Skip to content

Support URL-based downstream OAuth clients - #621

Merged
zackbart merged 1 commit into
mainfrom
feat/oauth-client-metadata-url
Sep 29, 2026
Merged

zackbart merged 1 commit into
mainfrom
feat/oauth-client-metadata-url

Conversation

@zackbart

@zackbart zackbart commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Basecamp advertises URL-based OAuth client IDs but rejects Connecta's HTTPS callback during dynamic client registration. Expose the SDK's clientMetadataUrl and default scope settings so deployments can authorize through a public client metadata document and retain the existing PKCE, issuer binding, encrypted token storage, refresh, and disconnect behavior.

Invalid metadata URLs and scope strings fail at construction. The settings participate in the retained-client configuration binding. Bumps the package and Node template to 0.26.3.

Validation: npm run release:check passed: 4,811 tests, 50 browser tests, package and Docker smoke checks, and zero production dependency vulnerabilities. OAuth tests cover URL-client code exchange, scopes, and the existing registration path. Basecamp's live pushed-authorization endpoint accepted One&Many's hosted metadata, exact callback, and full mcp offline_access scopes.

@zackbart
zackbart merged commit 6f6ddba into main Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant