Skip to main content

Module security

Module security 

Source
Expand description

Request identity, authorization, and rate-limiting primitives.

These controls live above the transport layer so the same policy is applied to STDIO, HTTP, WebSocket, and custom transports.

Structs§

AllowAllAuthorizer
Backwards-compatible authorizer used unless an application installs RBAC.
Permission
One fine-grained role permission. Patterns support exact values or a final *, for example tools/* and urn:customer:*.
Principal
Authenticated identity attached to an MCP request.
RateLimitConfig
Token-bucket limit applied independently to each principal and method.
RateLimiter
Concurrent in-process token-bucket limiter.
RbacAuthorizer
Deny-by-default role-based authorizer.
RequestContext
Context shared by validation, policy, observability, and request handlers.
RequestPolicy
Shared server request policy.
RequestTarget
Normalized target used by authorization policies.

Traits§

Authorizer
Authorization decision provider.