Module: MCPClient::Auth::OAuthProvider::TokenStore
- Included in:
- MCPClient::Auth::OAuthProvider
- Defined in:
- lib/mcp_client/auth/oauth_provider/token_store.rb
Overview
Where the OAuth tokens of one MCP server live, and which token answers for the authorization server in use.
MCP 2026-07-28 makes registration state per authorization server, and names what that state is: "client credentials, tokens". A token is issued by one authorization server, for one resource, and means nothing at another server — so it is stored twice, exactly as a client registration is: under the resource URL, which is the token currently in use and where every backend (and every record written by an earlier version) already keeps it, and under a key of its own authorization server (RegistrationStore#client_registration_key).
One MCP server can be served by more than one authorization server over its lifetime. With the token kept only under the resource URL, a switch away from a server threw its token away, and coming back meant sending the user through consent again for a grant that was never revoked. The per-authorization-server copy keeps it instead — while a token this client RETIRED stays retired wherever it is kept, and a token is still never presented to an authorization server other than the one that issued it.
Mixed into OAuthProvider; every method relies on its state.