feat: make OAUTH_RESOURCE the /mcp endpoint, and warn when audience is off - #63
Merged
Merged
Conversation
…s off Claude sends the URL users enter (path included) as the RFC 8707 resource and requires the protected-resource metadata to name it exactly, so OAUTH_RESOURCE should be https://host/mcp. Upload links are now built from that URL minus a trailing /mcp instead of pointing at a route under /mcp that does not exist. The 401 challenge's metadata URL moves into a tested helper. Startup warns when OAUTH_VERIFY_AUDIENCE=false. The README and Cloud Run guide now walk through registering the resource indicator (WorkOS supports RFC 8707 since May 2026) and prefer CIMD over DCR, which the 2026-07-28 spec deprecates.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 5 of 8 in the MCP best-practices stack. Stacked on #62, so merge in order.
Why
OAUTH_VERIFY_AUDIENCE=false.resourceand uses the environment's client ID asaud.resource"must match your MCP server URL exactly as the user enters it in Claude, including any path component". Claude sends that URL, path included, as the RFC 8707resource. SoOAUTH_RESOURCEshould behttps://host/mcp.OAUTH_RESOURCEand would have pointed athttps://host/mcp/upload/…, which doesn't exist.Changes
OAUTH_RESOURCE/SERVER_URLminus a trailing/mcpsegment. A deployment under a path prefix keeps its prefix, and only a whole/mcpsegment is dropped.OAUTH_VERIFY_AUDIENCE=false.protectedResourceMetadataUrl. A test checks it against the pathmcpAuthMetadataRouteractually serves for a/mcpresource.docs/cloud-run.md,.env.example):https://…/mcpin all three places: the provider's resource indicator,OAUTH_RESOURCE, and what users enter in ClaudeSteps for the live deployment (not done by this PR)
Do these in order. Flipping the flag first rejects every token.
https://<host>/mcpas a resource indicator.OAUTH_RESOURCE=https://<host>/mcp, then reconnect the connector once, so new tokens carryaud=https://<host>/mcp.OAUTH_VERIFY_AUDIENCE=false.registration_endpoint, so new users can't register a client. Existing connectors keep working.Verification
/mcpstripping (resource,SERVER_URL, path prefix, and alexware-mcppath that must not be stripped) and the warning.OAUTH_RESOURCE=…/mcp:/.well-known/oauth-protected-resource/mcpreturnsresource: …/mcpnpm testpasses all 479 tests.