(docs): Update authorization guide by localden · Pull Request #2155 · modelcontextprotocol/modelcontextprotocol · GitHub
Skip to content

(docs): Update authorization guide - #2155

Closed
localden wants to merge 29 commits into
mainfrom
localden/authguide
Closed

(docs): Update authorization guide#2155
localden wants to merge 29 commits into
mainfrom
localden/authguide

Conversation

@localden

Copy link
Copy Markdown
Contributor

Updating authorization guide with instructions for CIMD, given that we're now using that as the de-facto standard instead of DCR.

@localden
localden requested a review from a team as a code owner January 27, 2026 04:47
@localden localden added the documentation Improvements or additions to documentation label Jan 27, 2026
🏠 Remote-Dev: homespace
dend and others added 2 commits March 4, 2026 19:16
Move MCP Server Setup code examples (TS/Python/C#) to a standalone
top-level section before both testing sections, since the server code
is registration-agnostic. Add CIMD discovery field to AS metadata
example, expand CIMD testing section with reachability requirements
and common issues, and clarify public accessibility constraints.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Include the scope parameter in the WWW-Authenticate header example
and explain the scope selection strategy fallback behavior.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
dend and others added 2 commits March 4, 2026 19:49
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Reorganize the CIMD and DCR testing sections under a new umbrella
section. Replace the generic CIMD instructions with a detailed
end-to-end walkthrough using Stytch as the identity provider,
covering AS metadata, proxy setup, and common pitfalls.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
dend and others added 2 commits March 4, 2026 20:03
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add BankTools class definition to C# CIMD sample so it's
  self-contained
- Add Write the MCP Server subsection to DCR with full TypeScript
  and C# examples using Keycloak
- CIMD uses read:account scope, DCR uses mcp:tools scope, both
  internally consistent

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…ples

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace Mintlify Steps with proper guide sections (Stytch Setup,
Write the MCP Server, Testing with CIMD) and add placeholder image
frames for dashboard screenshots.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Stytch scopes are built on the RBAC system (Resources → Actions →
Permissions → Scopes), not a simple "Connected Apps → Scopes" menu.
Updated instructions to walk through creating a Resource and Scope in
the RBAC dashboard, fixed broken docs link, and removed reference to
nonexistent screenshot.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
dend and others added 2 commits March 4, 2026 21:41
The stytch-authorized-apps.png and stytch-login.png screenshots don't
exist yet, causing broken link lint errors.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auth documentation Improvements or additions to documentation security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants