0
Support OAuth Client ID Metadata Documents (CIMD) for MCP clients
Source: outline/outline#14010 · opened by @tommoor
Summary Add support for [OAuth Client ID Metadata Documents]( (CIMD) to the OAuth server, so that MCP clients can connect to the cloud root domain ( and not only to each workspace subdomain. With CIMD, the client does not register. It sends an HTTPS URL as its client_id, and the authorization server fetches a JSON document from that URL to get the client name and redirect URIs. The [MCP authorization spec (2025-11-25)]( says servers SHOULD support CIMD and MAY support Dynamic Client Registration (DCR). Why Today, MCP on the root domain fails at registration: POST /oauth/register returns 404 when there is no workspace on the request (server/routes/oauth/index.ts), because every OAuthClient must have a teamId. With CIMD there is no registration step: 1. POST /mcp returns 401 with WWW-Authenticate, and the metadata is served on the root domain. Works today. 2. Registration. Not needed with CIMD. 3. GET /oauth/authorize?client_id=<url> on the root domain shows the workspace cho…
No pledges yet. Be the first to back this.
Comments
Similar requests
ChatGPT plugin: one public MCP URL on the cloud root domain (workspace-independent OAuth clients + root-domain discovery)
0 votes · 0 comments
Add admin controls for MCP tools when using OAuth
3 votes · 0 comments
ChatGPT plugin, step 1: make the MCP server plugin-ready (securitySchemes, profile tool, structuredContent, manifest)
0 votes · 0 comments
ChatGPT plugin, step 2: inline UI cards via MCP Apps (document list and document preview)
0 votes · 0 comments
Add `get_attachment` MCP tool for downloading attachment content
2 votes · 0 comments
No comments yet.