modelcontextprotocol / modelcontextprotocol/php-sdk
[Client] Add OAuth 2.0 credential storage interface (TokenStorageInterface)
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 1.6k
- Forks
- 173
- Avg merge
- 2d 49m
- Merged PRs (30d)
- 23
Description
Context
Foundation for every OAuth flow on the client side. Without a storage abstraction we cannot persist access tokens, refresh tokens, registered client credentials, or PKCE verifiers across requests/sessions.
Scope
- Define
Mcp\Client\Auth\TokenStorageInterfacewith operations:getToken(string $resourceUrl): ?TokenSet,storeToken(string $resourceUrl, TokenSet $token): void,clearToken(string $resourceUrl): void, plus equivalents for registered client metadata. - Value object
TokenSet(access_token, refresh_token, expires_at, scope, token_type). - Default implementations:
InMemoryTokenStorage(ephemeral, per-process).Psr16TokenStorageadapter for PSR-16CacheInterface.
- Wire into
Client\Builder::setTokenStorage(...)(optional; defaults to in-memory).
Conformance scenarios unblocked
Prerequisite for all auth/* baseline scenarios.
Dependencies
None — must land first.
Acceptance
- Interface + value object + 2 storage adapters in
src/Client/Auth/. - Unit tests for both adapters.
- Builder method documented.
cc @soyuka
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with Client\Builder and the auth/* baseline scenarios, then inspect the src/Client/Auth/ area. Track the interface, TokenSet, both adapters, builder wiring, and unit tests against the listed operations and acceptance criteria; done when optional builder configuration and its documentation are covered.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- api, authentication
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100