Expand description
Request identity, authorization, and rate-limiting primitives.
These controls live above the transport layer so the same policy is applied to STDIO, HTTP, WebSocket, and custom transports.
Structs§
- Allow
AllAuthorizer - Backwards-compatible authorizer used unless an application installs RBAC.
- Permission
- One fine-grained role permission. Patterns support exact values or a final
*, for exampletools/*andurn:customer:*. - Principal
- Authenticated identity attached to an MCP request.
- Rate
Limit Config - Token-bucket limit applied independently to each principal and method.
- Rate
Limiter - Concurrent in-process token-bucket limiter.
- Rbac
Authorizer - Deny-by-default role-based authorizer.
- Request
Context - Context shared by validation, policy, observability, and request handlers.
- Request
Policy - Shared server request policy.
- Request
Target - Normalized target used by authorization policies.
Traits§
- Authorizer
- Authorization decision provider.