Skip to content

fix(auth): oauth metadata discovery - #641

Merged
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery
Feb 4, 2026
Merged

fix(auth): oauth metadata discovery#641
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery

Conversation

@glicht

Copy link
Copy Markdown
Contributor

Auth metadata discovery stopped checking <base_domain>/.well-known/oauth-authorization-server with the 0.13 release. Adding a fix.

Motivation and Context

See #632

How Has This Been Tested?

Added unit test that failed before the fix and passes after the fix

Breaking Changes

No

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • [ x I have added or updated documentation as needed

Additional context

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@glicht

Copy link
Copy Markdown
ContributorAuthor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@glicht I think it's ok. Just wanted to point out why it was done. I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

@tanish111tanish111 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@glicht tested locally?

@tanish111

tanish111 commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@alexhancock can you also look into it issue and fix once?

@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht tested locally?

Yes. I've tested locally and the fix works as expected. Thanks

@alexhancock

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock

Copy link
Copy Markdown
Contributor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

@github-actionsgithub-actionsBot added T-core Core library changes T-transport Transport layer changes labels Feb 4, 2026
@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

Thanks. I've pushed a format fix.

@wdawson

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock I'm happy to take a pass. I know there are several issues and PRs in flight and I don't know the history. But I was a contributor to some of the authorization changes (hopefully the less confusing ones 😅) and should be able to get to a "correct" implementation if that would be a good starting point. Then would love help testing that against all the things people need/want to make sure there aren't regressions like @glicht mentioned. Let me know if that approach is useful. Alternatively I can review or advise another implementor. Happy to chat on discord or whatever.

@alexhancock
alexhancock self-requested a review February 4, 2026 16:57
@alexhancock
alexhancock merged commit f6ebc7a into modelcontextprotocol:mainFeb 4, 2026
11 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Feb 4, 2026
@alexhancock

Copy link
Copy Markdown
Contributor

Yes @wdawson let's do a comprehensive change that addresses all edge cases in this space and makes the implementation of metadata discovery & handling correct.

Then when we have a branch where we believe everything functions 100% to spec, I can make a test build of goose (the other project I work on) which uses the branch and we can test with various servers before a merge

Thanks for being willing to help!

@wdawsonwdawson mentioned this pull request Feb 10, 2026
9 tasks
@gpealgpeal mentioned this pull request Feb 12, 2026
bolinfest pushed a commit to openai/codex that referenced this pull request Feb 12, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
@glicht
glicht deleted the fix/auth-meta-discovery branch February 13, 2026 23:21
monkeycode-aiBot pushed a commit to agogo233/Ecode that referenced this pull request Jun 8, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
AIALRA-0 pushed a commit to AIALRA-0/codex-turn-engine that referenced this pull request Jun 10, 2026
wangjiecloud pushed a commit to wangjiecloud/codex that referenced this pull request Jun 27, 2026
shafqatevo pushed a commit to alo-labs/kay that referenced this pull request Aug 7, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@glicht@wdawson@tanish111@alexhancock
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(auth): oauth metadata discovery by glicht · Pull Request #641 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix(auth): oauth metadata discovery - #641

Merged
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery
Feb 4, 2026
Merged

fix(auth): oauth metadata discovery#641
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery

Conversation

@glicht

Copy link
Copy Markdown
Contributor

Auth metadata discovery stopped checking <base_domain>/.well-known/oauth-authorization-server with the 0.13 release. Adding a fix.

Motivation and Context

See #632

How Has This Been Tested?

Added unit test that failed before the fix and passes after the fix

Breaking Changes

No

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • [ x I have added or updated documentation as needed

Additional context

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@glicht

Copy link
Copy Markdown
ContributorAuthor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@glicht I think it's ok. Just wanted to point out why it was done. I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

@tanish111tanish111 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@glicht tested locally?

@tanish111

tanish111 commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@alexhancock can you also look into it issue and fix once?

@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht tested locally?

Yes. I've tested locally and the fix works as expected. Thanks

@alexhancock

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock

Copy link
Copy Markdown
Contributor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

@github-actionsgithub-actionsBot added T-core Core library changes T-transport Transport layer changes labels Feb 4, 2026
@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

Thanks. I've pushed a format fix.

