Google Team Member and Copybara-Service
f1f44675e4
ADK changes
...
PiperOrigin-RevId: 829136628
2025-11-06 15:55:26 -08:00
Josh Soref and Copybara-Service
aa1233608a
chore: Fix spelling
...
Merge https://github.com/google/adk-python/pull/2447
This PR corrects misspellings identified by the [check-spelling action](https://github.com/marketplace/actions/check-spelling )
The misspellings have been reported at https://github.com/jsoref/adk-python/actions/runs/16840838898/attempts/1#summary-47711379253
The action reports that the changes in this PR would make it happy: https://github.com/jsoref/adk-python/actions/runs/16840839269/attempts/1#summary-47711380479
Note: while I use tooling to identify errors, the tooling doesn't _actually_ provide the corrections, I'm picking them on my own. I'm a human, and I may make mistakes.
I've included a couple of changes to make CI happy. Personally, I object to CI being in a state of "random drive by person who adds a blank line in the middle of a file must fix all the preexisting bugs in the file", but that appears to be the state for this repository.
COPYBARA_INTEGRATE_REVIEW=https://github.com/google/adk-python/pull/2447 from jsoref:spelling d85398e7fd154d124d477c6af6181481a01f34e0
PiperOrigin-RevId: 827629615
2025-11-03 13:33:53 -08:00
Kathy Wu and Copybara-Service
e8526f7e06
fix: Fix credential manager so that it supports the ServiceAccountCredentialExchanger
...
This fixes MCP authentication for gcloud service accounts. Previously it was failing to authenticate tool calls.
Co-authored-by: Kathy Wu <wukathy@google.com >
PiperOrigin-RevId: 826639044
2025-10-31 14:55:06 -07:00
Xiang (Sean) Zhou and Copybara-Service
5c6cdcd197
feat: Support Oauth2 client credentials grant type
...
PiperOrigin-RevId: 815813477
2025-10-06 11:28:17 -07:00
Google Team Member and Copybara-Service
c8c6cd70a4
feat: Introduce ExtendedOAuth2 scheme that auto-populates auth/token URLs
...
Use auto-discovered auth_endpoint and token_endpoint in CredentialManager.
PiperOrigin-RevId: 811183929
2025-09-24 22:21:07 -07:00
Google Team Member and Copybara-Service
2a2da0fe03
feat: Introduce OAuth2DiscoveryManager to fetch metadata needed for OAuth
...
This is the first step to bring ADK to compliance with MCP Authorization Spec.
PiperOrigin-RevId: 811177152
2025-09-24 21:53:48 -07:00
Mark Scannell and Copybara-Service
edda922791
feat: add audience and prompt as configurable for OAuth flows
...
Merge https://github.com/google/adk-python/pull/2738
Some OAuth servers require audience such as [Jira](https://developer.atlassian.com/cloud/confluence/oauth-2-3lo-apps/ ). This change allows the configuration of audience and prompt (if it needs to be changed) and adds some tests.
This is for issue [2755](https://github.com/google/adk-python/issues/2755 ).
Resolves #2755
Happy to provide changes/updates if needed.
COPYBARA_INTEGRATE_REVIEW=https://github.com/google/adk-python/pull/2738 from mescanne:oauth-audience-prompt 87ce1100792d9156ada2a004bcfaf2fe5fc69602
PiperOrigin-RevId: 802850034
2025-09-03 21:53:54 -07:00
Xiang (Sean) Zhou and Copybara-Service
3b922a2f6d
fix: Only process the auth responses in the last event with content (if applicable i.e. it's authored by user)
...
fixes : https://github.com/google/adk-python/issues/1944
PiperOrigin-RevId: 800560805
2025-08-28 12:09:21 -07:00
Xiang (Sean) Zhou and Copybara-Service
2f73cfde18
chore: Fix the long running test cases
...
The test test_token_exchange_not_supported was slow because of an incorrect monkeypatch target. The test was patching google.adk.auth.auth_handler.AUTHLIB_AVAILABLE, but the actual OAuth2 exchange logic uses a different AUTHLIB_AVAILABLE variable in google.adk.auth.exchanger.oauth2_credential_exchanger.
