pypi fastmcp 4.1.0
v4.1.0: Fourth and One

4 hours ago

FastMCP 4.1.0 is a maintenance release at heart: a broad sweep of fixes across OpenAPI, proxies, auth, tasks, and the CLI, plus full Python 3.15 support. It doesn't change how most servers behave. A few security fixes do tighten inputs that FastMCP previously accepted, though, and our versioning policy keeps breaking changes out of patch releases, so this ships as a point-one release.

Check these before upgrading:

  • MultiAuth now qualifies client IDs by source, so existing MultiAuth sessions and tasks start new ownership scopes. Finish pending tasks before upgrading.
  • Regex tool search uses Pydantic's regex engine, which doesn't support lookarounds or backreferences.
  • Skill files must resolve inside their configured directories.
  • OpenAPI path parameters reject . and .. segments.
  • HTTP sessions now expire after the MCP SDK's 30-minute idle default instead of never.
  • CodeMode requires Monty 1.1, which renames max_duration_secs to max_feed_duration_secs.

Thanks to our 48 contributors, including 21 first-time contributors!

What's Changed

Breaking Changes ⚠️

  • fix(http): preserve the SDK's default session idle timeout by @asts-top in #5229
  • Restore full Python 3.15 support by @Kludex in #5558

Enhancements ✨

Security 🔒

  • fix!: Qualify MultiAuth client identities by @jlowin in #5455
  • fix!: Validate OpenAPI path parameter segments by @jlowin in #5457
  • fix!: Resolve skill files within their configured directories by @jlowin and @GEONWOOHAN in #5459
  • fix!: Use Pydantic’s regex engine for tool search by @jlowin in #5467

Fixes 🐞

Docs 📚

Examples & Contrib 💡

  • Don't evaluate properties when registering MCPMixin methods by @asasemahmed in #5620

Dependencies 📦

  • chore(deps): bump the uv group across 2 directories with 2 updates by @dependabot[bot] in #5393

New Contributors

Full Changelog: v4.0.11...v4.1.0

Don't miss a new fastmcp release

NewReleases is sending notifications on new releases.