Repository navigation
[Deprecated-3][CONTROL-PLANE] DCR → Client ID Metadata Documents #5692
Copy link
Copy link
Open
Labels
CF-CONTROL-PLANEAdministrative interface to configure CF.Administrative interface to configure CF.SHOULDP2: Important but not vital; high-value items that are not crucial for the immediate releaseP2: Important but not vital; high-value items that are not crucial for the immediate releaseclient-mrkHigh priority itemsHigh priority itemsmcp-2026-07-28Issues related to compliance with MCP 2026-07-28Issues related to compliance with MCP 2026-07-28oauth-oidcOAuth/OIDC related issues and PRsOAuth/OIDC related issues and PRspythonPython / backend development (FastAPI)Python / backend development (FastAPI)work-queueIssues currently being actively triaged and sorted for work.Issues currently being actively triaged and sorted for work.
Description
Activity
- addedrustRust programmingRust programmingCF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.External dataplane which can extend ContextForge functionality.mcp-2026-07-28Issues related to compliance with MCP 2026-07-28Issues related to compliance with MCP 2026-07-28
on Jul 17, 2026 - changed the title
[-][Deprecated-3] DCR → Client ID Metadata Documents[/-][+][Deprecated-3][CONTROL-PLANE] DCR → Client ID Metadata Documents[/+]on Aug 11, 2026 - addedpythonPython / backend development (FastAPI)Python / backend development (FastAPI)oauth-oidcOAuth/OIDC related issues and PRsOAuth/OIDC related issues and PRsCF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.External dataplane which can extend ContextForge functionality.and removedrustRust programmingRust programmingCF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.External dataplane which can extend ContextForge functionality.
on Aug 11, 2026 3 remaining items
- added a parent issue
on Aug 20, 2026 - added2.0CF1.5 with the bolt on external data plane + Redis as a communication channelCF1.5 with the bolt on external data plane + Redis as a communication channeland removedtriageIssues / Features awaiting triageIssues / Features awaiting triage
on Aug 20, 2026 - removed a parent issue
on Aug 20, 2026 - addedCF-BUILTIN-DATAPLANEDataplane which is an internal part of CF and shipped as one with the control planeDataplane which is an internal part of CF and shipped as one with the control planeCF-CONTROL-PLANEAdministrative interface to configure CF.Administrative interface to configure CF.and removedCF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.External dataplane which can extend ContextForge functionality.2.0CF1.5 with the bolt on external data plane + Redis as a communication channelCF1.5 with the bolt on external data plane + Redis as a communication channelCF-BUILTIN-DATAPLANEDataplane which is an internal part of CF and shipped as one with the control planeDataplane which is an internal part of CF and shipped as one with the control plane
on Aug 20, 2026 Context on the fallback path this issue assumes exists: DCR has shipped and is on by default, so the "fall back to DCR only when CIMD is unsupported" branch will be falling back into live code rather than into something that still needs building.
Current state:
mcpgateway/services/dcr_service.pyimplements RFC 7591 registration, RFC 8414 AS metadata discovery, and client persistence, update and delete.DCR_ENABLEDandDCR_AUTO_REGISTER_ON_MISSING_CREDENTIALSboth default totrue(config.py:1008,:1011)./oauth/authorize/{gateway_id}auto-registers whenever a gateway has anissuerand noclient_id(oauth_router.py:670), then persists the credentials and setsauth_type=oauth.- Registered clients live in
registered_oauth_clients, with list, per-gateway lookup and delete exposed under/oauth/registered-clients. - Registration sends
redirect_uriprogrammatically, so operators of DCR-capable providers never see or copy it.
A couple of things that may affect the acceptance criteria:
- "Emit a safe deprecation notice when DCR fallback is used" is not satisfied today. The auto-register path logs success at info level with no deprecation signal, and nothing surfaces to the user.
- The fallback is currently silent and automatic rather than user-initiated. [FEATURE]: Dynamic Client Registration (RFC 7591) for OAuth-protected MCP servers #5720 specifies a mandatory confirmation before registration on the grounds that DCR creates a persistent side effect at the provider, and the shipped behaviour does not do that. Worth deciding whether CIMD detection runs ahead of the existing auto-register branch or replaces it.
No CIMD implementation exists yet. Grepping
client_id_metadata,client-id-metadataandcimdacrossmcpgateway/anddocs/returns nothing.Cross-linked this issue into #5716 and #5720 so the deprecation context is discoverable from the OAuth registration epic.
- added a parent issue
on Sep 7, 2026 - addedclient-mrkHigh priority itemsHigh priority itemsSHOULDP2: Important but not vital; high-value items that are not crucial for the immediate releaseP2: Important but not vital; high-value items that are not crucial for the immediate releasework-queueIssues currently being actively triaged and sorted for work.Issues currently being actively triaged and sorted for work.
on Oct 5, 2026
Metadata
Metadata
Assignees
Labels
CF-CONTROL-PLANEAdministrative interface to configure CF.Administrative interface to configure CF.SHOULDP2: Important but not vital; high-value items that are not crucial for the immediate releaseP2: Important but not vital; high-value items that are not crucial for the immediate releaseclient-mrkHigh priority itemsHigh priority itemsmcp-2026-07-28Issues related to compliance with MCP 2026-07-28Issues related to compliance with MCP 2026-07-28oauth-oidcOAuth/OIDC related issues and PRsOAuth/OIDC related issues and PRspythonPython / backend development (FastAPI)Python / backend development (FastAPI)work-queueIssues currently being actively triaged and sorted for work.Issues currently being actively triaged and sorted for work.
Part of #5677
Scope
Implement this in the Python ContextForge control plane (
IBM/mcp-context-forge). The control plane owns OAuth/OIDC client registration, authorization routes, credential persistence, and compatibility fallbacks.No Rust dataplane implementation is required. The dataplane consumes authenticated requests and must not become an IAM or OAuth client-registration service.
Spec link: https://modelcontextprotocol.io/specification/2026-07-28/changelog
Comprised of: Deprecated change 4 (deprecate OAuth 2.0 Dynamic Client Registration, RFC 7591 — spec PR modelcontextprotocol/modelcontextprotocol#2858).
Coordinates with: #5684 (
application_typestill applies on the DCR fallback path).What the spec says
Control-plane work
application_typebehavior on the DCR fallback path.Acceptance criteria
application_typeand a safe deprecation notice.Out of scope