Part of #5677
Spec link: https://modelcontextprotocol.io/specification/draft/changelog
Comprised of: Minor change 7 (iss validation — SEP-2468) + Minor change 8 (application_type — SEP-837) + Minor change 9 (issuer-bound credentials — SEP-2352)
What the spec says
- Authorization servers SHOULD include the
iss parameter in authorization responses per RFC 9207, and MCP clients MUST validate a present iss against the recorded issuer before redeeming the authorization code.
- MCP clients are required to specify an appropriate
application_type during Dynamic Client Registration to avoid OpenID Connect redirect URI conflicts.
- Client credentials are bound to the authorization server that issued them: clients MUST key persisted credentials by the issuer identifier, MUST NOT reuse them with a different authorization server, and MUST re-register when the authorization server changes.
Gateway work
- Add
iss validation to all gateway OAuth client flows, including OBO/token-exchange paths; fail closed on mismatch.
- Set correct
application_type in every DCR request.
- Re-key persisted credential storage by issuer identifier, with a migration for existing stored credentials.
- Implement re-registration on authorization server change; hard-block cross-issuer credential reuse.
Acceptance criteria
Part of #5677
Spec link: https://modelcontextprotocol.io/specification/draft/changelog
Comprised of: Minor change 7 (
issvalidation — SEP-2468) + Minor change 8 (application_type— SEP-837) + Minor change 9 (issuer-bound credentials — SEP-2352)What the spec says
issparameter in authorization responses per RFC 9207, and MCP clients MUST validate a presentissagainst the recorded issuer before redeeming the authorization code.application_typeduring Dynamic Client Registration to avoid OpenID Connect redirect URI conflicts.Gateway work
issvalidation to all gateway OAuth client flows, including OBO/token-exchange paths; fail closed on mismatch.application_typein every DCR request.Acceptance criteria
issmismatch.application_type.