modelcontextprotocol / modelcontextprotocol/php-sdk

[Client] Implement Authorization Server Metadata discovery (RFC 8414)

Open
#318 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

auth Client enhancement improves spec compliance
Dominant language
PHP
Stars
1.6k
Forks
173
Avg merge
2d 49m
Merged PRs (30d)
23

Description

Context

Once the AS issuer is known (from PRM), the client must fetch its metadata at /.well-known/oauth-authorization-server (RFC 8414) to learn the authorization_endpoint, token_endpoint, registration_endpoint, scopes_supported, token_endpoint_auth_methods_supported, and grant_types_supported.

Scope

  • Mcp\Client\Auth\AuthorizationServerMetadataDiscoverer.
  • Cache resolved metadata per issuer (TTL via PSR-16 if TokenStorage is backed by it).
  • Fall back to OpenID Connect discovery (/.well-known/openid-configuration) when RFC 8414 endpoint 404s.

Conformance scenarios unblocked

auth/metadata-* (full set), auth/scope-from-scopes-supported.

Dependencies

Blocked by: #317 (PRM provides the issuer URL).

Acceptance

  • Unit tests covering RFC 8414 + OIDC fallback.
  • Reuses existing Mcp\Server\Transport\Http\OAuth\OidcDiscovery for shape parity if practical.

cc @soyuka

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing Mcp\Client\Auth\AuthorizationServerMetadataDiscoverer and the existing Mcp\Server\Transport\Http\OAuth\OidcDiscovery for compatible metadata shapes. Check the auth/metadata-* and auth/scope-from-scopes-supported conformance scenarios, then verify RFC 8414 discovery, OIDC fallback, issuer caching, and the requested unit-test coverage.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
api, authentication
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.