Repository navigation
Document user-scoped MCP client credentials (proposed) - #7731
Draft
yangleyland wants to merge 1 commit into
Draft
yangleyland wants to merge 1 commit into
yangleyland wants to merge 1 commit into
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Co-Authored-By: replicas-connector[bot] <replicas-connector[bot]@users.noreply.github.com>
Contributor
|
Preview deployment for your docs. Learn more about Mintlify Previews.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Draft docs for a proposed feature: pass a user's OAuth access token (
subject_token) with the MCPclient_credentialsgrant, and Mintlify mints an/authed/mcptoken scoped to that user's groups by calling the site's Info API URL. This covers the TRM Labs relay case and the Elise AI "no IdP redirect" case.The feature is not built yet. Don't merge until it ships.
Adds a "Request access on behalf of a user" subsection under Client credentials in
ai/model-context-protocol.mdx.Research: what it would take
The current flow is the client route at
mint/apps/client/src/app/_mintlify/mcp/[subdomain]/oauth/token/route.ts(handleClientCredentials) calling serverPOST /api/mcp/oauth/token/client-credentialsand thenMcpOAuthService.clientCredentialsGrant. Today that path signsuserInfo: { groups: credential.groups }. The/authed/mcphandler already filters byuserInfo.groupson the JWT, so the MCP side needs no changes.mint (client)
handleClientCredentials: read the optionalsubject_tokenform field and forward it assubjectToken. Map upstreaminvalid_granterrors through.server
mcpClientCredentialsGrantBodySchema: add an optionalsubjectTokenwith a max length.ClientCredentialmodel and create schema: addallowUserTokens: boolean(default false).clientCredentialsGrant: whensubjectTokenis present:credential.allowUserTokensis set and the deployment's auth is OAuth with anapiUrl.fetch(auth.apiUrl, { headers: { Authorization: Bearer <subjectToken> }, redirect: 'error' })with a timeout, thenuserInfoSchema.safeParse. This is the same logic asClientAuthService.oauthHandshake, so pull it into a shared helper.userInfoinstead of the credential's groups.issueAccessTokenalready caps the TTL withuserInfo.expiresAt.refreshToken()would replay the storeduserInfo, so groups would stay stale after an IdP change or revocation. The caller re-sends the user token when the access token expires (10 min TTL).dashboard
create-credential-drawer.tsx/create-mcp-client-credential-dialog.tsx, and show it incredentials-section.tsx.Out of scope for v1
auth.tokenClaims). Today wedecodeJwtwithout verifying, which is fine after our own code exchange but unsafe for a token a third party hands us. Supporting it needs JWKS verification.leyland/mcp-token-exchange-poc) also accepted a JWT signed with the site's key. We can add that later.grant_type=urn:ietf:params:oauth:grant-type:token-exchange). This extendsclient_credentialsas requested, but uses the RFC'ssubject_tokenname so we can move to real token exchange later without renaming.Open questions for TRM and Elise
Checks
mint broken-linkspasses.valeisn't installed in this workspace, so I didn't run it.🤖 Generated with Claude Code
Co-Authored-By: replicas-connector[bot] <replicas-connector[bot]@users.noreply.github.com>