Kong / Kong/developer.konghq.com
Add deprecation label to MCP Oauth2 plugin
- Dominant language
- Ruby
- Stars
- 28
- Forks
- 121
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 313
Description
## Definition of done
Based on: https://konghq.atlassian.net/browse/AG-1472?atlOrigin=eyJpIjoiMDJmYzZlMzUyYTEwNDYwZWE4ZjA3ZGFmYzMxNDllNzUiLCJwIjoiaiJ9
In both API GW 3.16 and AIGW (2.2 ?) updates to MCP and Oauth make the MCP Oauth2 plugin redundant. We expect ~6 month transition period. Note that this period also coincides with users migrating to the new stateless MCP spec (https://blog.mcpservers.org/posts/mcp-spec-2026-07-28).
- Add deprecation notices and tags on this page: https://developer.konghq.com/plugins/ai-mcp-oauth2/
- Identify impact on AIGW, there is no matching policy page but there are Oauth references throughout https://developer.konghq.com/ai-gateway/entities/ai-mcp-server/
- Create migration guide from configuring Oauth for MCP with the plugin to OIDC (using https://developer.konghq.com/plugins/openid-connect/)
## Information
## Due date (optional)
## Size
- L (Large) Example: adding an API/Terraform how to, writing a reference page, writing a how to that involves a known third-party product (like Okta or Auth0)
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the ai-mcp-oauth2 plugin page and the AI MCP server page, then review the linked OpenID Connect documentation and the referenced MCP and OAuth updates. Identify all affected OAuth references, add the deprecation notices and tags, and document migration from the plugin to OIDC. Done means the plugin and AIGW impacts are covered and the migration path is clear.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100