SDKs overview

TL;DR — Six languages (Python, TypeScript, Go, Java, C#, Rust), one shared core primitive package per language, plus one adapter per popular MCP framework. All adapters do the same job: fetch AS metadata, cache the JWKS, publish RFC 9728 PRM, validate incoming JWTs (with or without DPoP), and expose token-exchange for delegation and upstream vending. This page tells you which adapter to install for your stack.

Which adapter for which stack

LanguageAdapter packageMCP framework it targetsFramework repo
Pythonauthplane-mcpOfficial MCP Python SDK — mcp.server.fastmcp.FastMCPmodelcontextprotocol/python-sdk
Pythonauthplane-fastmcpFastMCP (PrefectHQ)PrefectHQ/fastmcp
Pythonauthplane-sdk (core, imported as authplane)Framework-agnostic primitives—
TypeScript@authplane/mcpOfficial MCP TypeScript SDKmodelcontextprotocol/typescript-sdk
TypeScript@authplane/fastmcpFastMCP (punkpeye)punkpeye/fastmcp
TypeScript@authplane/honoHono web frameworkhonojs/hono
TypeScript@authplane/nestjsNestJSnestjs/nest
TypeScript@authplane/sdk (core)Framework-agnostic primitives—
GoauthplanemcpOfficial MCP Go SDKmodelcontextprotocol/go-sdk
Goauthplane mark3labsmark3labs/mcp-go community SDKmark3labs/mcp-go
Goauthplane httpGeneric net/http — any Go server—
Goauthplane (core)Framework-agnostic primitives—
Javaauthplane-mcpOfficial MCP Java SDK, on any Jakarta Servlet containermodelcontextprotocol/java-sdk
Javaauthplane-springSpring Boot — Spring Security or MCP transport hooksspring-projects/spring-boot
Javaauthplane-sdk (core)Framework-agnostic primitives—
C#Authplane.McpOfficial MCP C# SDK, on ASP.NET Coremodelcontextprotocol/csharp-sdk
C#Authplane.Sdk (core)Framework-agnostic primitives—
Rustauthplane-mcpOfficial Rust MCP SDK (rmcp), on axummodelcontextprotocol/rust-sdk
Rustauthplane-fastmcpfastmcp-rust — bearer tokens only—
Rustauthplane-sdk (core)Framework-agnostic primitives—

Naming trap. “FastMCP” is the class name of the official MCP Python SDK’s transport (mcp.server.fastmcp.FastMCP) and the name of two independent framework projects (PrefectHQ’s Python FastMCP, punkpeye’s TypeScript FastMCP). They are three different pieces of software. Pick the AuthPlane adapter that matches the framework you actually use.

Feature support

Every adapter delivers the same core functionality; the differences are how per-tool scope enforcement and inbound DPoP are wired.

FeaturePython (mcp)Python (fastmcp)TS (all)Go (all)Java (all)C# (all)Rust (mcp)Rust (fastmcp)Core packages
JWT signature validation (RS256/ES256/PS256)✓✓✓✓✓✓✓ [RS256/ES256 only]✓ [RS256/ES256 only]✓
RFC 8414 metadata discovery + cache✓✓✓✓✓✓✓✓✓
JWKS fetch + background rotation✓✓✓✓✓ [traffic-driven, no background timer]✓✓✓✓
RFC 9728 PRM publishing✓✓✓✓✓✓manual [serve prm_response()]manualmanual
Audience binding (aud = resource URI)✓✓✓✓✓✓✓✓✓
Inbound DPoP enforcement (RFC 9449)✓ [needs install_request_context]✓ no extra wiring✓✓✓✓✓✗ [DPoP-bound tokens rejected]✓
Outbound DPoP for calls to AS✓✓✓✓✓✓✓✓✓
Token exchange (RFC 8693) via client.exchange() (Go: client.TokenExchange(), C#: TokenExchangeAsync(), Rust: client.exchange_token())✓✓✓✓✓✓✓✓✓
Introspection revocation (RFC 7662)✓✓✓✓✓✓✓✓✓
URL elicitation → MCP JSON-RPC -32042✓✓✓✓✓ [authplane-mcp only, opt-in wrap]✓✓ [opt-in wrap]✓ [opt-in wrap]manual
Per-tool scope guardrequire_scope()@mcp.tool(auth=require_scopes(...))requireScopes()ClaimsFromContext() + manual checkclaims.requireScope()auto tools/{tool} scope / RequireScope()claims.require_scope()claims.require_scope()manual

Choose your adapter in three questions

  1. Which MCP framework are you using?
    • Official MCP SDK (Python, TS, or Go) → authplane-mcp / @authplane/mcp / authplanemcp.
    • PrefectHQ FastMCP (Python) → authplane-fastmcp.
    • punkpeye FastMCP (TS) → @authplane/fastmcp.
    • Hono → @authplane/hono.
    • NestJS → @authplane/nestjs.
    • mark3labs/mcp-go → authplane mark3labs.
    • Anything else in Go with plain net/http → authplane http.
    • Official MCP Java SDK on a Jakarta Servlet container → authplane-mcp.
    • Spring Boot → authplane-spring, then pick Spring Security or the MCP transport hooks.
    • Official MCP C# SDK on ASP.NET Core → Authplane.Mcp.
    • Official Rust MCP SDK (rmcp) on axum → authplane-mcp; fastmcp-rust → authplane-fastmcp (bearer only).
    • No framework, want raw primitives → the core authplane-sdk (Python) / @authplane/sdk / authplane (Go) / authplane-sdk (Java) / Authplane.Sdk (C#) / authplane-sdk (Rust) package.
  2. Do you need inbound DPoP enforcement? All adapters — including Python’s authplane-fastmcp — verify DPoP proofs when configured. authplane-mcp callers additionally call install_request_context(mcp) so the verifier can see the raw request; authplane-fastmcp needs no extra wiring. See Python: Inbound DPoP.
  3. Do you need to vend upstream tokens (GitHub, Slack, Google) from your tools? All adapters expose it: client.exchange() (Python, Java), auth.client.exchange() (TS), client.TokenExchange() (Go), AuthplaneAuthClient.TokenExchangeAsync() (C#), client.exchange_token() (Rust). See Guides: Wire up the Token Vault.

Install commands

Python

# For the official MCP Python SDK
pip install authplane-mcp

# For PrefectHQ FastMCP
pip install authplane-fastmcp

# Core primitives only
pip install authplane-sdk

Requires Python 3.11+. authplane-mcp supports mcp >=1.28.1, <2; authplane-fastmcp supports fastmcp >=3.2, <4.

TypeScript

# For the official MCP TypeScript SDK
npm install @authplane/sdk @authplane/mcp

# For punkpeye FastMCP
npm install @authplane/sdk @authplane/fastmcp fastmcp zod

# For Hono
npm install @authplane/sdk @authplane/hono hono

# For NestJS
npm install @authplane/sdk @authplane/nestjs @nestjs/common @nestjs/core

# Core primitives only
npm install @authplane/sdk

Requires Node.js 20 LTS or newer.

Go

# For the official MCP Go SDK
go get github.com/authplane/go-sdk/mcp

# For mark3labs/mcp-go
go get github.com/authplane/go-sdk/mark3labs

# For plain net/http (any framework)
go get github.com/authplane/go-sdk/http

# Core primitives only
go get github.com/authplane/go-sdk/core

Requires Go 1.24+ for core and http, 1.25+ for mcp, 1.25.5+ for mark3labs.

Java

<!-- Official MCP Java SDK adapter (pulls in the core) -->
<dependency>
  <groupId>ai.authplane.sdk</groupId>
  <artifactId>authplane-mcp</artifactId>
  <version>0.3.0</version>
</dependency>

Or Gradle: implementation("ai.authplane.sdk:authplane-mcp:0.3.0"). Swap the artifact for authplane-spring (Spring Boot) or authplane-sdk (core primitives only). Requires Java 21+ and one JVM flag — see Java: Required JVM property.

C#

# For the official MCP C# SDK on ASP.NET Core
dotnet add package Authplane.Mcp

# Core primitives only
dotnet add package Authplane.Sdk

Targets .NET 8 and 10.

Rust

# For the official Rust MCP SDK (rmcp) on axum
cargo add authplane-sdk authplane-mcp

# For fastmcp-rust (bearer tokens only)
cargo add authplane-sdk authplane-fastmcp

# Core primitives only
cargo add authplane-sdk

Requires Rust 1.91+ (edition 2024) and a Tokio runtime.

Versioning & compatibility

All AuthPlane SDKs follow semantic versioning. Same-major-line upgrades are drop-in; a major bump signals a breaking change and comes with a migration note in that repo’s CHANGELOG.md.

  • Python — pinning authplane-mcp==0.x is safe; the underlying MCP SDK version is called out in each release’s compatibility line.
  • TypeScript — @authplane/* packages share a version; upgrade the set together. Compatible with fastmcp@^3.35, hono@^4, @nestjs/*@^10 or ^11.
  • Go — module versions independent per adapter; the core module is the shared dependency and follows the same version cadence.
  • Java — the three ai.authplane.sdk artifacts share a version; upgrade them together. 0.3.0 fixes the error_description text and requires a host in the resource identifier — see Java: Upgrading from 0.2.0.
  • C# — Authplane.Sdk and Authplane.Mcp share a version; upgrade them together.
  • Rust — the three crates share a version; upgrade them together. API docs are on docs.rs.

Every SDK ships a conformance test suite that runs against a live AuthPlane instance. Green suite = the adapter meets the spec claims on this page.

What each SDK adapter does under the hood

Regardless of language and framework, the setup call performs the same seven steps described in Your first MCP server:

  1. Discover the AS via RFC 8414 metadata
  2. Fetch the JWKS + start background rotation
  3. Build an in-memory Resource object
  4. Wrap it in a Token Verifier the framework’s authenticate callback calls
  5. Build the RFC 9728 PRM document
  6. Wrap the underlying OAuth client to auto-translate ConsentRequiredError to MCP -32042
  7. Register an on-shutdown hook (aclose() / .close() / defer Close())

The differences between adapters are the surface — how the framework hands the request in, how you enforce scopes, and how the PRM handler gets mounted.