You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(cmid-server): Implement Server-Side Support for Client ID Metadata Documents (CIMD) - #1810
Implement Server-Side Support for Client ID Metadata Documents (CIMD)
Motivation and Context
This PR addresses issue #1801 by implementing server-side support for Client ID Metadata Documents (CIMD), as defined in SEP-991 and the MCP authorization specification.
Previously, the Authorization Server logic in the Python SDK could not resolve or validate clients that identify themselves via a URL (CIMD). This change enables the server to:
Advertise Support: Tells clients the server supports CIMD by adding client_id_metadata_document_supported: True to the server metadata.
Dynamic Resolution: Detects when a client_id is an HTTPS URL during the authorization flow.
Fetch & Validate: Fetches the metadata document from the provided URL and validates that the client_id inside the document matches the request.
Fallback Mechanism: If a client is not found in the static provider registry, it attempts to resolve it as a CIMD before returning an error.
How Has This Been Tested?
Added Unit Test Cases for the CIMD Server authorization flow -
test_cimd_authorization_flow
test_cimd_authorization_invalid_cimd_url
test_cimd_authorization_invalid_client_id
test_cimd_authorization_metadata_fetch_error
Breaking Changes
No
Types of changes
New feature (non-breaking change which adds functionality)
maxisbey
added
enhancement
Request for a new feature that's not currently supported
auth
Issues and PRs related to Authentication / OAuth
P2
Moderate issues affecting some users, edge cases, potentially valuable feature
labels
Dec 31, 2025
The /authorize fallback resolves URL client IDs, but /token still goes through ClientAuthenticator, which calls OAuthAuthorizationServerProvider.get_client() and rejects with "Invalid client_id" when it returns None. The fetched client isn't persisted through any provider method, so the token step has nothing to find.
Could ClientAuthenticator use the same URL client ID resolution path so CIMD clients work at /token? Please add a test that exercises /authorize followed by /token for a CIMD client. The token handler's jwt-bearer check (see #3598) also needs to allow CIMD clients without a stored shared secret.
Separately, per draft-ietf-oauth-client-id-metadata-document-00:
§6.5: the outbound fetch SHOULD avoid private and loopback addresses. The current fetch has no such check.
§6.6: the response SHOULD be limited to 5 KB. The current fetch has no size limit.
§4.4: error responses and malformed documents MUST NOT be cached. Caching isn't implemented yet, so this applies when it is.
The fetch also uses httpx's default timeout implicitly. Setting an explicit timeout on httpx.AsyncClient for the metadata fetch would make that bound visible and deliberate.
This branch has not been deployed
No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
authIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedP2Moderate issues affecting some users, edge cases, potentially valuable feature
3 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implement Server-Side Support for Client ID Metadata Documents (CIMD)
Motivation and Context
This PR addresses issue #1801 by implementing server-side support for Client ID Metadata Documents (CIMD), as defined in SEP-991 and the MCP authorization specification.
Previously, the Authorization Server logic in the Python SDK could not resolve or validate clients that identify themselves via a URL (CIMD). This change enables the server to:
How Has This Been Tested?
Added Unit Test Cases for the CIMD Server authorization flow -
Breaking Changes
No
Types of changes
Checklist