Repository navigation
Implement support for the new authorization specification #686
Copy link
Copy link
Closed
Labels
P1Significant bug affecting many users, highly requested featureSignificant bug affecting many users, highly requested featureenhancementRequest for a new feature that's not currently supportedRequest for a new feature that's not currently supportedimproves sdk consistencyImproves consistency with other SDKs such as TyepscriptImproves consistency with other SDKs such as Tyepscriptready for workEnough information for someone to start working onEnough information for someone to start working on
Description
Activity
- added a commit that references this issue
on May 16, 2025 - addedenhancementRequest for a new feature that's not currently supportedRequest for a new feature that's not currently supportedready for workEnough information for someone to start working onEnough information for someone to start working onP0Broken core functionality, security issues, critical missing featureBroken core functionality, security issues, critical missing featureimproves sdk consistencyImproves consistency with other SDKs such as TyepscriptImproves consistency with other SDKs such as Tyepscript
on Oct 7, 2025 Relatively old issue, need to confirm whether this may have already been implemented potentially as part of one of these https://github.com/modelcontextprotocol/python-sdk/pulls?q=is%3Apr+9728+is%3Aclosed
The authorization specification has been fully implemented through several PRs over the past months, including:
- RFC 9728 Protected Resource Metadata (MCP server separation into Authorization Server (AS) and Resource Server (RS) roles per spec PR #338 #982, Improved supported for ProtectedResourceMetadata #1235, Improve OAuth protected resource metadata URL construction per RFC 9728 #1407, Implement SEP-985: OAuth Protected Resource Metadata discovery fallback #1548, Fix OAuth discovery fallback and URL ordering #1624)
- RFC 8414 Authorization Server Metadata
- RFC 7591 Dynamic Client Registration
- RFC 8707 Resource Indicators
- PKCE with S256
- Client ID Metadata Documents support
Closing as implemented.
- addedP1Significant bug affecting many users, highly requested featureSignificant bug affecting many users, highly requested featureand removedP0Broken core functionality, security issues, critical missing featureBroken core functionality, security issues, critical missing feature
on Feb 23, 2026
Metadata
Metadata
Assignees
Labels
P1Significant bug affecting many users, highly requested featureSignificant bug affecting many users, highly requested featureenhancementRequest for a new feature that's not currently supportedRequest for a new feature that's not currently supportedimproves sdk consistencyImproves consistency with other SDKs such as TyepscriptImproves consistency with other SDKs such as Tyepscriptready for workEnough information for someone to start working onEnough information for someone to start working on
Is your feature request related to a problem? Please describe.
Implement support for the draft authorization specification that was merged earlier last month.
Describe the solution you'd like
Implement supoprt for RFC9728, along with other requirements outlined in the spec.
Describe alternatives you've considered
N/A
Additional context