Skip to content

[Deprecated-3][CONTROL-PLANE] DCR → Client ID Metadata Documents #5692

Description

@Lang-Akshay

Part of #5677

Scope

Implement this in the Python ContextForge control plane (IBM/mcp-context-forge). The control plane owns OAuth/OIDC client registration, authorization routes, credential persistence, and compatibility fallbacks.

No Rust dataplane implementation is required. The dataplane consumes authenticated requests and must not become an IAM or OAuth client-registration service.

Spec link: https://modelcontextprotocol.io/specification/2026-07-28/changelog
Comprised of: Deprecated change 4 (deprecate OAuth 2.0 Dynamic Client Registration, RFC 7591 — spec PR modelcontextprotocol/modelcontextprotocol#2858).
Coordinates with: #5684 (application_type still applies on the DCR fallback path).

What the spec says

  • The OAuth 2.0 Dynamic Client Registration Protocol (RFC 7591) is deprecated as a client registration mechanism in favor of Client ID Metadata Documents (CIMD).
  • DCR remains available for backward compatibility with authorization servers that do not support Client ID Metadata Documents.

Control-plane work

  • Implement CIMD-based client registration as the preferred Python control-plane path.
  • Publish the control plane's client metadata document at a stable, documented HTTPS URL.
  • Detect authorization-server CIMD support and fall back to DCR only when CIMD is unsupported.
  • Keep the [Minor-1] OAuth hardening #5684 application_type behavior on the DCR fallback path.
  • Store and retrieve registration metadata through the existing control-plane auth/credential services.
  • Emit a safe deprecation notice when DCR fallback is used; do not log client secrets or tokens.
  • Update control-plane configuration, API documentation, and OAuth integration tests.

Acceptance criteria

  • CIMD registration works through the Python control-plane authentication flow against a CIMD-capable authorization server.
  • The published client metadata document is stable, valid, and covered by tests.
  • Non-CIMD authorization servers use the existing DCR fallback with application_type and a safe deprecation notice.
  • Credentials remain issuer-bound and are persisted only through control-plane auth services.
  • No Rust dataplane OAuth registration, credential storage, or IAM behavior is introduced.

Out of scope

  • Rust dataplane changes.
  • MCP transport/session compatibility work unrelated to OAuth client registration.

Activity

  1. added
    rustRust programming
    CF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.
    mcp-2026-07-28Issues related to compliance with MCP 2026-07-28
    on Jul 17, 2026
  2. self-assigned this
    on Aug 6, 2026
  3. changed the title [-][Deprecated-3] DCR → Client ID Metadata Documents[/-] [+][Deprecated-3][CONTROL-PLANE] DCR → Client ID Metadata Documents[/+] on Aug 11, 2026
  4. added
    pythonPython / backend development (FastAPI)
    oauth-oidcOAuth/OIDC related issues and PRs
    CF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.
    and removed
    rustRust programming
    CF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.
    on Aug 11, 2026
  5. 3 remaining items

  6. added
    2.0CF1.5 with the bolt on external data plane + Redis as a communication channel
    and removed
    triageIssues / Features awaiting triage
    on Aug 20, 2026
  7. added
    CF-BUILTIN-DATAPLANEDataplane which is an internal part of CF and shipped as one with the control plane
    CF-CONTROL-PLANEAdministrative interface to configure CF.
    and removed
    CF-EXTERNAL-DATAPLANEExternal dataplane which can extend ContextForge functionality.
    2.0CF1.5 with the bolt on external data plane + Redis as a communication channel
    CF-BUILTIN-DATAPLANEDataplane which is an internal part of CF and shipped as one with the control plane
    on Aug 20, 2026
  8. a-effort commented on Aug 28, 2026

    @a-effort
    Collaborator

    Context on the fallback path this issue assumes exists: DCR has shipped and is on by default, so the "fall back to DCR only when CIMD is unsupported" branch will be falling back into live code rather than into something that still needs building.

    Current state:

    • mcpgateway/services/dcr_service.py implements RFC 7591 registration, RFC 8414 AS metadata discovery, and client persistence, update and delete.
    • DCR_ENABLED and DCR_AUTO_REGISTER_ON_MISSING_CREDENTIALS both default to true (config.py:1008, :1011).
    • /oauth/authorize/{gateway_id} auto-registers whenever a gateway has an issuer and no client_id (oauth_router.py:670), then persists the credentials and sets auth_type=oauth.
    • Registered clients live in registered_oauth_clients, with list, per-gateway lookup and delete exposed under /oauth/registered-clients.
    • Registration sends redirect_uri programmatically, so operators of DCR-capable providers never see or copy it.

    A couple of things that may affect the acceptance criteria:

    • "Emit a safe deprecation notice when DCR fallback is used" is not satisfied today. The auto-register path logs success at info level with no deprecation signal, and nothing surfaces to the user.
    • The fallback is currently silent and automatic rather than user-initiated. [FEATURE]: Dynamic Client Registration (RFC 7591) for OAuth-protected MCP servers #5720 specifies a mandatory confirmation before registration on the grounds that DCR creates a persistent side effect at the provider, and the shipped behaviour does not do that. Worth deciding whether CIMD detection runs ahead of the existing auto-register branch or replaces it.

    No CIMD implementation exists yet. Grepping client_id_metadata, client-id-metadata and cimd across mcpgateway/ and docs/ returns nothing.

    Cross-linked this issue into #5716 and #5720 so the deprecation context is discoverable from the OAuth registration epic.

  9. added
    SHOULDP2: Important but not vital; high-value items that are not crucial for the immediate release
    work-queueIssues currently being actively triaged and sorted for work.
    on Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    CF-CONTROL-PLANEAdministrative interface to configure CF.SHOULDP2: Important but not vital; high-value items that are not crucial for the immediate releaseclient-mrkHigh priority itemsmcp-2026-07-28Issues related to compliance with MCP 2026-07-28oauth-oidcOAuth/OIDC related issues and PRspythonPython / backend development (FastAPI)work-queueIssues currently being actively triaged and sorted for work.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions