Skip to content

[Client] Support token_endpoint_auth_method: client_secret_basic, client_secret_post, none #321

Description

@soyuka

Context

Per RFC 6749 §2.3 (and AS metadata token_endpoint_auth_methods_supported), the client must send its credentials to the token endpoint using whichever method the AS advertises:

  • client_secret_basic → HTTP Basic Authorization: Basic base64(client_id:client_secret)
  • client_secret_post → form-encoded client_id + client_secret body params
  • none → public client; only client_id in body, no secret

Scope

  • Strategy interface TokenEndpointAuthInterface + three implementations.
  • Auto-select implementation based on AS metadata's preferred method (intersect with what the client supports/has).

Conformance scenarios unblocked

auth/token-endpoint-auth-basic, auth/token-endpoint-auth-post, auth/token-endpoint-auth-none.

Dependencies

Blocked by: #318, #319.

Acceptance

  • Unit tests per strategy.
  • Conformance: 3 baseline scenarios pass.

cc @soyuka

Activity

  1. added
    ClientIssues & PRs related to the Client component
    P1Significant bug affecting many users, highly requested feature
    authIssues and PRs related to Authentication / OAuth
    improves spec complianceImproves consistency with other SDKs such as TyepScript
    enhancementRequest for a new feature that's not currently supported
    on May 19, 2026
  2. chr-hertel commented on May 26, 2026

    @chr-hertel
    Member

    Cross-reference: this work covers SEP-837 for the MCP Spec 2026-07-28 release — the spec aligns MCP DCR with OIDC's application_type requirements, which in turn constrains the available token_endpoint_auth_method values (confidential web clients vs public native clients).

    Coordinate with #320 (DCR) which also covers SEP-837. See umbrella #338.

  3. removed
    P1Significant bug affecting many users, highly requested feature
    on Aug 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ClientIssues & PRs related to the Client componentauthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedimproves spec complianceImproves consistency with other SDKs such as TyepScript

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions