Skip to content
CAI
Software that uses CAICheck a score

Neftedollar/FsMcp

70.5

Strong · 3 October 2026

4.9k

lines of production code

F#

with JavaScript, Python

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

FsMcp is an F\# library that provides a type-safe framework for building and interacting with Model Context Protocol (MCP) servers and clients. It enables developers to define tools, resources, and prompts with strict validation, while supporting both stdio and HTTP transports with enterprise-grade authorization and secure token management. The system includes utilities for testing server configurations without transport overhead and offers a pipeline-based API for chaining client operations with robust error handling.

Features

Add example servers for Calculator, Echo, and File operations

Added three new example server implementations demonstrating the FsMcp framework's capabilities: a Calculator server providing arithmetic tools (add, subtract, multiply, divide), an EchoServer featuring echo/reverse text tools, a status resource, and an explain prompt, and a FileServer offering file reading, directory listing, and metadata retrieval tools. These examples illustrate how to define typed tools, resources, and prompts, including validation imports and cancellation handling.

Calculator, EchoServer, FileServer · high confidence

Added F\# to C\# SDK interop and JSON serialization support

The FsMcp.Core library now includes an internal Interop module that bridges F\# domain types with the C\# ModelContextProtocol SDK, handling conversions for content blocks (text, images, embedded resources) and message roles. Additionally, a new Serialization module provides custom System.Text.Json converters to ensure F\# types are serialized to and deserialized from the MCP wire format correctly, including base64 encoding for binary data. These changes are supported by the addition of a packages.lock.json file, which pins the ModelContextProtocol SDK to version 1.4.1 and its dependencies.

src/FsMcp.Core · high confidence

Enterprise authorization and secure MCP client wrapper

The FsMcp.Client library now includes a new \McpClient\ wrapper that simplifies interaction with the underlying Model Context Protocol SDK, exposing high-level types for tools, resources, and prompts. This update introduces comprehensive enterprise-managed authorization support, allowing clients to authenticate via identity token providers and access token exchanges while enforcing strict security policies such as origin matching, header validation, and response size limits. The client also handles lifecycle management with configurable shutdown timeouts and redacts sensitive failure details in logs to prevent credential leakage.

FsMcp.Client · high confidence

Enterprise-grade MCP client with secure HTTP transport and automatic retry

The FsMcp.Client library now supports connecting to MCP servers via HTTP endpoints in addition to the existing stdio process transport. For HTTP connections, the client includes an enterprise authorization handler that automatically manages Bearer token acquisition, validates request safety (ensuring same-origin and preventing header overrides), and implements automatic retry logic with token refresh when receiving 401 Unauthorized responses. This allows users to securely integrate with MCP servers requiring authentication while handling transient auth failures transparently.

src/FsMcp.Client · high confidence

FsMcp documentation site launched with Docusaurus

The project now includes a dedicated documentation website built with Docusaurus, hosted at neftedollar.com/FsMcp. This site provides comprehensive guides for getting started, server and client configuration, enterprise-managed authorization, and testing, along with a full types reference. It features local search, SEO meta tags, structured data, and AI discovery files (llms.txt, ai.txt) to support both human readers and LLM-based tooling.

website · high confidence

Introduce core domain types and validation for MCP resources, tools, and prompts

This change adds the foundational type definitions and validation logic for the FsMcp.Core library, establishing the data structures used to represent MCP resources, tools, and prompts. Users can now define tools with input schemas and handlers, specify resources with URIs and MIME types, and create prompts with arguments, all backed by strict validation for identifiers like ToolName, ResourceUri, and MimeType to ensure data integrity at construction time.

FsMcp.Core · high confidence

New FsMcp.Sampling package introduces LLM sampling types and a failing tool definition

A new FsMcp.Sampling package has been added, providing the core types for LLM sampling requests and results (SamplingRequest, SamplingResult, SamplingError) along with helper builders. It also includes a SamplingContext for tool handlers to invoke sampling. However, the provided SamplingTool.define function is currently non-functional; it raises an exception indicating that the previous no-op implementation failed closed and that production support requires a future SDK RequestContext/McpServer-based handler API.

FsMcp.Sampling · high confidence

New FsMcp.Testing library for simplified server testing and property-based testing

The FsMcp.Testing library has been introduced to provide utilities for testing MCP server configurations without transport overhead. It includes a TestServer module that allows direct invocation of tool, resource, and prompt handlers from a ServerConfig, along with helper types for listing tools, resources, and prompts. Additionally, it provides Expecto assertion helpers for validating MCP results and FsCheck arbitraries for generating valid MCP domain types (such as ToolName, ResourceUri, and McpMessage) to support property-based testing.

FsMcp.Testing, src/FsMcp.Testing · high confidence

New ergonomic task pipeline for MCP client operations

The FsMcp.TaskApi library introduces a new \ClientPipeline\ module that wraps standard MCP client interactions in a pipe-friendly, error-handling style using \FsToolkit.ErrorHandling\. This allows users to chain operations like connecting, listing tools, calling tools, reading resources, and managing prompts within a single \taskResult\ computation expression, automatically handling validation and cancellation. The module also adds support for enterprise-managed authorization during connection and includes a lockfile pinning dependencies such as \FsToolkit.ErrorHandling\ (5.2.0) and \ModelContextProtocol\ (1.4.1).

src/FsMcp.TaskApi · high confidence

New release engineering and verification scripts for FsMcp

The repository now includes a comprehensive suite of automation scripts to support the build, packaging, and release verification of the FsMcp library. These scripts enable building example projects, packing the seven core FsMcp NuGet packages with strict metadata validation, and generating deterministic lockfiles. A new consumer smoke test validates the public API surface of the published packages against specific F\# compiler versions, while dedicated verifiers ensure the release artifacts are clean by checking for NuGet and npm vulnerabilities, verifying package metadata (such as descriptions, dependencies, and repository commits), and extracting release notes. Additionally, a regression harness reproduces a stdio stderr wedge issue, and a memory leak snapshot tool aids in diagnosing resource usage in MCP servers.

scripts · high confidence

New server builder DSL and resource subscription support

The FsMcp.Server library introduces a new computation-expression-based DSL for configuring MCP servers and defining tools, allowing users to specify server name, version, tools, resources, and prompts via \mcpServer\ and \mcpTool\ blocks. It adds support for resource subscriptions, enabling clients to subscribe to specific resource URIs and receive change notifications. Additionally, the built-in console logger can now be disabled via \consoleLogging\ to prevent stdio servers from wedging when the host leaves stderr unread, and legacy middleware declarations are now rejected to prevent silent failures.

FsMcp.Server · high confidence

Behavioural changes

FsMcp 2.0: Enterprise authorization, breaking API changes, and stdio stability fixes

This release introduces enterprise-managed authorization for MCP clients (ID-JAG profile with RFC 8693 token exchange) and secure server composition via ASP.NET Core DI. It includes several breaking changes: handler signatures now require a final \CancellationToken\, \McpClient.readResource\ returns the full \ResourceContents list\ instead of discarding items, resource subscriptions use opaque IDs, and typed tool input strictly rejects JSON string coercion for non-URI/prompt fields. Additionally, it fixes a critical stdio server wedge caused by unread stderr pipes and resolves a Windows startup crash in the stderr sink. The \FSharp.Core\ dependency floor is explicitly pinned to 10.1.203 to prevent consumer build breaks.

(repo-wide) · high confidence

FsMcp.Server 2.0 introduces breaking changes to dynamic server registration and adds observability features

The server library has been updated to version 2.0, introducing a breaking change where the legacy \DynamicServer\ API now fails immediately with an error rather than silently ignoring updates to the live SDK registry; users must rebuild and replace the composed server registration instead. This release also adds OpenTelemetry-compatible tracing and metrics middleware for monitoring request performance, implements a non-blocking stderr logger to prevent server wedging when the host does not read the error stream, and introduces support for streaming tool handlers and typed tool/resource/prompt definitions with auto-generated JSON schemas.

src/FsMcp.Server · high confidence

Guaranteed subscription cleanup on HTTP disconnect

The FsMcp server now ensures that resource subscriptions are automatically cleaned up when an HTTP session disconnects. This change wraps the SDK's session handler to enforce cleanup logic, preventing resource leaks and ensuring stateless honesty even if the client disconnects unexpectedly.

src/FsMcp.Server.Http · high confidence

Test coverage

Added HTTP wire contract tests for MCP server initialization and authorization; Added comprehensive test coverage for FsMcp.Server components; Added property-based and serialization tests for FsMcp.Core; Added test coverage for server-side tool, streaming, and validation features; Added tests for FsMcp.TaskApi client pipeline and validation; Added tests for HTTP subscription cleanup and multi-client session isolation; Added unit tests for FsMcp.Sampling; Added unit tests for FsMcp.Testing utilities; Initial test suite for FsMcp.Client with enterprise authorization and transport validation.

Dependencies

Initial project structure and dependency configuration for FsMcp and documentation site

This change introduces the foundational project structure for the FsMcp library, defining ten .NET SDK-style project files (FsMcp.Core, FsMcp.Client, FsMcp.Server, FsMcp.Server.Http, FsMcp.Sampling, FsMcp.TaskApi, FsMcp.Testing, and their corresponding test projects) targeting .NET 10.0. It establishes the dependency graph, referencing the ModelContextProtocol SDK, Microsoft.Extensions libraries, TypeShape, and FsToolkit.ErrorHandling. Additionally, it adds three example projects (Calculator, EchoServer, FileServer) and configures the Docusaurus-based documentation website with React 19, Docusaurus 3.10.2, and specific security overrides for npm packages like fast-uri and qs.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 69 → 71 (+1.2)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 84 → 83 (-0.1)
  • Architecture 85 → 93 (+8.3)
  • Maturity 78 → 78 (+0.0)
  • Readiness 56 → 56 (-0.1)
  • Security 89 → 89 (+0.0)
  • Performance 100 (new)

Resolved (2)

  • Documentation: no installation or build instructions (website/docs/enterprise-managed-authorization.md)
  • Documentation: no usage examples (website/docs/client-guide.md)

New (23)

  • Documentation: no architecture or design documentation (docs/index.md)
  • Documentation: no project overview (website/docs/server-guide.md)
  • Outdated (npm): @types/ws
  • Outdated (npm): algoliasearch-helper
  • Outdated (npm): ansi-regex
  • Outdated (npm): bundle-name
  • Outdated (npm): follow-redirects
  • Outdated (npm): fs-extra
  • Outdated (npm): mdast-util-gfm-strikethrough
  • Outdated (npm): mdast-util-to-markdown
  • Outdated (npm): micromark
  • Outdated (npm): micromark-core-commonmark
  • Outdated (npm): micromark-factory-space
  • Outdated (npm): micromark-util-types
  • Outdated (npm): pkijs
  • Outdated (npm): regenerate-unicode-properties
  • Outdated (npm): regexpu-core
  • Outdated (npm): regjsparser
  • Outdated (npm): shell-quote
  • Outdated (npm): source-map-js
  • …and 3 more

Architecture

  • Unchanged — 0 containers · 11 contexts · 11 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Neftedollar/FsMcp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6f5055493e301625714ef4eb1c479758a6810996 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-4f4226d619ea.