docs: add an authenticated Streamable HTTP MCP example - #1009
Open
louisss1016 wants to merge 2 commits into
Open
louisss1016 wants to merge 2 commits into
louisss1016 wants to merge 2 commits into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change Summary
Adds an authenticated Streamable HTTP example to both the Chinese and English Tools pages, closing the gap where only an unauthenticated
sseexample was shown.The example stays generic — a placeholder host, no external service, no new SDK dependency, no new transport implementation. It only uses the existing
mcpServers/headers/includesurface.Each page gets the same three points, in the same order:
typeonly switches the transport forsseandwebsocket; everything else, including omittingtype, goes through Streamable HTTP.${VAR}is not substituted. Rather than implying otherwise, the example shows readingos.environin Python and assemblingheadersthere, and says explicitly that a real token should not go into a config file or version control.headersdoes not apply to websocket, and the stdioenv(passed to the child process) is unrelated to a remoteheaders(an HTTP request header). Both are easy to conflate and fail silently.Also documents that
includeandexcludeare mutually exclusive.Related issue number
Ref #1003 — that issue asks whether a generic placeholder example or a disclosed third-party service example is preferred. This PR implements the generic option, which the issue itself offers as an acceptable alternative. Happy to rework it if maintainers prefer the other direction, and happy to yield to the issue author.
Verification
Docs-only; no runtime behaviour changed. Every claim was checked against source at
a56afcc:ms_agent/tools/mcp_client.py—_open_transportspecial-cases onlysseandwebsocket, everything else falls through tostreamablehttp_client;headers=is passed for Streamable HTTP and SSE, and the websocket branch callswebsocket_client(url)only.ms_agent/config/config.py—convert_mcp_servers_to_jsondoesdeepcopy(server_config)with no key allowlist, soheaders/includewritten under a server in yaml reach the client verbatim.register_resolveroroc.envanywhere in the repo, which is why${VAR}interpolation is documented as unsupported rather than assumed._plan_serverassertsSet either include or exclude in tools config., the source of the mutual-exclusivity note.tests/tools/test_mcp_client.py, which is whereMCPClient({'mcpServers': {...}})andasync with MCPClient(...) as ...are already exercised.Checklist
pre-commit installandpre-commit run --all-filesbefore git commit, and passed lint check — not run locally: this sandbox has no PyPI access, sopre-commitandpytestcannot be installed. The two relevant hooks (trailing-whitespace,end-of-file-fixer, plusmixed-line-ending --fix=lf) were checked by hand: no trailing whitespace, LF endings, no tabs, trailing newline present on both files.lint.yamlrunspre-commit run --from-ref, i.e. changed files only, so unrelated files cannot affect this PR.Note: drafted with AI assistance. The source claims above were each read from the code rather than assumed, but the local test/lint run could not be performed here.