FeatureFuel
12

OAuth 2.1 Server MCP Authentication: CIMD Support Soon?

Source: supabase/supabase#41695 · opened by @aslanyerdelen
Hello Supabase Team,

As you probably know, Dynamic Client Registration (DCR) has been painful in practice for MCP clients: it bloats the OAuth Apps list (lots of one-off client_ids) and creates security/operational concerns. Supabase’s current MCP auth guidance also highlights DCR as the default path today.

The Model Context Protocol authorization spec has now evolved to de-emphasize DCR and instead prioritize Client ID Metadata Documents (CIMD) (URL-based client identity / metadata).

OpenAI and Anthropic are also implementing the new CIMD approach for their MCP clients, instead of DCR enforcement.

Related:
• PR:
• Spec section:

Question: Are you planning to add support for Client ID Metadata Documents (CIMD) in the Supabase OAuth server, and if so, do you have an expected timeline?

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests