Module: MCPClient::Auth::OAuthProvider::ClientAuthentication

Included in:
MCPClient::Auth::OAuthProvider
Defined in:
lib/mcp_client/auth/oauth_provider/client_authentication.rb

Overview

How this client authenticates at the token endpoint.

A confidential client — one the authorization server issued a client_secret to — must present that secret with every token request, and RFC 7591 Section 2 says how: "if unspecified or omitted, the default is client_secret_basic". This client used to send the secret only for client_secret_post and to record an omitted method as none, which is the one combination that never authenticates: a registration that issued a secret and named no method produced a record whose secret was never sent, and every token request went out as an unauthenticated client for an authorization server that expects HTTP Basic.

So the method the authorization server registered decides, defaulting as the RFC does:

  • client_secret_basic — the credentials go in an Authorization: Basic header, form-urlencoded before they are base64'd (RFC 6749 Section 2.3.1), never in the body;
  • client_secret_post — in the request body, as before;
  • none (a public client, or no secret at all) — nothing is sent;
  • anything else (private_key_jwt, client_secret_jwt, a method a future RFC adds) — this client cannot produce that assertion, so it sends no credentials and says so, rather than guessing with the secret in a header the server did not ask for.

Mixed into OAuthProvider.

Constant Summary collapse

DEFAULT_TOKEN_ENDPOINT_AUTH_METHOD =

RFC 7591 Section 2: the token_endpoint_auth_method a registration response that names none is read as.

'client_secret_basic'
NO_CLIENT_AUTHENTICATION =

The method a public client declares: no credentials are sent.

'none'