Skip to content

fix: include "none" in token_endpoint_auth_methods_supported metadata - #2261

Closed
namabile wants to merge 1 commit into
modelcontextprotocol:v1.xfrom
namabile:fix/token-endpoint-auth-methods-none
Closed

namabile wants to merge 1 commit into
modelcontextprotocol:v1.xfrom
namabile:fix/token-endpoint-auth-methods-none

Conversation

@namabile

@namabile namabile commented Mar 9, 2026 •

Copy link
Copy Markdown

Summary

build_metadata() in mcp/server/auth/routes.py hardcodes token_endpoint_auth_methods_supported to ["client_secret_post", "client_secret_basic"], omitting "none". This breaks public client OAuth flows used by MCP clients like Claude Code and Cursor.

Spec References

  • MCP Authorization Spec (2025-06-18): "Authorization servers MUST implement OAuth 2.1 with appropriate security measures for both confidential and public clients." Best practices: "We strongly recommend that local clients implement OAuth 2.1 as a public client."
  • RFC 7591 Section 2: token_endpoint_auth_method: "none" — "The client is a public client as defined in OAuth 2.0, Section 2.1, and does not have a client secret."
  • RFC 8414 Section 2: token_endpoint_auth_methods_supported uses values from RFC 7591, which includes "none".
  • Official MCP example server: Uses token_endpoint_auth_methods_supported: ['none'] — the Python SDK is the outlier.

The Problem

The registration handler (register.py:54-60) already supports public clients — it skips client_secret generation when token_endpoint_auth_method: "none". But the metadata doesn't advertise this capability, so clients assume a secret is always required and fail during token exchange.

Changes:

  • Add "none" to token_endpoint_auth_methods_supported in build_metadata()
  • Add "none" to revocation_endpoint_auth_methods_supported for consistency
  • Update test assertions

Fixes #2260

Test plan

  • uv run pytest tests/client/test_auth.py::test_build_metadata — 2 passed, 1 xfailed
  • uv run pytest tests/server/fastmcp/auth/test_auth_integration.py — 40 passed
  • uv run ruff check — all checks passed
  • uv run ruff format --check — already formatted
  • Manual verification: MCP server metadata now advertises "none", allowing Claude Code to complete public client OAuth flow

The `build_metadata()` function hardcoded `token_endpoint_auth_methods_supported`
to `["client_secret_post", "client_secret_basic"]`, but the registration handler
already supports `token_endpoint_auth_method: "none"` for public clients.

MCP clients like Claude Code follow the metadata to determine supported auth
methods. Without "none" advertised, public client flows break: the client
registers successfully (no client_secret), but then cannot complete the token
exchange because the metadata implies a secret is required.

Also includes "none" in `revocation_endpoint_auth_methods_supported` for
consistency.

Fixes modelcontextprotocol#2260
@maxisbey

maxisbey commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Thanks for the PR, and sorry it sat here without a proper review.

We're closing most of the open PR backlog. v2 is out and changed a lot of the SDK, so many older PRs no longer apply as written, and we're a small team that realistically doesn't have the capacity to work through the rest.

If this still matters to you on v2, the most useful thing you can do is open an issue (or comment on the existing one) with your use case and a repro. Hearing why it matters to you is what we use to decide what to prioritise.

AI Disclaimer

@maxisbey maxisbey closed this Oct 5, 2026
@maxisbey maxisbey added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants