Repository navigation
[Server][Auth] SEP-2350: Emit per-operation scopes in insufficient_scope 403 responses (RFC 6750 §3.1) #362
Description
Activity
- addedServerIssues & PRs related to the Server componentIssues & PRs related to the Server componentP1Significant bug affecting many users, highly requested featureSignificant bug affecting many users, highly requested featureauthIssues and PRs related to Authentication / OAuthIssues and PRs related to Authentication / OAuthimproves spec complianceImproves consistency with other SDKs such as TyepScriptImproves consistency with other SDKs such as TyepScriptenhancementRequest for a new feature that's not currently supportedRequest for a new feature that's not currently supported
on May 26, 2026 - added a parent issue
on May 26, 2026 - added2026-07-28All issues and PRs related to the spec release 2026-07-28All issues and PRs related to the spec release 2026-07-28
on May 26, 2026 I'd like to work on this. I checked the current
main, and most of the server-side SEP-2350 path is already in place:JwtTokenValidator::requireScopes()puts the operation's full required scope set on the 403 result, andAuthorizationMiddlewareprefers those result scopes.The remaining edge case is
AuthorizationResult::forbidden()without scopes.AuthorizationMiddleware::resolveScopes()then falls back to the resource-widescopes_supported, so a 403 can advertise unrelated scopes instead of the requirements for the current operation.I propose keeping the
scopes_supportedfallback for initial 401 challenges, while making 403 challenges use only scopes explicitly carried byAuthorizationResult. If a custom validator returns a 403 without scopes, the header would omitscoperather than infer it from PRM. This preserves the current public factory and is allowed by RFC 6750, where the 403scopeattribute is optional.I'd cover explicit per-operation scopes, omitted scope on a scope-less 403, and unchanged 401 fallback behavior. Does that match the intended scope for this issue?
- removedP1Significant bug affecting many users, highly requested featureSignificant bug affecting many users, highly requested feature
on Aug 19, 2026 Already correctly scoped since the OAuth middleware landed in #221 —
JwtTokenValidator::requireScopes()reports only the scopes required for the current operation, never a cumulative set. No change needed.- moved this from Todo to Done in 2026-07-28 Spec Implementation
on Aug 19, 2026
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsDone
Implements the server-side portion of SEP-2350 for the MCP Spec 2026-07-28 release.
Tracked by umbrella #338. Client-side scope accumulation is covered by existing #322.
Spec summary
PHP SDK changes
src/Server/Transport/Http/OAuth/403 responses must emit ONLY the scopes required for the requested operation inWWW-Authenticate: Bearer error="insufficient_scope" scope="...".Related