Conversation
Added section on Bearer Scheme Downgrade Protection, specifying that DPoP-bound access tokens must not be used as bearer tokens and detailing the server's response requirements.
Author
|
@pcarleton — this adds the normative Bearer-downgrade sentence backing conformance in modelcontextprotocol/conformance#395 and modelcontextprotocol/conformance#527 Could you review/merge into the draft branch? |
Clarified error codes for DPoP proof validation failures and access token issues. See modelcontextprotocol/conformance#528
26 tasks
Added DPoP advertisement section for MCP servers, including requirements for `dpop_signing_alg_values_supported` and `dpop_bound_access_tokens_required` fields in Protected Resource Metadata.
Added details on MCP server DPoP advertisement and requirements for DPoP-bound access tokens.
Removed extra line break in the DPoP challenge section.
Clarify requirements for DPoP challenge in WWW-Authenticate header.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implementing the SEP-1932 conformance suite (modelcontextprotocol/conformance#395, plus community extensions modelcontextprotocol/conformance#527 / modelcontextprotocol/conformance#528 / modelcontextprotocol/conformance#529) surfaced three places where the profile relied on descriptive or absent text. This PR adds the normative sentences:
Bearerscheme; rejection is HTTP 401 with aBearerorDPoPchallenge. Backs the tightened probe in feat(sep-1932): tighten the Bearer-downgrade probe (stacked on #395) conformance#527.invalid_dpop_prooffor RFC 9449 §4.3 validation failures (including malformed or duplicatedDPoPheaders),invalid_tokenfor failures of the access token itself. Backs the §7.1 error-code check in feat(sep-1932): DPoP error codes (stacked on #527) conformance#528.dpop_signing_alg_values_supported(non-empty, asymmetric algorithms only); a server that requires DPoP-bound tokens MUST setdpop_bound_access_tokens_required: true, and a server that sets it MUST enforce it; advertising aDPoPchallenge withalgsis SHOULD per RFC 9449 §7.1; absent fields keep their RFC 9728 defaults. Grounds the discovery checks in feat(sep-1932): DPoP discovery signals (stacked on #528) conformance#529.Motivation and Context
How Has This Been Tested?
Breaking Changes
Types of changes
Checklist
Additional context