Repository navigation
fix: support chatgpt mcp connections with private_key_jwt client authentication - #926
Merged
Merged
Conversation
- Require each MCP client to use exactly one token method: none or private_key_jwt. - Verify private_key_jwt assertions against the client JWKS and reject replayed jti values. - Authenticate the client before an authorization code is consumed.
Contributor
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes
Reviewed the cloud OAuth token-endpoint client authentication change at ce7fd8e7, including assertion verification, JWKS fetching, grant ordering, migration 0023, and the ChatGPT Client ID Metadata Document path.
- Method binding: Each MCP client stores one token-endpoint method,
noneorprivate_key_jwt, and/oauth/tokenenforces that method instead of accepting either. - Assertion checks: A
private_key_jwtclient must present a single-use RFC 7523 JWT, verified against its HTTPS JWKS, before an authorization code is consumed or treated as a replay. - ChatGPT CIMD: A metadata document that declares
private_key_jwtwith an HTTPSjwks_uriis stored as confidential. An unsupported declared method falls back to public only whennoneis also listed. - Replay and fetch limits:
jtivalues are stored as hashes withON CONFLICT DO NOTHING. JWKS fetches reuse the metadata document fetcher's address and redirect guards, with a per-URI cache and rate limit. - Reference pins: This commit also moves the
reference_projects/code_forgeandreference_projects/jeansubmodule pointers. Those pins are not part of the cloud runtime.
grok-4.7 | 𝕏
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Each MCP client now has exactly one token-endpoint authentication method,
noneorprivate_key_jwt, and/oauth/tokenenforces that method.private_key_jwtclients must present a single-use JWT bearer assertion, verified against their HTTPS JWKS, before an authorization code is consumed. Public clients that send an assertion are rejected. ChatGPT Client ID Metadata Documents that declareprivate_key_jwtwith an HTTPSjwks_uriare stored as confidential clients.Screenshots
No visual change.
Testing
dart format --set-exit-if-changed lib test integration_test toolflutter analyzeflutter test --coverage --exclude-tags goldendart run tool/quality/coverage_report.dart --input coverage/lcov.info --min-lines 100 --worst 25flutter test --tags goldenflutter test integration_test -d macosflutter build macos,flutter build windows, orflutter build linuxcd landing && bun run checkFlutter, golden, desktop E2E, desktop build, and landing checks do not apply. This change is in the cloud authorization server.
Added unit coverage for assertion claim checks, algorithm and key rejection, public-client refusal, form credential parsing, method selection, and the ChatGPT metadata document. Added
cloud/tests/contracts/mcp_client_auth_contract.rsfor the token-endpoint contract. Schema migration0023is included in the required startup set.AI Review Report
No separate AI review run is recorded for this branch.
Cross-platform shortcut, label, path, shell, terminal, release, and updater behavior does not apply. The change is server-side OAuth client authentication.
Security Audit
Reviewed token-endpoint client authentication.
noneandprivate_key_jwt.alg=noneare rejected. A key that names an algorithm may verify only that algorithm.jtivalues are stored as hashes and inserted withON CONFLICT DO NOTHING. A replay returnsinvalid_client. Expired assertion rows are deleted by retention cleanup.kidvalues cannot force a fetch per request.Notes
Migration
0023_mcp_client_authentication.sqladdstoken_endpoint_auth_method,jwks_uri, andtoken_endpoint_auth_signing_algonmcp_clients, plusmcp_client_assertionsforjtireplay. Existing rows default tonone.Clients that declare an unsupported method fall back to
noneonly when they also listnone. Otherwise registration is refused.The branch also moves the
reference_projects/code_forgeandreference_projects/jeansubmodule pointers.