Skip to content

feat(cmid-server): Implement Server-Side Support for Client ID Metadata Documents (CIMD) - #1810

Open
punitmahes wants to merge 1 commit into
modelcontextprotocol:mainfrom
punitmahes:feat/server-cimd-support
Open

punitmahes wants to merge 1 commit into
modelcontextprotocol:mainfrom
punitmahes:feat/server-cimd-support

Conversation

@punitmahes

@punitmahes punitmahes commented Dec 20, 2025 •

Copy link
Copy Markdown

Implement Server-Side Support for Client ID Metadata Documents (CIMD)

Motivation and Context

This PR addresses issue #1801 by implementing server-side support for Client ID Metadata Documents (CIMD), as defined in SEP-991 and the MCP authorization specification.
Previously, the Authorization Server logic in the Python SDK could not resolve or validate clients that identify themselves via a URL (CIMD). This change enables the server to:

  • Advertise Support: Tells clients the server supports CIMD by adding client_id_metadata_document_supported: True to the server metadata.
  • Dynamic Resolution: Detects when a client_id is an HTTPS URL during the authorization flow.
  • Fetch & Validate: Fetches the metadata document from the provided URL and validates that the client_id inside the document matches the request.
  • Fallback Mechanism: If a client is not found in the static provider registry, it attempts to resolve it as a CIMD before returning an error.

How Has This Been Tested?

Added Unit Test Cases for the CIMD Server authorization flow -

  • test_cimd_authorization_flow
  • test_cimd_authorization_invalid_cimd_url
  • test_cimd_authorization_invalid_client_id
  • test_cimd_authorization_metadata_fetch_error

Breaking Changes

No

Types of changes

  • New feature (non-breaking change which adds functionality)

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@punitmahes
punitmahes force-pushed the feat/server-cimd-support branch from 86fce91 to fa13db7 Compare December 21, 2025 12:44
@maxisbey maxisbey added enhancement Request for a new feature that's not currently supported auth Issues and PRs related to Authentication / OAuth P2 Moderate issues affecting some users, edge cases, potentially valuable feature labels Dec 31, 2025
@punitmahes

Copy link
Copy Markdown
Author

@maxisbey Any updates on this PR?

@maxisbey
maxisbey requested a review from pcarleton March 6, 2026 10:59
@dougbyrne

Copy link
Copy Markdown

The /authorize fallback resolves URL client IDs, but /token still goes through ClientAuthenticator, which calls OAuthAuthorizationServerProvider.get_client() and rejects with "Invalid client_id" when it returns None. The fetched client isn't persisted through any provider method, so the token step has nothing to find.

Could ClientAuthenticator use the same URL client ID resolution path so CIMD clients work at /token? Please add a test that exercises /authorize followed by /token for a CIMD client. The token handler's jwt-bearer check (see #3598) also needs to allow CIMD clients without a stored shared secret.

Separately, per draft-ietf-oauth-client-id-metadata-document-00:

  • §6.5: the outbound fetch SHOULD avoid private and loopback addresses. The current fetch has no such check.
  • §6.6: the response SHOULD be limited to 5 KB. The current fetch has no size limit.
  • §4.4: error responses and malformed documents MUST NOT be cached. Caching isn't implemented yet, so this applies when it is.

The fetch also uses httpx's default timeout implicitly. Setting an explicit timeout on httpx.AsyncClient for the metadata fetch would make that bound visible and deliberate.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auth Issues and PRs related to Authentication / OAuth enhancement Request for a new feature that's not currently supported P2 Moderate issues affecting some users, edge cases, potentially valuable feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants