modelcontextprotocol / modelcontextprotocol/php-sdk

[2026-07-28] Authorization hardening (OAuth/OIDC)

Open
#338 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

2026-07-28 auth Client enhancement improves spec compliance Server
Dominant language
PHP
Stars
1.6k
Forks
173
Avg merge
2d 49m
Merged PRs (30d)
23

Description

Tracking issue for the MCP Spec 2026-07-28 releaseAuthorization hardening milestone.

Most of this milestone overlaps with the existing client-OAuth backlog (#315–#326). New SEP-specific work concentrates on issuer validation, AS-binding semantics, server-side scope emission, and OIDC offline_access handling.

SEPs covered

SEP Title Spec PR Coverage
SEP-2468 Recommend iss Parameter (RFC 9207) #2468 New issue
SEP-2352 Authorization Server binding and migration #2352 New issue
SEP-2351 RFC 8414 well-known URI suffix #2351 Covered by #318
SEP-2350 Client-side scope accumulation in step-up #2350 Client covered by #322; new server-side issue
SEP-2207 OIDC-flavored refresh token guidance #2207 New issues (client + server)
SEP-837 OIDC application_type during DCR #837 Covered by #320 + #321

Sub-issues

  • #360 — SEP-2468: Validate iss parameter in authorization response (client)
  • #361 — SEP-2352: Key DCR/tokens by AS issuer; reject cross-AS reuse (client)
  • #362 — SEP-2350: Emit per-operation scopes in insufficient_scope 403 responses (server)
  • #363 — SEP-2207: Request offline_access against OIDC-flavored AS (client)
  • #364 — SEP-2207: Audit PRM to ensure offline_access is not advertised as required (server)

Existing issues to annotate with SEP refs

  • #315 (TokenStorage) → SEP-2352
  • #318 (RFC 8414 AS metadata) → SEP-2351
  • #319 (Auth Code + PKCE) → SEP-2468, SEP-2207
  • #320 (DCR) → SEP-2352, SEP-837
  • #321 (token_endpoint_auth_method) → SEP-837
  • #322 (scope handling/step-up) → SEP-2350
  • #323 (refresh_token grant) → SEP-2207

Notes

  • All six SEPs are merged.
  • PHP SDK client-side OAuth is largely unimplemented; the bulk of work is therefore on the client side via the existing #315–#326 backlog plus the new SEP-specific issues above. Server-side OAuth middleware needs targeted PRM/WWW-Authenticate audits only.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing sub-issues #360–#364 and the related OAuth backlog #315–#326, then read the linked SEP references and existing authorization implementation. This tracking issue is complete when its five sub-issues are resolved and the listed PRM and WWW-Authenticate audits are finished.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.