fastmcp.client.auth.client_credentials
Machine-to-machine (M2M) OAuth client authentication for FastMCP.
These providers authenticate a FastMCP client to a protected MCP server without
a browser, using the OAuth 2.0 client_credentials grant:
ClientCredentialsOAuthProviderauthenticates with aclient_idandclient_secret(the common M2M case).PrivateKeyJWTOAuthProviderauthenticates with an RFC 7523private_key_jwtclient assertion (workload identity federation, or a locally signed JWT).
OAuth provider, they can be constructed without an mcp_url and
bound to the server URL automatically when passed to Client(auth=...).
Classes
ClientCredentialsOAuthProvider
OAuth client_credentials provider using a client ID and secret.
This is the standard machine-to-machine flow: the client exchanges its
client_id and client_secret at the authorization server’s token
endpoint for an access token, which is then attached to every request. The
token endpoint is discovered from the MCP server’s OAuth metadata, so callers
provide the MCP server URL rather than a raw token endpoint.
Methods:
async_auth_flow
PrivateKeyJWTOAuthProvider
OAuth client_credentials provider using private_key_jwt (RFC 7523).
Instead of a shared client secret, the client authenticates to the token
endpoint with a signed JWT assertion. The assertion_provider callback
receives the authorization server’s issuer identifier (the required JWT
audience) and returns the assertion. Use
SignedJWTParameters.create_assertion_provider() to sign locally with a
private key, static_assertion_provider() for a pre-built JWT, or supply your
own callback for workload identity federation.
Methods:

