AE-M2TJC01A
Shared MCP client instance sends concurrent agent runs' requests under the first caller's per-user credentials
IDENTITY FAILUREseverity: CRITICALcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: LOW
When one MCP server/toolset instance is shared across concurrent agent runs, the MCP session is created once by whichever caller enters first, and per-request auth derived from a ContextVar is evaluated in that caller's task context; overlapping callers' requests go out under the first caller's identity. The project documented the per-run toolset pattern (merged) because the underlying transport fix exists only in the mcp 2.0 beta line; a code change scoping sessions per entering context was proposed but not merged.
- Framework / agent
- Pydantic AI · Pydantic AI agents calling MCP tools with per-user bearer tokens
- Remediation attempts
- APPLIEDSUGGESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- GITHUB ISSUE MCPServerStreamableHTTP: concurrent callers can leak per-request auth headers across each other — github.com/pydantic/pydantic-ai, retrieved 2026-09-29
- GITHUB PULL REQUEST Document per-user MCP authentication: build `MCPToolset` per run via `@agent.toolset` — github.com/pydantic/pydantic-ai, retrieved 2026-09-29
- GITHUB PULL REQUEST Scope `MCPToolset` sessions to the entering context so concurrent callers don't share auth identity — github.com/pydantic/pydantic-ai, retrieved 2026-09-29
Symptoms
- A second concurrent caller's MCP request is authenticated as the first caller
- The auth hook is invoked on every request but reads the wrong task's context, so the leak is silent
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-M2TJC01A. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.