Enterprise-Managed Authorization: say how the Resource Authorization Server gets the IdP's signing keys
@pcarleton já está trabalhando nisso.
Desde 6/10/2026.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 45/100
- Tipo de issue
- Documentação
- Clareza
- Razoavelmente clara
- Status de atividade
- Ativa
- Domínio
- authentication, authorization, documentation, security
Direção de pesquisa
Start with section 5.1 and the referenced ID-JAG §4.4.1, then compare the OpenID Connect Discovery and RFC 8414 metadata requirements. Done means the specification explains how the Resource Authorization Server obtains signing keys and includes the proposed User-Agent guidance, with the origin, rotation, and multi-tenant questions resolved.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Problem
Section 5.1 sends ID-JAG processing to §4.4.1 of draft-ietf-oauth-identity-assertion-authz-grant-04, which requires a valid signature. Neither document says how the Resource Authorization Server finds the IdP's signing keys. The draft assumes the Resource Authorization Server already trusts the IdP, but trusting an issuer doesn't tell you where its keys are.
We implement this extension in Notion's hosted MCP server and have tested it against several IdPs. Each implementation has to choose, on its own:
- how to find the keys (
jwks_urifrom OpenID Connect Discovery, from RFC 8414 metadata, or configured by hand); - whether
jwks_urimust be on the issuer's origin; - when to refetch keys after rotation;
- how to handle multi-tenant issuers.
One failure from our testing shows the cost. An IdP behind a CDN web application firewall returned 403 to our JWKS fetch, because the library making it sent no User-Agent. Our discovery fetch to the same host sent one and got 200. Nothing in the spec chain told either side what to expect. (Library fix: cloudflare/workers-oauth-provider#394.)
Proposal
Additive, no breaking changes. In section 5.1:
- The Resource Authorization Server SHOULD get the IdP's signing keys from the
jwks_uriin the metadata for the ID-JAG'siss, found with OpenID Connect Discovery 1.0 or RFC 8414. - A non-normative note: metadata, JWKS, and Client ID Metadata Document fetches are ordinary HTTP requests, so they SHOULD include a
User-Agentper RFC 9110 §10.1.5. IdPs commonly sit behind firewalls that block requests without one.
Open questions
- Should rule 1 live here, or in the ID-JAG draft so it covers non-MCP uses too?
- Should
jwks_urihave to share the issuer's origin? We require it today. It narrows where keys can come from, but some IdPs may host keys on a separate domain. - Is refetch-on-unknown-
kidguidance for key rotation in scope?
This looks to us like a clarification that doesn't need a SEP. We're happy to follow the SEP process if the maintainers prefer, and to send a PR with the wording.
- Linguagem predominante
- MDX
- Estrelas
- 165
- Forks
- 54
- Métricas de merge de PRs
- Nenhum PR com merge em 30d
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de modelcontextprotocol/ext-auth
-
enhancement
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 25/100
modelcontextprotocol/ext-auth#32 · 1 comentário ·
-
DEBUGAbertabug
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 10/100
-
Add Authorization Flow for MCP client server hosts extensionTalvez já em andamento @sberyozkin assumiu há 183 dias. Abertaenhancement
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 30/100
modelcontextprotocol/ext-auth#26 · 1 comentário ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 35/100
-
enhancement
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 25/100
modelcontextprotocol/ext-auth#21 · 1 comentário ·
Todas as issues de modelcontextprotocol/ext-auth
Issues semelhantes
-
status: waiting-for-triage type: bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
spring-projects/spring-security#19847 ·
Mantenedores costumam responder em até 1 dia
-
area:auth bug triage:confirmed
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Cotal-AI/Cotal#3414 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
architecture
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
DiegoMicali/MovieFlix#16 ·
-
area/auth area/billing comp/agent duplicate P2 provider/anthropic sweeper:risk-security-boundary type/bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 63/100
NousResearch/hermes-agent#134897 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
area/rules
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
usnistgov/macos_security#843 ·
Mantenedores costumam responder em até 1 dia