FastMCP
Apache-2.0 Python framework for building MCP servers fast — decorator-based, zero boilerplate, typed tool definitions.
FastMCP
FastMCP is a high-level Python framework for building Model Context Protocol (MCP) servers with minimal boilerplate. Inspired by FastAPI's decorator pattern, it lets you expose Python functions as MCP tools, resources, and prompts in seconds — handling all protocol-level serialization, schema generation, and transport setup automatically.
Key features
- Decorator-based API:
@mcp.tool(),@mcp.resource(),@mcp.prompt()— just annotate functions - Automatic JSON Schema generation from Python type hints
- Supports stdio and SSE (HTTP) transports
- Built-in testing utilities — run MCP servers in-process for unit tests
- Async-first but sync functions work too
- Apache-2.0 license
Quick start
pip install fastmcp
from fastmcp import FastMCP
mcp = FastMCP("My AI Tool Server")
@mcp.tool()
def add(a: int, b: int) -> int:
"""Add two numbers together."""
return a + b
@mcp.resource("config://settings")
def get_settings() -> str:
"""Return application settings."""
return "debug=false, version=1.0"
if __name__ == "__main__":
mcp.run() # stdio transport by default
# Run with SSE transport for HTTP access
fastmcp run server.py --transport sse --port 8000
Install via ai-supply
npx ai-supply add fastmcp-python
Curated mirror of the open-source FastMCP (Apache-2.0). Get it from the source.
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
The same gate an agent runs before installing (POST /api/v1/trust/fastmcp-python/check). Click a policy:
Consume FastMCP programmatically. Authenticate with an API key or session — see Authorize an agent.
# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/fastmcp-python
# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/fastmcp-python/check \
-H "Content-Type: application/json" \
-d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'
# CLI
npx ai-supply add fastmcp-python
# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/fastmcp-python/install \
-H "Authorization: Bearer $AIM_KEY"
# MCP tool
install_listing({ "slug": "fastmcp-python" })OpenAPI spec →Curated mirror — latest upstream source. See the repository for tagged releases.