[Client] Implement Cross-App Access (token exchange, RFC 8693)
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- php
- Domain
- api, authentication
Research direction
Start with Mcp\Client\Auth\Grant\TokenExchangeGrant and review dependencies #321 and #318 for token-endpoint authentication and builder requirements. Use the stated request parameters as the target shape, add unit coverage for that shape, and run the auth/cross-app-access-complete-flow conformance scenario; done means the scenario passes.
Written by the indexing model from the issue text.
Description
Context
Cross-App Access (XAA) lets an MCP client present an existing IdP id_token to the MCP server's authorization server to obtain a scoped access token for the MCP resource. Uses grant_type=urn:ietf:params:oauth:grant-type:token-exchange (RFC 8693).
Scope
Mcp\Client\Auth\Grant\TokenExchangeGrant:- Body params:
grant_type=urn:ietf:params:oauth:grant-type:token-exchange,subject_token=<idp_id_token>,subject_token_type=urn:ietf:params:oauth:token-type:id_token,audience=<mcp_resource>, optionalscope. - Authenticate to token endpoint per #321.
- Body params:
- Builder API to supply IdP id_token + IdP issuer/token_endpoint discovery (needed by the conformance harness; see #325).
Conformance scenarios unblocked
auth/cross-app-access-complete-flow.
Dependencies
Blocked by: #321, #318.
Acceptance
- Unit tests for token exchange request shape.
- Conformance: scenario passes.
cc @soyuka
- Dominant language
- PHP
- Stars
- 1.6k
- Forks
- 173
- Avg merge
- 2d 49m
- Merged PRs (30d)
- 23
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from modelcontextprotocol/php-sdk
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStan OpenServer
Difficulty 1/5 Under an hour Newbie friendliness 78/100
modelcontextprotocol/php-sdk#468 · 2 comments ·
-
needs confirmation needs maintainer action Server
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
modelcontextprotocol/php-sdk#398 · 1 reaction ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
modelcontextprotocol/php-sdk#370 ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 55/100
modelcontextprotocol/php-sdk#510 · 1 comment ·
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 45/100
modelcontextprotocol/php-sdk#504 ·
All issues in modelcontextprotocol/php-sdk
Similar issues
-
jira-created
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Difficulty 1/5 Under an hour Newbie friendliness 70/100
nunomaduro/phpinsights#745 ·
-
status/awaiting_triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
WordPress/plugin-check#1486 ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
az-digital/az_quickstart#6019 ·