• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

stacklok / toolhive / 21987880162

13 Feb 2026 01:04PM UTC coverage: 61.99% (-0.06%) from 62.048%
21987880162

push

github

web-flow
Add AWS STS auth type to MCPExternalAuthConfig CRD (#3816)

Extends the MCPExternalAuthConfig CRD with a new 'awsSts' authentication type
that enables AWS STS token exchange with SigV4 request signing for MCP servers.

The AWSStsConfig supports:
- Region and service configuration for SigV4 signing
- Default IAM role ARN for token exchange
- Role claim-based mapping for multi-tenant scenarios
- Session name claim for CloudTrail correlation
- Configurable session duration

This allows vMCP to authenticate with AWS services (like AWS MCP Server) by
exchanging incoming OIDC tokens for temporary AWS credentials using STS
AssumeRoleWithWebIdentity.

Fixes: #3570

48 of 130 new or added lines in 6 files covered. (36.92%)

10 existing lines in 3 files now uncovered.

44268 of 71411 relevant lines covered (61.99%)

76.19 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

79.58
/pkg/transport/proxy/httpsse/http_proxy.go


Source Not Available

STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc