Skip to main content

McpServerConfig

Struct McpServerConfig 

Source
pub struct McpServerConfig {
Show 18 fields pub id: String, pub command: Option<String>, pub args: Vec<String>, pub env: HashMap<String, String>, pub url: Option<String>, pub timeout: u64, pub policy: McpPolicy, pub headers: HashMap<String, String>, pub oauth: Option<McpOAuthConfig>, pub trust_level: McpTrustLevel, pub tool_allowlist: Option<Vec<String>>, pub allow_untrusted_without_allowlist: bool, pub expected_tools: Vec<String>, pub roots: Vec<McpRootEntry>, pub tool_metadata: HashMap<String, ToolSecurityMeta>, pub elicitation_enabled: Option<bool>, pub env_isolation: Option<bool>, pub media_passthrough: bool,
}

Fields§

§id: String§command: Option<String>

Stdio transport: command to spawn.

§args: Vec<String>§env: HashMap<String, String>

Environment variables for the spawned Stdio process. Values may hold vault references (${VAULT_KEY}) or, in a hand-written config, raw secrets.

§Security

Intentionally not redacted in Serialize: --init persists this map to config.toml, so a redacting Serialize would corrupt the round-trip. The redacting Debug impl on this struct is the approved representation for any log/dump/status output — never emit this field’s values via Serialize or any other non-Debug representation.

§url: Option<String>

HTTP transport: remote MCP server URL.

§timeout: u64§policy: McpPolicy

Optional declarative policy for this server (allowlist, denylist, rate limit).

§headers: HashMap<String, String>

Static HTTP headers for the transport (e.g. Authorization: Bearer <token>). Values support vault references: ${VAULT_KEY}.

§Security

Intentionally not redacted in Serialize — same rationale as env: --init persists this map to config.toml, and the redacting Debug impl is the approved representation for log/dump/status output — never emit this field’s values via Serialize or any other non-Debug representation.

§oauth: Option<McpOAuthConfig>

OAuth 2.1 configuration for this server.

§trust_level: McpTrustLevel

Trust level for this server. Default: Untrusted.

§tool_allowlist: Option<Vec<String>>

Tool allowlist. None means no override (inherit defaults). Some(vec![]) is an explicit empty list (deny all for Untrusted/Sandboxed). Some(vec!["a", "b"]) allows only listed tools.

§allow_untrusted_without_allowlist: bool

Explicit opt-in to expose all tools for an Untrusted server that has no tool_allowlist declared. Default: false — secure by default (fails closed).

When false (default) and trust_level == Untrusted with tool_allowlist = None, zero tools are exposed. Set true only when you intentionally want this server to expose all its tools while still running the full untrusted pipeline (SSRF checks, sanitization, injection detection, attestation, data-flow filtering) — this is distinct from trust_level = trusted, which additionally relaxes SSRF/data-flow enforcement. Has no effect on Trusted/Sandboxed servers or when tool_allowlist is set.

§expected_tools: Vec<String>

Expected tool names for attestation. Supplements tool_allowlist.

When non-empty: tools not in this list are filtered out (Untrusted/Sandboxed) or warned about (Trusted). Schema drift is logged when fingerprints change between connections.

§roots: Vec<McpRootEntry>

Filesystem roots exposed to this MCP server via roots/list. Each entry is a {uri, name?} pair. URI must use file:// scheme. When empty, the server receives an empty roots list.

§tool_metadata: HashMap<String, ToolSecurityMeta>

Per-tool security metadata overrides. Keys are tool names. When absent for a tool, metadata is inferred from the tool name via heuristics.

§elicitation_enabled: Option<bool>

Per-server elicitation override. None = inherit global elicitation_enabled. Some(true) = allow this server to elicit regardless of global setting. Some(false) = always decline for this server.

§env_isolation: Option<bool>

Isolate the environment for this Stdio server.

When true (or when [mcp].default_env_isolation = true), the spawned process only sees a minimal base env (PATH, HOME, etc.) plus this server’s env map. Overrides [mcp].default_env_isolation when set explicitly. Default: false (backward compatible).

§media_passthrough: bool

Opt-in: decode and attach images this server returns as native MessagePart::Image siblings for vision-capable providers (spec-072). Default: false.

Independent of trust_level but always hard-blocked when trust_level == McpTrustLevel::Sandboxed, regardless of this flag.

Trait Implementations§

Source§

impl Clone for McpServerConfig

Source§

fn clone(&self) -> McpServerConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for McpServerConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for McpServerConfig

Source§

fn deserialize<__D>( __deserializer: __D, ) -> Result<McpServerConfig, <__D as Deserializer<'de>>::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for McpServerConfig

Source§

fn serialize<__S>( &self, __serializer: __S, ) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more