You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AI Agent调用带Header认证的MCP服务器遇阻塞问题求助

问题解决与方案评估

一、RunStatus.REQUIRES_ACTION状态排查与解决

REQUIRES_ACTION状态表示Agent已生成工具调用请求,但需显式执行调用并返回结果才能推进流程。针对你的场景,按以下步骤排查处理:

1. 确认Agent是否触发工具调用

  • 查看线程消息历史,检查Agent输出是否包含tool_call结构。若未触发,大概率是Agent指令描述模糊,比如未明确要求调用testing_tool或未说明参数要求。
  • 调整Agent的instructions,明确指定调用逻辑,例如:"必须调用testing_tool工具,传入arg1='test1', arg2='test2', arg3='test3'完成任务"。

2. 实现工具调用的执行与结果提交

当Agent进入REQUIRES_ACTION状态时,需手动处理工具调用并提交结果:

# 获取当前运行详情
run = project_client.agents.runs.get(thread_id=thread.id, run_id=run.id)

if run.status == RunStatus.REQUIRES_ACTION:
    tool_calls = run.required_action.submit_tool_outputs.tool_calls
    tool_outputs = []
    
    for tool_call in tool_calls:
        if tool_call.tool_name == "testing_tool":
            try:
                # 执行MCP工具调用(确保请求头携带正确token)
                output = {"status": "success"}
                tool_outputs.append({
                    "tool_call_id": tool_call.id,
                    "output": json.dumps(output)
                })
            except Exception as e:
                tool_outputs.append({
                    "tool_call_id": tool_call.id,
                    "output": json.dumps({"error": str(e)})
                })
    
    # 提交工具执行结果
    project_client.agents.runs.submit_tool_outputs(
        thread_id=thread.id,
        run_id=run.id,
        submit_tool_outputs_body={"tool_outputs": tool_outputs}
    )

3. 校验MCP服务器的认证逻辑

  • 查看MCP服务器日志,确认是否收到请求、请求头Authorization是否正确传递。若日志显示No headers found或Invalid auth token,需检查MCPToolResource的server_label是否与创建McpTool时的标签完全一致,headers键名是否为Authorization(部分框架对大小写敏感)。

4. 排查网络与权限问题

  • 确认Azure AI Agent所在环境可访问MCP服务器,无防火墙或网络策略拦截请求。
  • 若MCP服务器为公网部署,检查是否允许Azure AI服务的IP范围访问。

二、现有实现方案合理性与优化方向

合理点

  • 采用请求头认证符合API安全规范,避免敏感token暴露在请求参数中。
  • 基于MCP集成自定义工具,契合Azure AI Agent的扩展标准,便于后续新增工具。
  • 设置approval_mode="never",适配自动化测试场景,无需人工干预。

优化方向

1. 认证安全优化

  • 替换硬编码token的方式,使用Azure Key Vault存储auth_token,在创建MCPToolResource时动态读取:
from azure.keyvault.secrets import SecretClient
secret_client = SecretClient(vault_url="https://your-vault.vault.azure.net/", credential=credential)
auth_token = secret_client.get_secret("mcp-auth-token").value

mcp_tool_resource = MCPToolResource(
    server_label=mcp_server_label,
    headers={"Authorization": auth_token}
)

2. 工具逻辑优化

  • 新增参数校验,避免因参数缺失导致异常:
@mcp.tool()
async def testing_tool(
    arg1: str, arg2: str, arg3: str
) -> Dict[str,str]:
    # 参数非空校验
    if not all([arg1, arg2, arg3]):
        raise ValueError("Missing required arguments")
    
    # 原有认证逻辑
    headers = get_http_headers()
    auth_header = headers.get("authorization", "")
    if not auth_header:
        raise AuthError("Missing bearer token")
    if auth_header != "abcdef":
        raise AuthError("Invalid auth token")
    
    return {"status": "success", "message": "Tool executed successfully"}
  • 确保AuthError能被Azure AI Agent正确解析,建议返回标准HTTP状态码(如401)和清晰错误信息。

3. Agent流程自动化优化

  • 配置Agent实现自动工具调用:确保Agent指令足够明确,工具元数据(参数名称、类型)定义正确,让Agent能自动生成合规的工具调用请求,无需手动处理REQUIRES_ACTION状态。

4. 监控与日志优化

  • 在MCP服务器和Agent代码中添加详细日志,记录请求头、参数、响应状态及Agent运行状态变化。
  • 使用Azure Monitor监控Agent运行状态与MCP服务器请求指标,及时发现异常。

内容的提问来源于stack exchange,提问作者lefty

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 07:53:21