Expand description
Proxy-side identity store for MCP sessions.
MCP clients authenticate on the initialize call but may omit the bearer
token on subsequent session-only requests. This module persists the
authenticated identity keyed by mcp-session-id so those follow-ups can be
enriched (enrich_with_cached_identity) on any replica, and evicts the
row on session teardown or a stale-session backend response
(handle_mcp_response). The store is the trust anchor for session-based
MCP auth — rows are only written for a verified AuthenticatedUser.
Copyright (c) systemprompt.io — Business Source License 1.1. See https://systemprompt.io for licensing details.