Azure / Azure/CosmosDBShell

M7. MCP authorization (OAuth code flow)

Open
#159 2 comments 0 reactions 0 assignees View on GitHub
agentic enhancement P1
Dominant language
C#
Stars
3
Forks
7
Avg merge
1d 9h
Merged PRs (30d)
18

Description

## Why

Today the MCP server relies solely on **origin-header validation** and localhost binding — safe for a single-user local machine, but there is **no authorization layer**. Any **remote, hosted, or shared** agent deployment (team agent, CI runner, cloud-hosted assistant) currently has no supported way to authenticate a caller. The MCP spec defines an **OAuth 2.1 authorization-code flow** for exactly this; adopting it unlocks hosted/agentic scenarios without falling back to master keys.

This is the natural companion to confirmation/elicitation (item M3): authorization answers *"who is allowed to call,"* M3 answers *"what may they do."*

## Proposed behavior

- Implement the MCP **authorization-code flow** for the HTTP transport: advertise the authorization server, validate bearer tokens on each request, and map the authenticated identity onto the shell's existing Entra/RBAC connection so tool calls run with **least-privilege, per-caller** credentials rather than a shared session.
- Keep localhost/no-auth as an explicit opt-in for the current single-user experience.

## Acceptance criteria

- Unauthenticated remote requests are rejected.
- A client can complete the authorization-code flow and call tools with a bearer token.
- Identity flows to the Cosmos/ARM credential.
- Localhost no-auth mode preserved behind a flag.
- Threat model + `docs/mcp.md` updated.

---
_Filed from the Agentic & Automation Roadmap (`docs/agentic-roadmap.md`), item **M7**, Wave 2. Priority P1._

Contributor guide

Open the contributing guide

Research direction

Start with docs/mcp.md and docs/agentic-roadmap.md, especially roadmap item M7, then trace the HTTP transport and existing Entra/RBAC credential path. Done means remote unauthenticated requests are rejected, bearer-token authorization works, identity reaches Cosmos/ARM credentials, localhost no-auth remains flag-gated, and the threat model and documentation are updated.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, csharp
Domain
authentication, authorization, cli, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.