Skip to content

[2026-07-28] Authorization hardening (OAuth/OIDC) #338

Description

@chr-hertel

Tracking issue for the MCP Spec 2026-07-28 releaseAuthorization hardening milestone.

Most of this milestone overlaps with the existing client-OAuth backlog (#315#326). New SEP-specific work concentrates on issuer validation, AS-binding semantics, server-side scope emission, and OIDC offline_access handling.

SEPs covered

SEP Title Spec PR Coverage
SEP-2468 Recommend iss Parameter (RFC 9207) #2468 New issue
SEP-2352 Authorization Server binding and migration #2352 New issue
SEP-2351 RFC 8414 well-known URI suffix #2351 Covered by #318
SEP-2350 Client-side scope accumulation in step-up #2350 Client covered by #322; new server-side issue
SEP-2207 OIDC-flavored refresh token guidance #2207 New issues (client + server)
SEP-837 OIDC application_type during DCR #837 Covered by #320 + #321

Sub-issues

Existing issues to annotate with SEP refs

Notes

Metadata

Metadata

Assignees

No one assigned

    Labels

    2026-07-28All issues and PRs related to the spec release 2026-07-28ClientIssues & PRs related to the Client componentP0Broken core functionality, security issues, critical missing featureServerIssues & PRs related to the Server componentauthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedimproves spec complianceImproves consistency with other SDKs such as TyepScript

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions