Skip to content

feat: support secure OAuth MCP credential lifecycle - #25

Merged
SaladDay merged 14 commits into
mainfrom
codex/credential-lifecycle
Sep 22, 2026
Merged

SaladDay merged 14 commits into
mainfrom
codex/credential-lifecycle

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Problem and behavior

Vault credentials supported static bearer tokens only. Add the pinned mcp_oauth resource variant and generic dispatch-time refresh so application-authorized grants can reach the existing MCP Runtime path securely. Application consent and provider revocation remain application-owned; no additional public authentication routes or harness-specific OAuth implementation are introduced.

Access/refresh/client secrets are encrypted with their tenant, Vault and exact destination binding. Refresh, replacement and deletion serialize on the existing Credential row; failed exchanges or commits never return an uncommitted token or fall back to anonymous access. The client and Core Web can safely read mixed credential lists.

Validation

  • Fixed OpenAI SDK 3.13.0 and raw HTTP resource, tenant-isolation, replacement/deletion and restart checks against standalone Core.
  • Genuine Keycloak 26.7.4 authorization/consent/PKCE, refresh rotation and revocation with none/basic/post authentication; actual MCP introspection and real Kimi calls through Codex and Claude.
  • Codex lifecycle: five successful Turns, two revoked/deleted-grant failures before native/MCP work. Claude: initial and refreshed access. Latest-main Core/daemon integration also receives fresh-database resource checks and one real refreshed Turn per harness.
  • Required server gate, separately executed Web/client checks, sqlc/OpenAPI generation, race/concurrency/commit-failure tests and fresh GPT-6 Astra high whole-diff review.

Limits

Refresh checks move the declared expiry into the past; they do not claim waiting for real JWT expiry. No running-turn token withdrawal/hot replacement, automatic 401 retry, arbitrary provider qualification or complete protocol compatibility. Keycloak exists only in private acceptance infrastructure. See services/agents-api/oauth-credentials.md for exact null, network and revocation boundaries.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit 4eecc41 into main Sep 22, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant