CourseModel Context Protocol · Module 7: Authorization · part 45 of 83
Part 45 · Module 7: Authorization

Topic 6: Module 7 milestone and interview questions

9 min read·22 Sept 2026

Project Milestone

The notes assistant is now safe to expose over HTTP. Your repository should contain:

text
notes-assistant/
  notes_assistant/
    auth.py                   NEW: JWTTokenVerifier, mint_dev_token, auth_from_env, READ_SCOPE, WRITE_SCOPE
    server.py                 UPDATED: token_verifier/auth parameters, notes:write check, auth_from_env in main
    store.py, llm.py, config.py, host.py   unchanged
  examples/
    m07_tokens.py             shared settings and good/bad test tokens
    m07_no_token_in_memory.py why stdio and in-memory calls carry no token
    m07_issuer_slash.py       the trailing-slash issuer pitfall
    m07_pkce.py               PKCE S256 checked against RFC 7636
    m07_token_matrix.py       HTTP status for every token
    m07_scoped_calls.py       read versus write scopes through a real client
    m07_rejected.py           catching and diagnosing a refused token
    m07_client_metadata.py    CIMD document and OAuthClientProvider
    m07_auth_overhead.py      verification and end-to-end latency
    m07_step_up.py            reading a scope challenge
    m07_passthrough.py        token passthrough versus a separate token
    m07_identity_assertion.py enterprise ID-JAG client provider
    m07_jwks_verifier.py      RS256 with PyJWKClient
    m07_production_wiring.py  the JWKS verifier in build_server
    m07_lab.py                the end-to-end lab
  tests/
    test_auth.py              NEW: 9 tests for the verifier and the HTTP door

Code explained

  • In simple words: a map of what changed in the project this module.
  • What happens: auth.py is new and server.py reached its final form; everything else in notes_assistant/ is untouched. The examples/ files are the module's scripts in the order you met them, and tests/test_auth.py joins the Module 5 tests.
  • Comes out: with the tests from earlier modules in place, python -m pytest -q should report everything passing, including the 9 new tests. To run the protected server yourself: set NOTES_AUTH_KEY, NOTES_AUTH_ISSUER, and NOTES_RESOURCE_URL, then start it with NOTES_TRANSPORT=streamable-http.

What the capstone (Module 11) will ask of this code, and where it already stands: "Protect the HTTP version with OAuth and validate the token audience" is done; "a token issued for a different server, checking it is rejected" is the wrong-audience row of the lab.

The rest of this course is yours to keep

This course is bought on its own, once, and stays readable afterwards, including the parts added to it later.