@wdawson

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock I'm happy to take a pass. I know there are several issues and PRs in flight and I don't know the history. But I was a contributor to some of the authorization changes (hopefully the less confusing ones 😅) and should be able to get to a "correct" implementation if that would be a good starting point. Then would love help testing that against all the things people need/want to make sure there aren't regressions like @glicht mentioned. Let me know if that approach is useful. Alternatively I can review or advise another implementor. Happy to chat on discord or whatever.

@alexhancock
alexhancock self-requested a review February 4, 2026 16:57
@alexhancock
alexhancock merged commit f6ebc7a into modelcontextprotocol:mainFeb 4, 2026
11 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Feb 4, 2026
@alexhancock

Copy link
Copy Markdown
Contributor

Yes @wdawson let's do a comprehensive change that addresses all edge cases in this space and makes the implementation of metadata discovery & handling correct.

Then when we have a branch where we believe everything functions 100% to spec, I can make a test build of goose (the other project I work on) which uses the branch and we can test with various servers before a merge

Thanks for being willing to help!

@wdawsonwdawson mentioned this pull request Feb 10, 2026
9 tasks
@gpealgpeal mentioned this pull request Feb 12, 2026
bolinfest pushed a commit to openai/codex that referenced this pull request Feb 12, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
@glicht
glicht deleted the fix/auth-meta-discovery branch February 13, 2026 23:21
monkeycode-aiBot pushed a commit to agogo233/Ecode that referenced this pull request Jun 8, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
AIALRA-0 pushed a commit to AIALRA-0/codex-turn-engine that referenced this pull request Jun 10, 2026
wangjiecloud pushed a commit to wangjiecloud/codex that referenced this pull request Jun 27, 2026
shafqatevo pushed a commit to alo-labs/kay that referenced this pull request Aug 7, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@glicht@wdawson@tanish111@alexhancock
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(auth): oauth metadata discovery by glicht · Pull Request #641 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix(auth): oauth metadata discovery - #641

Merged
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery
Feb 4, 2026
Merged

fix(auth): oauth metadata discovery#641
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery

Conversation

@glicht

Copy link
Copy Markdown
Contributor

Auth metadata discovery stopped checking <base_domain>/.well-known/oauth-authorization-server with the 0.13 release. Adding a fix.

Motivation and Context

See #632

How Has This Been Tested?

Added unit test that failed before the fix and passes after the fix

Breaking Changes

No

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • [ x I have added or updated documentation as needed

Additional context

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@glicht

Copy link
Copy Markdown
ContributorAuthor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@glicht I think it's ok. Just wanted to point out why it was done. I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

@tanish111tanish111 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@glicht tested locally?

@tanish111

tanish111 commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@alexhancock can you also look into it issue and fix once?

@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht tested locally?

Yes. I've tested locally and the fix works as expected. Thanks

@alexhancock

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock

Copy link
Copy Markdown
Contributor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

@github-actionsgithub-actionsBot added T-core Core library changes T-transport Transport layer changes labels Feb 4, 2026
@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

Thanks. I've pushed a format fix.

@wdawson

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock I'm happy to take a pass. I know there are several issues and PRs in flight and I don't know the history. But I was a contributor to some of the authorization changes (hopefully the less confusing ones 😅) and should be able to get to a "correct" implementation if that would be a good starting point. Then would love help testing that against all the things people need/want to make sure there aren't regressions like @glicht mentioned. Let me know if that approach is useful. Alternatively I can review or advise another implementor. Happy to chat on discord or whatever.

@alexhancock
alexhancock self-requested a review February 4, 2026 16:57
@alexhancock
alexhancock merged commit f6ebc7a into modelcontextprotocol:mainFeb 4, 2026
11 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Feb 4, 2026
@alexhancock

Copy link
Copy Markdown
Contributor

Yes @wdawson let's do a comprehensive change that addresses all edge cases in this space and makes the implementation of metadata discovery & handling correct.

Then when we have a branch where we believe everything functions 100% to spec, I can make a test build of goose (the other project I work on) which uses the branch and we can test with various servers before a merge

Thanks for being willing to help!

