modelcontextprotocol / modelcontextprotocol/python-sdk
[v2] Add an end-to-end public-client PKCE server contract
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- Python
- Sterne
- 24.3k
- Forks
- 4k
- Ø Merge
- 1 T. 1 Std.
- Gemergte PRs (30 T.)
- 31
Beschreibung
What happened?
With mcp==2.1.1, an MCP authorization server still cannot advertise and register an OAuth public client consistently without downstream patching:
build_metadata()does not includenoneintoken_endpoint_auth_methods_supported.RegistrationHandlerdefaults an omittedtoken_endpoint_auth_methodtoclient_secret_post, minting a secret even for clients intending to operate as PKCE public clients.- The individual token handler pieces support
token_endpoint_auth_method="none"when it is explicitly supplied, but there is no end-to-end SDK test pinning discovery -> DCR -> authorization-code/PKCE token exchange for a public client.
This is related to #2260, which was closed, and #2261, which remains open. The inconsistency is still present in the published v2 SDK.
For a real MCP server integration, we currently have to monkeypatch metadata generation and DCR's omitted-method behavior at import time. Those patches depend on private implementation details and are difficult to remove safely without a supported end-to-end public-client contract.
What did you expect?
The v2 server auth surface should support a complete public-client PKCE flow without monkeypatching:
- Authorization-server metadata advertises
none. - DCR preserves an explicit
token_endpoint_auth_method="none"and has a documented, interoperable default for omitted methods. - The token endpoint accepts the registered public client without a client secret and verifies the PKCE
code_verifieragainst the authorization code's challenge. - An SDK integration test covers the full flow so future releases do not regress it.
Merging or superseding #2261 plus adding the end-to-end test would provide a clear downstream exit condition.
Code to reproduce
from mcp.server.auth.handlers.register import RegistrationHandler
from mcp.server.auth.routes import build_metadata
# In mcp==2.1.1:
# - build_metadata() omits "none" from token_endpoint_auth_methods_supported
# - RegistrationHandler.handle defaults an omitted token_endpoint_auth_method
# to "client_secret_post"
SDK version
2.1.1
Area
Auth
Related
- #2260
- #2261
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne mit mcp.server.auth.routes.build_metadata und mcp.server.auth.handlers.register.RegistrationHandler und verfolge anschließend die Token-Handler für Authorization Code/PKCE sowie die vorhandenen SDK-Auth-Tests. Die Arbeit ist abgeschlossen, wenn die Discovery keine Methoden ankündigt, die Registrierung explizit angegebene und weggelassene Methoden konsistent behandelt, der Token-Austausch den PKCE code_verifier ohne ein Secret verifiziert und ein End-to-End-Integrationstest den Ablauf abdeckt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- python
- Bereich
- authentication, backend-api-design, security
- Issue-Typ
- Feature
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Aktiv
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 50/100