Skip to content

[Minor-1] OAuth hardening #5684

Description

@Lang-Akshay

Part of #5677

Spec link: https://modelcontextprotocol.io/specification/draft/changelog
Comprised of: Minor change 7 (iss validation — SEP-2468) + Minor change 8 (application_type — SEP-837) + Minor change 9 (issuer-bound credentials — SEP-2352)

What the spec says

  • Authorization servers SHOULD include the iss parameter in authorization responses per RFC 9207, and MCP clients MUST validate a present iss against the recorded issuer before redeeming the authorization code.
  • MCP clients are required to specify an appropriate application_type during Dynamic Client Registration to avoid OpenID Connect redirect URI conflicts.
  • Client credentials are bound to the authorization server that issued them: clients MUST key persisted credentials by the issuer identifier, MUST NOT reuse them with a different authorization server, and MUST re-register when the authorization server changes.

Gateway work

  • Add iss validation to all gateway OAuth client flows, including OBO/token-exchange paths; fail closed on mismatch.
  • Set correct application_type in every DCR request.
  • Re-key persisted credential storage by issuer identifier, with a migration for existing stored credentials.
  • Implement re-registration on authorization server change; hard-block cross-issuer credential reuse.

Acceptance criteria

  • Authorization code redemption fails closed on iss mismatch.
  • Credential store keyed by issuer; cross-issuer reuse impossible.
  • All DCR requests include application_type.

Metadata

Metadata

Assignees

Labels

CF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.mcp-2026-07-28Issues related to compliance with MCP 2026-07-28rustRust programmingtriageIssues / Features awaiting triage

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions