Skip to content

[2026-07-28] Authorization hardening (OAuth/OIDC) #338

Description

@chr-hertel

Tracking issue for the MCP Spec 2026-07-28 release — Authorization hardening milestone.

Most of this milestone overlaps with the existing client-OAuth backlog (#315–#326). New SEP-specific work concentrates on issuer validation, AS-binding semantics, server-side scope emission, and OIDC offline_access handling.

SEPs covered

SEP Title Spec PR Coverage
SEP-2468 Recommend iss Parameter (RFC 9207) #2468 New issue
SEP-2352 Authorization Server binding and migration #2352 New issue
SEP-2351 RFC 8414 well-known URI suffix #2351 Covered by #318
SEP-2350 Client-side scope accumulation in step-up #2350 Client covered by #322; new server-side issue
SEP-2207 OIDC-flavored refresh token guidance #2207 New issues (client + server)
SEP-837 OIDC application_type during DCR #837 Covered by #320 + #321

Sub-issues

Existing issues to annotate with SEP refs

Notes

Activity

  1. added
    ServerIssues & PRs related to the Server component
    ClientIssues & PRs related to the Client component
    P0Broken core functionality, security issues, critical missing feature
    authIssues and PRs related to Authentication / OAuth
    improves spec complianceImproves consistency with other SDKs such as TyepScript
    enhancementRequest for a new feature that's not currently supported
    on May 26, 2026
  2. added
    2026-07-28All issues and PRs related to the spec release 2026-07-28
    on May 26, 2026
  3. removed
    P0Broken core functionality, security issues, critical missing feature
    on Aug 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    2026-07-28All issues and PRs related to the spec release 2026-07-28ClientIssues & PRs related to the Client componentServerIssues & PRs related to the Server componentauthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedimproves spec complianceImproves consistency with other SDKs such as TyepScript

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions