Skip to content

fix: allow opting out of Mcp-Param-* validation (avoids a full tools/list per tools/call) - #3599

Closed
KaiyiQuan wants to merge 1 commit into
modelcontextprotocol:mainfrom
KaiyiQuan:fix/3565-mcp-param-validation-optout
Closed

KaiyiQuan wants to merge 1 commit into
modelcontextprotocol:mainfrom
KaiyiQuan:fix/3565-mcp-param-validation-optout

Conversation

@KaiyiQuan

Copy link
Copy Markdown

Fixes #3565.

Problem

On the 2026-07-28 HTTP path, every tools/call with arguments runs the server's full tools/list handler before dispatch (_mcp_param_rejection → _tool_input_schema) to resolve the called tool's inputSchema for Mcp-Param-* header validation. There is no way to opt out, and it runs even when no tool declares x-mcp-header.

For a server whose tools/list is expensive — e.g. a gateway aggregating several backend MCP servers where listing fans out per-user credentials — this is a large per-call cost on every single tools/call.

Change

Add an explicit opt-out on the lowlevel Server:

Server(..., mcp_param_validation=False, ...)

When False, the schema-resolving tools/list walk is skipped entirely and tools/call dispatches directly. Default remains True, so every existing Mcp-Param-* validation behavior is unchanged (missing-header rejection, mismatch rejection, orphan/duplicate header rejection all still fire). The McpServer wrapper delegates to the same app, so the flag is honored there too.

Tests

  • test_modern_tools_call_skips_tools_list_when_mcp_param_validation_opted_out: with the flag off, an argument-bearing tools/call returns 200 and the tools/list handler is never invoked (list_calls == 0).
  • test_modern_tools_call_runs_tools_list_by_default_for_validation: with the flag on (default), the missing-header rejection for an annotated argument still returns 400 HEADER_MISMATCH.

Full suite: 5893 passed.

Every argument-bearing tools/call resolves the called tool's inputSchema by
running the full tools/list handler (_mcp_param_rejection -> _tool_input_schema).
For a server whose tools/list is expensive (e.g. a gateway aggregating backend
servers), that is a large per-call cost even when no tool declares x-mcp-header.

Add Server(mcp_param_validation=False) to skip the schema-resolving walk while
keeping the default behavior (and all existing validation) untouched. The flag
lives on the lowlevel Server and is honored by the modern single-exchange HTTP
path; the McpServer wrapper delegates to the same app.

Regression tests: with the flag off, an argument-bearing tools/call dispatches
without invoking the tools/list handler (list_calls == 0); with the flag on,
the missing-header rejection still fires.
Copilot AI balanced review requested due to automatic review settings September 30, 2026 13:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions github-actions Bot added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Sep 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3565.

If a maintainer assigns you to #3565, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take.

You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way.

CONTRIBUTING.md has the full reasoning, but in short:

  • We're a small team with very little capacity to review community PRs right now.
  • Many recent PRs are AI-generated with little human review, and reviewing one carefully still costs a maintainer as much time as it ever did. A well-described issue is usually more useful to us than the code.

Maintainers: reopen, remove missing-issue-link, or add bypass-issue-check to override.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Mcp-Param-* validation runs the full tools/list handler on every tools/call

2 participants