@wdawsonwdawson mentioned this pull request Feb 10, 2026
9 tasks
@gpealgpeal mentioned this pull request Feb 12, 2026
bolinfest pushed a commit to openai/codex that referenced this pull request Feb 12, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
@glicht
glicht deleted the fix/auth-meta-discovery branch February 13, 2026 23:21
monkeycode-aiBot pushed a commit to agogo233/Ecode that referenced this pull request Jun 8, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
AIALRA-0 pushed a commit to AIALRA-0/codex-turn-engine that referenced this pull request Jun 10, 2026
wangjiecloud pushed a commit to wangjiecloud/codex that referenced this pull request Jun 27, 2026
shafqatevo pushed a commit to alo-labs/kay that referenced this pull request Aug 7, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@glicht@wdawson@tanish111@alexhancock
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(auth): oauth metadata discovery by glicht · Pull Request #641 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix(auth): oauth metadata discovery - #641

Merged
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery
Feb 4, 2026
Merged

fix(auth): oauth metadata discovery#641
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery

Conversation

@glicht

Copy link
Copy Markdown
Contributor

Auth metadata discovery stopped checking <base_domain>/.well-known/oauth-authorization-server with the 0.13 release. Adding a fix.

Motivation and Context

See #632

How Has This Been Tested?

Added unit test that failed before the fix and passes after the fix

Breaking Changes

No

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • [ x I have added or updated documentation as needed

Additional context

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@glicht

Copy link
Copy Markdown
ContributorAuthor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@glicht I think it's ok. Just wanted to point out why it was done. I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

@tanish111tanish111 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@glicht tested locally?

@tanish111

tanish111 commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@alexhancock can you also look into it issue and fix once?

@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht tested locally?

Yes. I've tested locally and the fix works as expected. Thanks

@alexhancock

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock

Copy link
Copy Markdown
Contributor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

@github-actionsgithub-actionsBot added T-core Core library changes T-transport Transport layer changes labels Feb 4, 2026
@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

Thanks. I've pushed a format fix.

@wdawson

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock I'm happy to take a pass. I know there are several issues and PRs in flight and I don't know the history. But I was a contributor to some of the authorization changes (hopefully the less confusing ones 😅) and should be able to get to a "correct" implementation if that would be a good starting point. Then would love help testing that against all the things people need/want to make sure there aren't regressions like @glicht mentioned. Let me know if that approach is useful. Alternatively I can review or advise another implementor. Happy to chat on discord or whatever.

@alexhancock
alexhancock self-requested a review February 4, 2026 16:57
@alexhancock
alexhancock merged commit f6ebc7a into modelcontextprotocol:mainFeb 4, 2026
11 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Feb 4, 2026
@alexhancock

Copy link
Copy Markdown
Contributor

Yes @wdawson let's do a comprehensive change that addresses all edge cases in this space and makes the implementation of metadata discovery & handling correct.

Then when we have a branch where we believe everything functions 100% to spec, I can make a test build of goose (the other project I work on) which uses the branch and we can test with various servers before a merge

Thanks for being willing to help!

@wdawsonwdawson mentioned this pull request Feb 10, 2026
9 tasks
@gpealgpeal mentioned this pull request Feb 12, 2026
bolinfest pushed a commit to openai/codex that referenced this pull request Feb 12, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
@glicht
glicht deleted the fix/auth-meta-discovery branch February 13, 2026 23:21
monkeycode-aiBot pushed a commit to agogo233/Ecode that referenced this pull request Jun 8, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
AIALRA-0 pushed a commit to AIALRA-0/codex-turn-engine that referenced this pull request Jun 10, 2026
wangjiecloud pushed a commit to wangjiecloud/codex that referenced this pull request Jun 27, 2026
shafqatevo pushed a commit to alo-labs/kay that referenced this pull request Aug 7, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@glicht@wdawson@tanish111@alexhancock
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(auth): oauth metadata discovery by glicht · Pull Request #641 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix(auth): oauth metadata discovery - #641

Merged
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery
Feb 4, 2026
Merged

fix(auth): oauth metadata discovery#641
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery

Conversation

@glicht

Copy link
Copy Markdown
Contributor

Auth metadata discovery stopped checking <base_domain>/.well-known/oauth-authorization-server with the 0.13 release. Adding a fix.

Motivation and Context

See #632

How Has This Been Tested?

Added unit test that failed before the fix and passes after the fix

Breaking Changes

No

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • [ x I have added or updated documentation as needed

Additional context

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@glicht

Copy link
Copy Markdown
ContributorAuthor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@glicht I think it's ok. Just wanted to point out why it was done. I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

@tanish111tanish111 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@glicht tested locally?

