Skip to content

[Client] Implement Authorization Server Metadata discovery (RFC 8414) #318

Description

@soyuka

Context

Once the AS issuer is known (from PRM), the client must fetch its metadata at /.well-known/oauth-authorization-server (RFC 8414) to learn the authorization_endpoint, token_endpoint, registration_endpoint, scopes_supported, token_endpoint_auth_methods_supported, and grant_types_supported.

Scope

  • Mcp\Client\Auth\AuthorizationServerMetadataDiscoverer.
  • Cache resolved metadata per issuer (TTL via PSR-16 if TokenStorage is backed by it).
  • Fall back to OpenID Connect discovery (/.well-known/openid-configuration) when RFC 8414 endpoint 404s.

Conformance scenarios unblocked

auth/metadata-* (full set), auth/scope-from-scopes-supported.

Dependencies

Blocked by: #317 (PRM provides the issuer URL).

Acceptance

  • Unit tests covering RFC 8414 + OIDC fallback.
  • Reuses existing Mcp\Server\Transport\Http\OAuth\OidcDiscovery for shape parity if practical.

cc @soyuka

Activity

  1. added
    ClientIssues & PRs related to the Client component
    P1Significant bug affecting many users, highly requested feature
    authIssues and PRs related to Authentication / OAuth
    improves spec complianceImproves consistency with other SDKs such as TyepScript
    enhancementRequest for a new feature that's not currently supported
    on May 19, 2026
  2. chr-hertel commented on May 26, 2026

    @chr-hertel
    Member

    Cross-reference: this work fully covers SEP-2351 for the MCP Spec 2026-07-28 release — the spec clarifies that MCP uses the default RFC 8414 oauth-authorization-server well-known suffix with path-insertion semantics (not naive append) for issuers with path components.

    Please ensure the implementation follows RFC 8414 §3.1 path-insertion. See umbrella #338.

  3. removed
    P1Significant bug affecting many users, highly requested feature
    on Aug 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ClientIssues & PRs related to the Client componentauthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedimproves spec complianceImproves consistency with other SDKs such as TyepScript

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions