Module: MCPClient::Auth::OAuthProvider::RegistrationStore

Included in:
MCPClient::Auth::OAuthProvider
Defined in:
lib/mcp_client/auth/oauth_provider/registration_store.rb

Overview

Where OAuth client registration state lives, and which record answers for the authorization server in use.

MCP 2026-07-28 (SEP-2352) makes registration state per authorization server: a client_id (and the secret that may come with it) is issued by one authorization server and means nothing at another. One MCP server can be served by more than one authorization server over its lifetime — a migration, a challenge that names another one, a host that configures a second — so credentials keyed by the resource URL alone cannot hold both: configuring the second replaces the first, and coming back to the first reports "these credentials belong to another authorization server" instead of finding its registration.

So every record is additionally kept under a key of its own authorization server (#client_registration_key), while the resource URL stays the key of the registration currently in use. That keeps the documented storage interface intact — a backend still sees opaque string keys, and records written by earlier versions are found where they were left — while giving each authorization server registration state of its own.

Mixed into OAuthProvider; every method relies on its state.

Instance Method Summary collapse

Instance Method Details

#client_registration_key(issuer) ⇒ String

The storage key the registration state of one authorization server is kept under. The resource URL itself is the key of the record in use (and of records persisted before this layout existed); each authorization server additionally has a key derived from the resource URL and its issuer identifier, so a host can configure credentials for several authorization servers behind one MCP server:

storage.set_client_info(provider.client_registration_key(issuer), credentials)

A normalized server URL never carries a fragment, so the separator cannot collide with a resource URL.

Parameters:

  • issuer (String, nil) —

    the issuer identifier of the authorization server

Returns:

  • (String) —

    the storage key for that server's registration state



42
43
44
45
46
# File 'lib/mcp_client/auth/oauth_provider/registration_store.rb', line 42

def client_registration_key(issuer)
  return server_url unless issuer.is_a?(String) && !issuer.empty? && issuer != Token::RETIRED_ISSUER

  "#{server_url}#authorization_server=#{issuer}"
end