mirror of
https://github.com/open-webui/open-webui.git
synced 2026-05-06 10:58:17 -05:00
[PR #22266] [CLOSED] feat: Add OAuth2.1 static auth for MCP servers #49625
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/open-webui/open-webui/pull/22266
Author: @DonMul
Created: 3/5/2026
Status: ❌ Closed
Base:
dev← Head:addOAuth2.1Static📝 Commits (10+)
fe6783cMerge pull request #19030 from open-webui/devfc05e0aMerge pull request #19405 from open-webui/deve3faec6Merge pull request #19416 from open-webui/dev9899293Merge pull request #19448 from open-webui/dev140605eMerge pull request #19462 from open-webui/dev6f1486fMerge pull request #19466 from open-webui/devd95f533Merge pull request #19729 from open-webui/deva7271530.6.43 (#20093)6adde20Merge pull request #20394 from open-webui/devf9b0534Merge pull request #20522 from open-webui/dev📊 Changes
7 files changed (+210 additions, -39 deletions)
View changed files
📝
backend/open_webui/main.py(+29 -24)📝
backend/open_webui/routers/configs.py(+29 -8)📝
backend/open_webui/routers/tools.py(+2 -2)📝
backend/open_webui/utils/middleware.py(+1 -1)📝
backend/open_webui/utils/oauth.py(+98 -1)📝
src/lib/apis/configs/index.ts(+3 -0)📝
src/lib/components/AddToolServerModal.svelte(+48 -3)📄 Description
Changelog Entry
Added
OAuth2.1 Staticauthentication option for static client_id and client_secret for MCP serversDescription
I needed to add some MCP servers to an Open WebUI instance, but these MCP servers required static oauth client data (client_id and client_secret). This was not possible with the current version of Open WebUI. I developed an extra authentication option where these fields can be entered by the end user, and those being used to register the client.
Added
Added
OAuth 2.1 - Staticauth type for MCP servers. See screenshot below in the Screenshots sectionAdditional Information
I was doubting to include these options directly in the OAuth 2.1 aut htype, but deliberately decided to make it a separate option to reduce possible confusion since a lot of MCPs actually do accept the dynamic OAuth data.
Screenshots or Videos
Contributor License Agreement
By submitting this pull request, I confirm that I have read and fully agree to the Contributor License Agreement (CLA), and I am providing my contributions under its terms.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.