Repository navigation
Implement server-side support for Client ID Metadata Documents (CIMD) #1801
Copy link
Copy link
Open
Labels
P2Moderate issues affecting some users, edge cases, potentially valuable featureModerate issues affecting some users, edge cases, potentially valuable featureauthIssues and PRs related to Authentication / OAuthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedRequest for a new feature that's not currently supportedneeds decisionIssue is actionable, needs maintainer decision on whether to implementIssue is actionable, needs maintainer decision on whether to implement
Description
Activity
- addedauthIssues and PRs related to Authentication / OAuthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedRequest for a new feature that's not currently supportedready for workEnough information for someone to start working onEnough information for someone to start working onP0Broken core functionality, security issues, critical missing featureBroken core functionality, security issues, critical missing feature
on Dec 18, 2025 @maxisbey I would be happy to work upon this. Let me know if this is open for contribution.
- addedP2Moderate issues affecting some users, edge cases, potentially valuable featureModerate issues affecting some users, edge cases, potentially valuable featureand removedP0Broken core functionality, security issues, critical missing featureBroken core functionality, security issues, critical missing feature
on Jan 14, 2026 Thanks for the PR @punitmahes!
Is there anything I can do to help get this merged @maxisbey?
- addedneeds decisionIssue is actionable, needs maintainer decision on whether to implementIssue is actionable, needs maintainer decision on whether to implementand removedready for workEnough information for someone to start working onEnough information for someone to start working on
on Apr 17, 2026 #3598 is a use case to keep in mind here: the ID-JAG (
jwt-bearer) grant for Client ID Metadata Document clients, which authenticate withprivate_key_jwtor not at all. The token handler refuses that grant for any client without a stored shared secret, so that check needs another look when this lands.
Metadata
Metadata
Assignees
Labels
P2Moderate issues affecting some users, edge cases, potentially valuable featureModerate issues affecting some users, edge cases, potentially valuable featureauthIssues and PRs related to Authentication / OAuthIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supportedRequest for a new feature that's not currently supportedneeds decisionIssue is actionable, needs maintainer decision on whether to implementIssue is actionable, needs maintainer decision on whether to implement
Summary
PR #1652 implemented client-side support for Client ID Metadata Documents (CIMD) per SEP-991, but the server-side implementation is missing. Authorization servers built with the Python SDK cannot currently support CIMD.
Background
CIMD (draft-ietf-oauth-client-id-metadata-document-00) allows OAuth clients to use HTTPS URLs as client identifiers, where the URL points to a JSON document containing client metadata. This is the recommended registration approach per the MCP spec (ahead of DCR).
From the MCP Authorization spec:
Current State
Client-side (implemented in #1652)
is_valid_client_metadata_url()- validates HTTPS URLs with path componentshould_use_client_metadata_url()- checks if server advertises CIMD supportcreate_client_info_from_metadata_url()- uses URL as client_idServer-side (missing)
client_id_metadata_document_supported=truein OAuth metadataSpec Requirements for Authorization Servers
From the MCP spec and CIMD RFC:
client_idmatches the URL exactlyReferences
AI Disclaimer