@tanish111

tanish111 commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@alexhancock can you also look into it issue and fix once?

@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht tested locally?

Yes. I've tested locally and the fix works as expected. Thanks

@alexhancock

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock

Copy link
Copy Markdown
Contributor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

@github-actionsgithub-actionsBot added T-core Core library changes T-transport Transport layer changes labels Feb 4, 2026
@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

Thanks. I've pushed a format fix.

@wdawson

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock I'm happy to take a pass. I know there are several issues and PRs in flight and I don't know the history. But I was a contributor to some of the authorization changes (hopefully the less confusing ones 😅) and should be able to get to a "correct" implementation if that would be a good starting point. Then would love help testing that against all the things people need/want to make sure there aren't regressions like @glicht mentioned. Let me know if that approach is useful. Alternatively I can review or advise another implementor. Happy to chat on discord or whatever.

@alexhancock
alexhancock self-requested a review February 4, 2026 16:57
@alexhancock
alexhancock merged commit f6ebc7a into modelcontextprotocol:mainFeb 4, 2026
11 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Feb 4, 2026
@alexhancock

Copy link
Copy Markdown
Contributor

Yes @wdawson let's do a comprehensive change that addresses all edge cases in this space and makes the implementation of metadata discovery & handling correct.

Then when we have a branch where we believe everything functions 100% to spec, I can make a test build of goose (the other project I work on) which uses the branch and we can test with various servers before a merge

Thanks for being willing to help!

@wdawsonwdawson mentioned this pull request Feb 10, 2026
9 tasks
@gpealgpeal mentioned this pull request Feb 12, 2026
bolinfest pushed a commit to openai/codex that referenced this pull request Feb 12, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
@glicht
glicht deleted the fix/auth-meta-discovery branch February 13, 2026 23:21
monkeycode-aiBot pushed a commit to agogo233/Ecode that referenced this pull request Jun 8, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
AIALRA-0 pushed a commit to AIALRA-0/codex-turn-engine that referenced this pull request Jun 10, 2026
wangjiecloud pushed a commit to wangjiecloud/codex that referenced this pull request Jun 27, 2026
shafqatevo pushed a commit to alo-labs/kay that referenced this pull request Aug 7, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@glicht@wdawson@tanish111@alexhancock
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(auth): oauth metadata discovery by glicht · Pull Request #641 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix(auth): oauth metadata discovery - #641

Merged
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery
Feb 4, 2026
Merged

fix(auth): oauth metadata discovery#641
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery

Conversation

@glicht

Copy link
Copy Markdown
Contributor

Auth metadata discovery stopped checking <base_domain>/.well-known/oauth-authorization-server with the 0.13 release. Adding a fix.

Motivation and Context

See #632

How Has This Been Tested?

Added unit test that failed before the fix and passes after the fix

Breaking Changes

No

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • [ x I have added or updated documentation as needed

Additional context

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@glicht

Copy link
Copy Markdown
ContributorAuthor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@glicht I think it's ok. Just wanted to point out why it was done. I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

@tanish111tanish111 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@glicht tested locally?

@tanish111

tanish111 commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@alexhancock can you also look into it issue and fix once?

@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht tested locally?

Yes. I've tested locally and the fix works as expected. Thanks

@alexhancock

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock

Copy link
Copy Markdown
Contributor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

@github-actionsgithub-actionsBot added T-core Core library changes T-transport Transport layer changes labels Feb 4, 2026
@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

Thanks. I've pushed a format fix.

@wdawson

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock I'm happy to take a pass. I know there are several issues and PRs in flight and I don't know the history. But I was a contributor to some of the authorization changes (hopefully the less confusing ones 😅) and should be able to get to a "correct" implementation if that would be a good starting point. Then would love help testing that against all the things people need/want to make sure there aren't regressions like @glicht mentioned. Let me know if that approach is useful. Alternatively I can review or advise another implementor. Happy to chat on discord or whatever.

@alexhancock
alexhancock self-requested a review February 4, 2026 16:57
@alexhancock
alexhancock merged commit f6ebc7a into modelcontextprotocol:mainFeb 4, 2026
11 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Feb 4, 2026
@alexhancock

Copy link
Copy Markdown
Contributor

Yes @wdawson let's do a comprehensive change that addresses all edge cases in this space and makes the implementation of metadata discovery & handling correct.

