
The MCP client discovers, registers and authorizes with PKCE S256, then the MCP server validates the token.
What the MCP spec requires
- An OAuth 2.1 AS that mints RFC 9068 JWT access tokens bound to a specific resource via RFC 8707.
- Agent identities: Long-lived client credentials for the agents a user trusts (
client_credentialsgrant). - Delegation grants: A user-approved record that lets a specific agent act on a specific resource. Revoking the grant invalidates every derived token at the next introspection refresh.
- Token exchange (RFC 8693): When an agent acts on behalf of a user, the access token carries an
actclaim chain so the resource server can see the full delegation path and reject the request if any link is revoked. - Resource server validation: The MCP tool server validates tokens, enforces audience binding, walks the actor chain, and emits the correct
WWW-Authenticateheader on failure (RFC 6750 + RFC 9728). - Discovery documents:
/.well-known/oauth-authorization-server(RFC 8414) and/.well-known/oauth-protected-resource(RFC 9728) so MCP clients can auto-configure.
How theauth-go covers the spec
The one-import claim
Themcpresource module is a separately versioned, zero-dependency Go module. A consumer importing it does not transitively pull theauth core or any storage adapter. This matters for MCP tool servers that are operated independently of the AS.
Actor chain depth
The RFC 8693act chain is capped at 3 links (configurable via AgentConfig.MaxChainDepth, hard ceiling 3). Deeper chains are rejected with invalid_request: actor chain depth exceeded. This prevents runaway delegation trees and limits blast radius if any agent is compromised.
Revocation propagation
When a user revokes a delegation grant:- The
delegation_grants.revoked_atfield is set immediately. - New introspection calls return
active: false. - The
mcpresourcevalidator refreshes its introspection cache withinCacheTTL(default 60 seconds). - After the TTL, every request using a derived token returns 401.
WithCacheTTL(0) on the mcpresource.Validator and accept the per-request introspection cost.
Next steps
- Authorization Server - Wire the AS in your application.
- Resource Server (mcpresource) - Wire the RS middleware.
- Guides: Add an OAuth Provider - Add social login on top of the AS.