Skip to content

oauthex: require S256 PKCE support in GetAuthServerMeta - #1327

Merged
guglielmo-san merged 2 commits into
modelcontextprotocol:mainfrom
akshita317:oauthex/require-s256-pkce
Oct 2, 2026
Merged

guglielmo-san merged 2 commits into
modelcontextprotocol:mainfrom
akshita317:oauthex/require-s256-pkce

Conversation

@akshita317

Copy link
Copy Markdown
Contributor

GetAuthServerMeta rejected an authorization server that advertises no
PKCE method, but accepted one whose code_challenge_methods_supported
lists only "plain". The SDK's clients always send an S256 challenge
(oauth2.S256ChallengeOption in auth and auth/extauth), so with such a
server the flow failed late, when the authorization endpoint rejected
the request in the user's browser, rather than during discovery with a
clear error.

Require "S256" in the advertised methods. The MCP authorization spec
requires clients to use S256 (OAuth 2.1 section 7.5.2), and the
TypeScript SDK refuses such a server during discovery in the same way.
Servers that offer both methods, such as Google's (see
testdata/google-auth-meta.json), are unaffected.

The new server_with_only_plain_pkce case of
TestGetAuthServerMetaPKCESupport fails without the change;
server_with_plain_and_s256_pkce checks that a mixed list is accepted.

Fixes #1326

GetAuthServerMeta rejected an authorization server that advertises no
PKCE method, but accepted one whose code_challenge_methods_supported
lists only "plain". The SDK's clients always send an S256 challenge
(oauth2.S256ChallengeOption in auth and auth/extauth), so with such a
server the flow failed late, when the authorization endpoint rejected
the request in the user's browser, rather than during discovery with a
clear error.

Require "S256" in the advertised methods. The MCP authorization spec
requires clients to use S256 (OAuth 2.1 section 7.5.2), and the
TypeScript SDK refuses such a server during discovery in the same way.
Servers that offer both methods, such as Google's (see
testdata/google-auth-meta.json), are unaffected.

The new server_with_only_plain_pkce case of
TestGetAuthServerMetaPKCESupport fails without the change;
server_with_plain_and_s256_pkce checks that a mixed list is accepted.

Fixes modelcontextprotocol#1326

Signed-off-by: Akshita kumari <110122283+akshita317@users.noreply.github.com>
@guglielmo-san
guglielmo-san merged commit 25a53e3 into modelcontextprotocol:main Oct 2, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauthex: GetAuthServerMeta accepts a server whose only PKCE method is plain, but clients always use S256

2 participants