Then when we have a branch where we believe everything functions 100% to spec, I can make a test build of goose (the other project I work on) which uses the branch and we can test with various servers before a merge

Thanks for being willing to help!

@wdawsonwdawson mentioned this pull request Feb 10, 2026
9 tasks
@gpealgpeal mentioned this pull request Feb 12, 2026
bolinfest pushed a commit to openai/codex that referenced this pull request Feb 12, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
@glicht
glicht deleted the fix/auth-meta-discovery branch February 13, 2026 23:21
monkeycode-aiBot pushed a commit to agogo233/Ecode that referenced this pull request Jun 8, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
AIALRA-0 pushed a commit to AIALRA-0/codex-turn-engine that referenced this pull request Jun 10, 2026
wangjiecloud pushed a commit to wangjiecloud/codex that referenced this pull request Jun 27, 2026
shafqatevo pushed a commit to alo-labs/kay that referenced this pull request Aug 7, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@glicht@wdawson@tanish111@alexhancock
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(auth): oauth metadata discovery by glicht · Pull Request #641 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix(auth): oauth metadata discovery - #641

Merged
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery
Feb 4, 2026
Merged

fix(auth): oauth metadata discovery#641
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery

Conversation

@glicht

Copy link
Copy Markdown
Contributor

Auth metadata discovery stopped checking <base_domain>/.well-known/oauth-authorization-server with the 0.13 release. Adding a fix.

Motivation and Context

See #632

How Has This Been Tested?

Added unit test that failed before the fix and passes after the fix

Breaking Changes

No

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • [ x I have added or updated documentation as needed

Additional context

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@glicht

Copy link
Copy Markdown
ContributorAuthor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@glicht I think it's ok. Just wanted to point out why it was done. I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

@tanish111tanish111 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@glicht tested locally?

@tanish111

tanish111 commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@alexhancock can you also look into it issue and fix once?

@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht tested locally?

Yes. I've tested locally and the fix works as expected. Thanks

@alexhancock

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock

Copy link
Copy Markdown
Contributor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

@github-actionsgithub-actionsBot added T-core Core library changes T-transport Transport layer changes labels Feb 4, 2026
@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

Thanks. I've pushed a format fix.

@wdawson

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock I'm happy to take a pass. I know there are several issues and PRs in flight and I don't know the history. But I was a contributor to some of the authorization changes (hopefully the less confusing ones 😅) and should be able to get to a "correct" implementation if that would be a good starting point. Then would love help testing that against all the things people need/want to make sure there aren't regressions like @glicht mentioned. Let me know if that approach is useful. Alternatively I can review or advise another implementor. Happy to chat on discord or whatever.

@alexhancock
alexhancock self-requested a review February 4, 2026 16:57
@alexhancock
alexhancock merged commit f6ebc7a into modelcontextprotocol:mainFeb 4, 2026
11 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Feb 4, 2026
@alexhancock

Copy link
Copy Markdown
Contributor

Yes @wdawson let's do a comprehensive change that addresses all edge cases in this space and makes the implementation of metadata discovery & handling correct.

Then when we have a branch where we believe everything functions 100% to spec, I can make a test build of goose (the other project I work on) which uses the branch and we can test with various servers before a merge

Thanks for being willing to help!

@wdawsonwdawson mentioned this pull request Feb 10, 2026
9 tasks
@gpealgpeal mentioned this pull request Feb 12, 2026
bolinfest pushed a commit to openai/codex that referenced this pull request Feb 12, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
@glicht
glicht deleted the fix/auth-meta-discovery branch February 13, 2026 23:21
monkeycode-aiBot pushed a commit to agogo233/Ecode that referenced this pull request Jun 8, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
AIALRA-0 pushed a commit to AIALRA-0/codex-turn-engine that referenced this pull request Jun 10, 2026
wangjiecloud pushed a commit to wangjiecloud/codex that referenced this pull request Jun 27, 2026
shafqatevo pushed a commit to alo-labs/kay that referenced this pull request Aug 7, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@glicht@wdawson@tanish111@alexhancock
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(auth): oauth metadata discovery by glicht · Pull Request #641 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix(auth): oauth metadata discovery - #641

Merged
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery
Feb 4, 2026
Merged

fix(auth): oauth metadata discovery#641
alexhancock merged 2 commits into
modelcontextprotocol:mainfrom
glicht:fix/auth-meta-discovery

Conversation

@glicht

Copy link
Copy Markdown
Contributor

Auth metadata discovery stopped checking <base_domain>/.well-known/oauth-authorization-server with the 0.13 release. Adding a fix.

Motivation and Context

See #632

How Has This Been Tested?

Added unit test that failed before the fix and passes after the fix

Breaking Changes

No

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • [ x I have added or updated documentation as needed

Additional context

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@glicht

Copy link
Copy Markdown
ContributorAuthor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@wdawson

Copy link
Copy Markdown
Contributor

This was due to an intentional correction in the MCP spec version 2025-11-25

@wdawson see #632

The change that was implemented was a breaking change. I don't think that was the purpose. The sdk stopped working with common mcp servers (such as cloudflare).

Also from what I checked in the typescript-sdk it supports fetching from: <base_domain>/.well-known/oauth-authorization-server as a fallback. So, I think we should maintain this support for backwards compatibility.

@glicht I think it's ok. Just wanted to point out why it was done. I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

@tanish111tanish111 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@glicht tested locally?

@tanish111

tanish111 commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

@alexhancock can you also look into it issue and fix once?

@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht tested locally?

Yes. I've tested locally and the fix works as expected. Thanks

@alexhancock

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock

Copy link
Copy Markdown
Contributor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

@github-actionsgithub-actionsBot added T-core Core library changes T-transport Transport layer changes labels Feb 4, 2026
@glicht

Copy link
Copy Markdown
ContributorAuthor

@glicht for this one specifically, looks like it needs the code formatter run. cargo fmt should do it

Thanks. I've pushed a format fix.

@wdawson

Copy link
Copy Markdown
Contributor

@wdawson@tanish111@glicht re:

I think the bigger problem is that this SDK seems to not use the protected resource metadata location and tries to discover something first. Fixing that bug might fix this issue with Cloudflare

I feel like we've made a patchwork set of fixes/adjustments/tweaks over time. I get so confused by the ordering needed!

Is anyone well positioned to take a holistic look at how the Rust SDK gets/uses resource metadata?

@alexhancock I'm happy to take a pass. I know there are several issues and PRs in flight and I don't know the history. But I was a contributor to some of the authorization changes (hopefully the less confusing ones 😅) and should be able to get to a "correct" implementation if that would be a good starting point. Then would love help testing that against all the things people need/want to make sure there aren't regressions like @glicht mentioned. Let me know if that approach is useful. Alternatively I can review or advise another implementor. Happy to chat on discord or whatever.

@alexhancock
alexhancock self-requested a review February 4, 2026 16:57
@alexhancock
alexhancock merged commit f6ebc7a into modelcontextprotocol:mainFeb 4, 2026
11 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Feb 4, 2026
@alexhancock

Copy link
Copy Markdown
Contributor

Yes @wdawson let's do a comprehensive change that addresses all edge cases in this space and makes the implementation of metadata discovery & handling correct.

Then when we have a branch where we believe everything functions 100% to spec, I can make a test build of goose (the other project I work on) which uses the branch and we can test with various servers before a merge

Thanks for being willing to help!

@wdawsonwdawson mentioned this pull request Feb 10, 2026
9 tasks
@gpealgpeal mentioned this pull request Feb 12, 2026
bolinfest pushed a commit to openai/codex that referenced this pull request Feb 12, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
@glicht
glicht deleted the fix/auth-meta-discovery branch February 13, 2026 23:21
monkeycode-aiBot pushed a commit to agogo233/Ecode that referenced this pull request Jun 8, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
AIALRA-0 pushed a commit to AIALRA-0/codex-turn-engine that referenced this pull request Jun 10, 2026
wangjiecloud pushed a commit to wangjiecloud/codex that referenced this pull request Jun 27, 2026
shafqatevo pushed a commit to alo-labs/kay that referenced this pull request Aug 7, 2026
modelcontextprotocol/rust-sdk#598 in 0.14 broke
some MCP oauth (like Linear) and
modelcontextprotocol/rust-sdk#641 fixed it in
0.15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@glicht@wdawson@tanish111@alexhancock