What was happening:
Test set auth_handler.AUTHLIB_AVAILABLE = False
AuthHandler.exchange_auth_token() called OAuth2CredentialExchanger.exchange()
But oauth2_credential_exchanger.AUTHLIB_AVAILABLE was still True
The exchanger attempted real OAuth2 token exchange with client.fetch_token()
This made actual network calls to OAuth2 endpoints, causing timeouts and delays
PiperOrigin-RevId: 788576949
2025-07-29 13:14:28 -07:00
Xiang (Sean) Zhou and Copybara-Service
430b82024f
chore: Fixed flaky test_update_credential_with_tokens unittest
...
PiperOrigin-RevId: 786340983
2025-07-23 10:45:01 -07:00
Xiang (Sean) Zhou and Copybara-Service
b977d12ea8
refactor: Add save_credential and load_credential in callback context for developer to access credential service
...
developer may want to save/load credentials themselves to/from credential service. see (https://github.com/google/adk-python/issues/1816 )
PiperOrigin-RevId: 783487628
2025-07-15 15:09:19 -07:00
Xiang (Sean) Zhou and Copybara-Service
1a75848391
refactor: Use CallbackContext in credential service for saving/loading credential
...
1. credential service may be accessed by callbacks
2. plan to add load_credential and save_credential method in CallbackContext (see cl/782158513) given customer has requirement to access credential service themselves. (see https://github.com/google/adk-python/issues/1816 )
It's backward compatible given CallbackContext is parent class of ToolContext
PiperOrigin-RevId: 783480378
2025-07-15 14:48:38 -07:00
hironow
843b791bb0
chore(fix typo): correct typo AUTHLIB_AVIALABLE → AUTHLIB_AVAILABLE
2025-07-10 03:08:31 +09:00
Xiang (Sean) Zhou and Copybara-Service
29cd183aa1
chore: Add credential service backed by session state
...
PiperOrigin-RevId: 774878336
2025-06-23 12:16:03 -07:00
Xiang (Sean) Zhou and Copybara-Service
9a1115c504
chore: Remove service account support
...
given it was not correctly supported.
PiperOrigin-RevId: 773137317
2025-06-18 18:19:05 -07:00
Xiang (Sean) Zhou and Copybara-Service
2c739ab581
chore: Add Credential Manager for managing tools credential (Experimental)
...
PiperOrigin-RevId: 772986051
2025-06-18 11:01:38 -07:00
Xiang (Sean) Zhou and Copybara-Service
9a207cb832
refactor: Refactor oauth2_credential_exchanger to exchanger and refresher separately
...
PiperOrigin-RevId: 772979993
2025-06-18 10:46:39 -07:00
Xiang (Sean) Zhou and Copybara-Service
a17ebe6ebd
chore: Add a credential refresher registry
...
PiperOrigin-RevId: 772747251
2025-06-17 21:12:30 -07:00
Xiang (Sean) Zhou and Copybara-Service
55201cb6a1
chore: Add credential exchanger registry (Experimentals)
...
PiperOrigin-RevId: 772713412
2025-06-17 19:09:21 -07:00
Xiang (Sean) Zhou and Copybara-Service
0a9625317a
refactor: Adapt service account credential exchanger to base credential exchanger interface
...
PiperOrigin-RevId: 772710438
2025-06-17 18:55:46 -07:00
Xiang (Sean) Zhou and Copybara-Service
c04adaade1
chore: Add in memory credential service (Experimental)
...
PiperOrigin-RevId: 772534962
2025-06-17 10:45:49 -07:00
Xiang (Sean) Zhou and Copybara-Service
94caccc148
refactor: Extract util method from OAuth2 credential fetcher for reuse
...
Context: we'd like to separate fetcher into exchanger and refresher later. This cl help to extract the common utility that will be used by both exchanger and refresher.
PiperOrigin-RevId: 772257995
2025-06-16 19:03:16 -07:00
Xiang (Sean) Zhou and Copybara-Service
a4d432a9e6
chore: Add Service Account Credential Exchanger (Experimental)
...
PiperOrigin-RevId: 771507089
2025-06-14 13:39:50 -07:00
Xiang (Sean) Zhou and Copybara-Service
8ebf229c47
chore: Add base credential service interface (WIP)
...
PiperOrigin-RevId: 771358480
2025-06-13 23:24:30 -07:00
Xiang (Sean) Zhou and Copybara-Service
177980106b
feat: Support refresh access token automatically for rest_api_tool
...
1. let auth_handler.py to utilize the oauth2 credential fetcher to exchange token
2. restructure tool_auth_handler.py to support refresh token
PiperOrigin-RevId: 770901469
2025-06-12 20:07:43 -07:00