Skip to content

[2026-07-28] Authorization hardening (OAuth/OIDC) #338

@chr-hertel

Description

@chr-hertel

Tracking issue for the MCP Spec 2026-07-28 releaseAuthorization hardening milestone.

Most of this milestone overlaps with the existing client-OAuth backlog (#315#326). New SEP-specific work concentrates on issuer validation, AS-binding semantics, server-side scope emission, and OIDC offline_access handling.

SEPs covered

SEP Title Spec PR Coverage
SEP-2468 Recommend iss Parameter (RFC 9207) #2468 New issue
SEP-2352 Authorization Server binding and migration #2352 New issue
SEP-2351 RFC 8414 well-known URI suffix #2351 Covered by #318
SEP-2350 Client-side scope accumulation in step-up #2350 Client covered by #322; new server-side issue
SEP-2207 OIDC-flavored refresh token guidance #2207 New issues (client + server)
SEP-837 OIDC application_type during DCR #837 Covered by #320 + #321

Sub-issues

Existing issues to annotate with SEP refs

Notes

Metadata

Metadata

Assignees

No one assigned

    Labels

    2026-07-28All issues and PRs related to the spec release 2026-07-28ClientIssues & PRs related to the Client componentP0Broken core functionality, security issues, critical missing featureServerIssues & PRs related to the Server componentauthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedimproves spec complianceImproves consistency with other SDKs such as TyepScript

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions