Skip to main content

Crate pmcp_server_toolkit

Crate pmcp_server_toolkit 

Source
Expand description

Runtime library for config-driven MCP servers.

pmcp-server-toolkit lifts the operational glue that pmcp-run servers share — auth providers, secrets resolution, static resources/prompts, a [[tools]] synthesizer, and code-mode wiring — into the public SDK.

Phase 83 ships the empty crate skeleton; subsequent plans land the functionality across these modules:

  • auth — AuthProvider implementations (StaticAuthProvider, BearerAuthProvider).
  • secrets — SecretsProvider trait + env/AWS implementations and the SecretValue newtype that never leaks via Debug/Display/Serialize.
  • config — ServerConfig types with #[serde(deny_unknown_fields)] strictness.
  • prompts — StaticPromptHandler adapter for static prompt templates.
  • resources — StaticResourceHandler adapter for shipped resources.
  • tools — synthesize_from_config builder turning [[tools]] into runtime handlers.
  • sql — SqlConnector trait + dialect enum for backend-agnostic SQL toolkits.
  • builder_ext — ServerBuilderExt extension methods on pmcp::ServerBuilder.
  • code_mode (feature code-mode) — re-exports from pmcp-code-mode plus toolkit glue.
  • error — ToolkitError enum and the crate-level Result<T> alias.

The public module set is locked by Phase 83 decision D-15. See the .planning/phases/83-toolkit-core-lift-pmcp-server-toolkit/ design log for the architectural responsibility map and review notes.

Re-exports§

pub use error::Result;
pub use error::ToolkitError;
pub use crate::auth::StaticAuthProvider;
pub use crate::secrets::EnvSecrets;
pub use crate::secrets::SecretValue;
pub use crate::secrets::SecretsProvider;
pub use crate::secrets::SecretsProviderChain;
pub use crate::secrets::OrgSecretsManagerProvider;
pub use crate::secrets::SecretsManagerSecrets;
pub use crate::secrets::SsmSecrets;
pub use crate::resources::StaticResourceHandler;
pub use crate::prompts::StaticPromptHandler;
pub use crate::prompts::prompt_handlers_from_config;
pub use crate::config::ServerConfig;
pub use crate::error::ConfigValidationError;
pub use crate::tools::synthesize_from_config;
pub use crate::tools::synthesize_from_config_with_connector;
pub use crate::tools::synthesize_from_config_with_http_connector;
pub use crate::tools::synthesize_from_config_with_http_connector_and_hooks;
pub use crate::tools::synthesize_from_config_and_hooks;
pub use crate::tools::synthesize_from_config_with_connector_and_hooks;
pub use crate::tools::synthesize_from_config_with_http_connector_and_scripts;
pub use crate::tools::synthesize_from_config_with_http_connector_and_scripts_and_hooks;
pub use crate::builder_ext::ServerBuilderExt;
pub use crate::sql::ConnectorError;
pub use crate::sql::Dialect;
pub use crate::sql::SqlConnector;
pub use crate::policy::emit_validation_report;
pub use crate::policy::render_validation_report;
pub use crate::policy::ArgumentRefusal;
pub use crate::policy::ArgumentValidator;
pub use crate::policy::ArgumentValidators;
pub use crate::policy::OutboundRequest;
pub use crate::policy::PolicyRefusal;
pub use crate::policy::ReportLevel;
pub use crate::policy::ReportLine;
pub use crate::policy::RequestPolicy;
pub use crate::policy::ToolkitHooks;
pub use crate::http::HttpConnector;
pub use crate::http::HttpConnectorError;
pub use crate::http::Operation;
pub use crate::http::auth::create_auth_provider;
pub use crate::http::auth::AuthConfig;
pub use crate::http::HttpClient;
pub use crate::workbook::WorkbookBuilderExt;
pub use crate::code_mode::assemble_code_mode_prompt;
pub use crate::code_mode::assemble_code_mode_prompt_with_schema;

Modules§

auth
AuthProvider impls for the toolkit — bearer-token-based static auth suitable for dev/test environments. Production callers should use pmcp’s OAuth/JWT providers instead.
builder_ext
Builder extension trait for pmcp::ServerBuilder — connects config-driven synthesis (Plans 04, 05, 06) to the public Phase 82 builder API.
code_mode
Code-mode wiring: bridges [code_mode] config blocks into pmcp-code-mode’s validation pipeline + HMAC token machinery, with policy / executor / validation types re-exported verbatim (NO duplicate impl per RESEARCH §“Anti-Patterns” #2).
config
ServerConfig + sub-sections. Strict #[serde(deny_unknown_fields)] per D-13.
env_ref
The ${VAR} / env:VAR reference grammar — the ONE parse chokepoint every env-reference path in the toolkit shares (credentials, token_secret, and [backend].base_url).
error
Toolkit error type and crate-level Result alias.
http
HTTP backend primitives for config-driven OpenAPI MCP servers (Phase 90).
policy
The two explicitly-registered validation escape hatches (Phase 128, E1 + E2).
prompts
Static MCP prompts for config-driven servers.
resources
Static MCP resources for config-driven servers.
secrets
Secrets management for the toolkit.
sql
SQL connector trait (3-method surface) + dialect enum.
tools
[[tools]] → ToolInfo + Arc<dyn ToolHandler> synthesizer.
workbook
Governed-Excel workbook served-tool module (Phase 92).

Structs§

EmbeddedSource
The binary-baked workbook BundleSource (WBSV-09), re-exported at the crate root only when the workbook-embedded feature is active. The binary-baked BundleSource (WBSV-09), re-exported only when the toolkit’s workbook-embedded feature layers the runtime’s embedded (include_dir) support on top of the LocalDirSource-only workbook build.
LocalDirSource
Re-export of the full boot surface (D-11) so Shape A/B consumers register a served workbook WITHOUT ever naming pmcp-workbook-runtime: the BundleSource trait + its on-disk impl, the fail-closed loader entry point, and both error types. The EmbeddedSource impl is re-exported separately under the workbook-embedded feature (it needs the runtime’s embedded include_dir support). A BundleSource that reads a bundle from a directory tree on disk.

Enums§

BundleLoadError
Re-export of the full boot surface (D-11) so Shape A/B consumers register a served workbook WITHOUT ever naming pmcp-workbook-runtime: the BundleSource trait + its on-disk impl, the fail-closed loader entry point, and both error types. The EmbeddedSource impl is re-exported separately under the workbook-embedded feature (it needs the runtime’s embedded include_dir support). Errors load surfaces — every one is fail-closed (the bundle is rejected, the server never boots on a tampered/malformed bundle).
BundleSourceError
Re-export of the full boot surface (D-11) so Shape A/B consumers register a served workbook WITHOUT ever naming pmcp-workbook-runtime: the BundleSource trait + its on-disk impl, the fail-closed loader entry point, and both error types. The EmbeddedSource impl is re-exported separately under the workbook-embedded feature (it needs the runtime’s embedded include_dir support). Errors a BundleSource may surface.

Constants§

VERSION
This toolkit build’s own version, captured at compile time.

Traits§

AuthProvider
Core authentication provider trait. This is the main abstraction that MCP servers use for authentication.
BundleSource
Re-export of the full boot surface (D-11) so Shape A/B consumers register a served workbook WITHOUT ever naming pmcp-workbook-runtime: the BundleSource trait + its on-disk impl, the fail-closed loader entry point, and both error types. The EmbeddedSource impl is re-exported separately under the workbook-embedded feature (it needs the runtime’s embedded include_dir support). Raw-byte access to a single bundle’s members.

Functions§

demo_db_path
Resolve the writable filesystem path for the demo SQLite database.
load_bundle
Re-export of the full boot surface (D-11) so Shape A/B consumers register a served workbook WITHOUT ever naming pmcp-workbook-runtime: the BundleSource trait + its on-disk impl, the fail-closed loader entry point, and both error types. The EmbeddedSource impl is re-exported separately under the workbook-embedded feature (it needs the runtime’s embedded include_dir support). Load + fail-closed integrity-verify a bundle from any BundleSource.

Attribute Macros§

async_trait
The #[async_trait] attribute, re-exported so an out-of-crate implementor of RequestPolicy (or http::auth::HttpAuthProvider) does not have to add an async-trait dependency of its own — and, more importantly, cannot end up on a DIFFERENT version of it than the trait was declared with, which produces a signature-mismatch error that reads as a lifetime bug.