Support for Device Code Flow for MCP OAuth authentication

Open
#18 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Quiet

Research direction

Start by reading the MCP Specification's OAuth authentication requirements and identify how browser-based authorization is currently defined. Done means the specification clearly defines Device Code Flow support for headless, remote, and CI environments, including its required behavior and integration points.

Written by the indexing model from the issue text.

Description

enhancement

Is your feature request related to a problem? Please describe.
Currently, MCP ONLY supports browser-based authentication via OAuth which is limiting in a number of environments (headless, remote, CI, etc.). Adding support for Device Code Flow would be a huge quality of life improvement

Describe the solution you'd like
Add support for Device Code Flow the the MCP Specification

Describe alternatives you've considered
N/A

Additional context
N/A

Dominant language
MDX
Stars
164
Forks
54
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from modelcontextprotocol/ext-auth

All issues in modelcontextprotocol/ext-auth

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.