oss staging 040626 (#29671) 2026-06-04 11:07:20 -07:00
test_mcp_sampling_response_conversion.py test(mcp): update MCP suites for SDK2 handler signatures and ctx var 2026-09-18 23:34:30 +00:00
test_mcp_sampling_tool_conversion.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_mcp_server.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_server_identity_env.py test: trim mcp fixture docstring and reload comment 2026-09-01 11:06:08 +00:00
test_mcp_server_manager.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_session_logging.py Add MCP semantic conventions to otelv2 (#29468) 2026-06-02 11:45:36 -07:00
test_mcp_sigv4_auth.py feat(mcp): scan and pin upstream tool descriptions (#43283) 2026-09-28 18:38:49 -07:00
test_mcp_stale_session.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_tool_search.py refactor(mcp): extract explicit operation context and dispatch 2026-09-21 12:24:15 -07:00
test_mcp_toolset_scope.py test(mcp): preserve toolset scope across explicit context 2026-09-21 12:31:48 -07:00
test_oauth2_flow_backfill.py feat(mcp): startup backfill stamping oauth2_flow on legacy null rows (#32290) 2026-07-06 18:42:08 -07:00
test_oauth2_token_cache.py test(mcp): give the new cache and tombstone patches TQ008 reasons and match the keyword eviction call 2026-09-18 02:49:41 +00:00
test_oauth_identity_binding.py fix(mcp): preserve identity checks across cached OAuth credentials 2026-09-10 13:08:46 -07:00
test_oauth_issuer_stamp_backfill.py fix(mcp): never write discovery results to the row, heal rows a release already stamped, and retry failed discovery with backoff 2026-07-29 17:51:22 -07:00
test_openapi_to_mcp_generator.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_openapi_tool_auth.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_operations.py feat(mcp): configure protocol versions and capability discovery (#43169) 2026-09-25 13:13:52 -07:00
test_proxy_api_credentials.py fix(proxy): evict the member's cached user row on team member add 2026-09-16 16:31:28 -07:00
test_rest_endpoints.py feat(mcp): configure protocol versions and capability discovery (#43169) 2026-09-25 13:13:52 -07:00
test_result_conversion.py feat(mcp): share compatibility-aware result conversion across tool surfaces (#43089) 2026-09-25 06:51:28 -07:00
test_semantic_tool_filter.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_server_resolution.py refactor(mcp): add shared server resolver without changing callers (#43262) 2026-09-26 13:01:37 -07:00
test_short_mcp_tool_prefix.py fix(mcp): preserve legacy behavior on SDK2 and streamline verification 2026-09-18 22:28:31 -07:00
test_ui_session_utils.py fix(mcp): deny the interactive dcr_bridge authorize for a user without server access (#37865) 2026-08-21 12:27:00 -07:00
test_utils.py fix(mcp): preserve discovery attribution and sanitize logging headers (#42541) 2026-09-22 14:26:48 -07:00