Repository navigation
feat: support secure OAuth MCP credential lifecycle - #25
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and behavior
Vault credentials supported static bearer tokens only. Add the pinned
mcp_oauthresource variant and generic dispatch-time refresh so application-authorized grants can reach the existing MCP Runtime path securely. Application consent and provider revocation remain application-owned; no additional public authentication routes or harness-specific OAuth implementation are introduced.Access/refresh/client secrets are encrypted with their tenant, Vault and exact destination binding. Refresh, replacement and deletion serialize on the existing Credential row; failed exchanges or commits never return an uncommitted token or fall back to anonymous access. The client and Core Web can safely read mixed credential lists.
Validation
Limits
Refresh checks move the declared expiry into the past; they do not claim waiting for real JWT expiry. No running-turn token withdrawal/hot replacement, automatic 401 retry, arbitrary provider qualification or complete protocol compatibility. Keycloak exists only in private acceptance infrastructure. See
services/agents-api/oauth-credentials.mdfor exact null, network and revocation boundaries.Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.