[2026-07-28] Authorization hardening (OAuth/OIDC)

Open
#338 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Quiet
Tech stack
php

Research direction

Start by reviewing sub-issues #360–#364 and the related OAuth backlog #315–#326, then read the linked SEP references and existing authorization implementation. This tracking issue is complete when its five sub-issues are resolved and the listed PRM and WWW-Authenticate audits are finished.

Written by the indexing model from the issue text.

Description

2026-07-28 auth Client enhancement improves spec compliance Server

Tracking issue for the MCP Spec 2026-07-28 releaseAuthorization hardening milestone.

Most of this milestone overlaps with the existing client-OAuth backlog (#315–#326). New SEP-specific work concentrates on issuer validation, AS-binding semantics, server-side scope emission, and OIDC offline_access handling.

SEPs covered

SEP Title Spec PR Coverage
SEP-2468 Recommend iss Parameter (RFC 9207) #2468 New issue
SEP-2352 Authorization Server binding and migration #2352 New issue
SEP-2351 RFC 8414 well-known URI suffix #2351 Covered by #318
SEP-2350 Client-side scope accumulation in step-up #2350 Client covered by #322; new server-side issue
SEP-2207 OIDC-flavored refresh token guidance #2207 New issues (client + server)
SEP-837 OIDC application_type during DCR #837 Covered by #320 + #321

Sub-issues

  • #360 — SEP-2468: Validate iss parameter in authorization response (client)
  • #361 — SEP-2352: Key DCR/tokens by AS issuer; reject cross-AS reuse (client)
  • #362 — SEP-2350: Emit per-operation scopes in insufficient_scope 403 responses (server)
  • #363 — SEP-2207: Request offline_access against OIDC-flavored AS (client)
  • #364 — SEP-2207: Audit PRM to ensure offline_access is not advertised as required (server)

Existing issues to annotate with SEP refs

  • #315 (TokenStorage) → SEP-2352
  • #318 (RFC 8414 AS metadata) → SEP-2351
  • #319 (Auth Code + PKCE) → SEP-2468, SEP-2207
  • #320 (DCR) → SEP-2352, SEP-837
  • #321 (token_endpoint_auth_method) → SEP-837
  • #322 (scope handling/step-up) → SEP-2350
  • #323 (refresh_token grant) → SEP-2207

Notes

  • All six SEPs are merged.
  • PHP SDK client-side OAuth is largely unimplemented; the bulk of work is therefore on the client side via the existing #315–#326 backlog plus the new SEP-specific issues above. Server-side OAuth middleware needs targeted PRM/WWW-Authenticate audits only.
Dominant language
PHP
Stars
1.6k
Forks
173
Avg merge
2d 49m
Merged PRs (30d)
23

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from modelcontextprotocol/php-sdk

All issues in modelcontextprotocol/php-sdk

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.