Skip to content

MCP Authorization specification 2026-07-28 - #51333

Merged
ahus1 merged 1 commit into
keycloak:mainfrom
Hitachi:ISSUE-48527
Aug 2, 2026
Merged

MCP Authorization specification 2026-07-28#51333
ahus1 merged 1 commit into
keycloak:mainfrom
Hitachi:ISSUE-48527

Conversation

@tnorimat

Copy link
Copy Markdown
Contributor

closes #48527

Copilot AI review requested due to automatic review settings July 31, 2026 11:37
@tnorimat
tnorimat requested a review from a team as a code owner July 31, 2026 11:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates MCP authorization documentation for the 2026-07-28 specification.

Changes:

  • Adds the latest MCP version and compliance matrix entries.
  • Extends setup guidance to cover 2026-07-28.
  • Documents RFC 9207 support.
Suppressed comments (2)

docs/guides/securing-apps/mcp-authz-server.adoc:54

  • The new 2026-07-28 entry should not mark RFC 8707 as an authorization-server MUST. That release requires MCP clients to send resource even when the authorization server does not support it, so use - for this authorization-server compliance row.
| MUST

docs/guides/securing-apps/mcp-authz-server.adoc:105

  • This conformance result follows from the incorrect RFC 8707 authorization-server requirement above. Since 2026-07-28 explicitly allows authorization servers not to support resource, Keycloak's stated limitation does not make its authorization-server support partial under the guide's criteria.
| https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization[2026-07-28]
| Partially Supported without Resource Indicators for OAuth 2.0

Comment thread docs/guides/securing-apps/mcp-authz-server.adoc Outdated
@ahus1 ahus1 self-assigned this Jul 31, 2026
closes keycloak#48527

Signed-off-by: Takashi Norimatsu <takashi.norimatsu.ws@hitachi.com>
Copilot AI review requested due to automatic review settings July 31, 2026 12:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

Suppressed comments (2)

docs/guides/securing-apps/mcp-authz-server.adoc:52

  • The 2026-07-28 specification makes RFC 8707 mandatory for MCP clients, not authorization servers; its security section explicitly qualifies the audience-binding behavior as applying “when the Authorization Server supports the capability.” Because this table is scoped to authorization-server requirements, MUST overstates Keycloak's obligation here.
| MUST

docs/guides/securing-apps/mcp-authz-server.adoc:35

  • The new release-specific column is still introduced by line 28's moving /specification/draft/ reference, so that citation can describe a later draft rather than the 2026-07-28 requirements recorded here. Link this header to the immutable 2026-07-28 standards section.
|Standard |2026-07-28 |2025-11-25 |2025-06-18 |2025-03-26 |{project_name}

@tnorimat

Copy link
Copy Markdown
Contributor Author

@ahus1 I fixed the point the first copilot review proposed.

@ahus1
ahus1 merged commit 7bf1e46 into keycloak:main Aug 2, 2026
68 checks passed
@ahus1

ahus1 commented Aug 2, 2026

Copy link
Copy Markdown
Member

@tnorimat - thank you for this pull request! Please create backports for 26.7 and 26.6 for this change.

@tnorimat
tnorimat deleted the ISSUE-48527 branch August 2, 2026 09:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP Authorization specification 2026-07-28

3 participants