FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

PHP SDK — Tier 3 Assessment · Issue #3274 · modelcontextprotocol/modelcontextprotocol · GitHub

Repository navigation

PHP SDK — Tier 3 Assessment #3274

Description

MCP SDK Tier Audit: modelcontextprotocol/php-sdk

SDK: modelcontextprotocol/php-sdk
Version: v0.7.1 (published 2026-08-14, pre-1.0) · assessed on main @ 8c06dce
Date: 2026-08-19
Requirements revisions scored: 2025-11-25 and 2026-07-28 (frozen per-revision requirement sets, each run at that revision's own wire version, per @modelcontextprotocol/conformance 0.2.0-alpha.11)
Auditor: mcp-sdk-tier-audit skill (tier-check CLI + subagent evaluation)
Previous assessment: Tier 3 (#2305, 2026-02-23, v0.4.0)

Result

Tier 3. Server-side conformance is excellent (100%, 67/67) and every process signal (triage, labels, P0 handling, spec tracking, dependency policy, roadmap) passes. Two hard requirements block Tier 2: client conformance is only 20% (10/50), almost entirely because OAuth/authorization client scenarios are unimplemented or failing (38 of 39 scored auth scenarios), and no stable 1.0.0+ release has ever shipped (current: v0.7.1). Documentation gaps (38/48 features) and a missing versioning policy further block Tier 1.

All 40 client failures are pre-declared as expected in the SDK's own baseline files (conformance-baseline-2025-11-25.yml, conformance-baseline-2026-07-28.yml) — this is a tracked, deliberate OAuth gap (matching the in-progress auth work called out in ROADMAP.md), not silent breakage. Per SEP-1730 the score is still the raw pass rate regardless of baseline, so this doesn't change the tier — but it's worth knowing the gap is fully tracked, not accidental.

# Requirement Tier 1 Standard Tier 2 Standard Value T1 T2
1a Server Conformance 100% pass rate ≥ 80% pass rate 100% (67/67 across both revisions) ✅ ✅
1b Client Conformance 100% pass rate ≥ 80% pass rate 20% (10/50 across both revisions) ❌ ❌
2 Issue Triage ≥ 90% within 2 biz days ≥ 80% within 1 month 100% (69/69) ✅ ✅
2b Labels 12 required labels 12 required labels 12/12 ✅ ✅
3 Critical Bug Resolution All P0s within 7 days All P0s within 2 weeks 0 open ✅ ✅
4 Stable Release Required + clear versioning At least one stable release v0.7.1 (pre-1.0) ❌ ❌
4b Spec Tracking Timeline agreed per release Within 6 months 17d gap ✅ ✅
5 Documentation Comprehensive w/ examples Basic docs for core features 38/48 features (core 31/36, 86%) ❌ ✅
6 Dependency Policy Published update policy Published update policy dependabot.yml configured ✅ ✅
7 Roadmap Published roadmap Plan toward Tier 1 ROADMAP.md, substantive ✅ ✅
8 Versioning Policy Documented breaking change policy N/A Not found ❌ N/A

Tier 1: 6/8 met (failing: Client Conformance, Stable Release, Documentation, Versioning Policy)
Tier 2: 5/7 met (failing: Client Conformance, Stable Release)


1–2. Conformance — ✅ server 67/67, ❌ client 10/50

Scored against the frozen 2025-11-25 and 2026-07-28 requirement sets, each run at its own wire, against the SDK's own everything-server/client conformance fixtures. The repo carries baseline files at tests/Conformance/conformance-baseline-{2025-11-25,2026-07-28}.yml — every client failure below matches an entry in one of them.

Server — 67/67 (100%)

30/30 scored at 2025-11-25, 37/37 scored at 2026-07-28. Not scored (informational): server-sse-polling/server-session-lifecycle/json-schema-2020-12 (pending/added-after-release, all passing anyway), 10 tasks-* scenarios at 2026-07-28 (extension, SEP-2663 not yet implemented, all failing) plus http-header-validation/http-custom-header-server-validation (pending).

All 67 scored server scenarios (100% pass)
Scenario Scored at Status
tools-list 2025-11-25, 2026-07-28 PASS
tools-call-with-progress 2025-11-25, 2026-07-28 PASS
tools-call-with-logging 2025-11-25 PASS
tools-call-simple-text 2025-11-25, 2026-07-28 PASS
tools-call-sampling 2025-11-25 PASS
tools-call-mixed-content 2025-11-25, 2026-07-28 PASS
tools-call-image 2025-11-25, 2026-07-28 PASS
tools-call-error 2025-11-25, 2026-07-28 PASS
tools-call-embedded-resource 2025-11-25, 2026-07-28 PASS
tools-call-elicitation 2025-11-25 PASS
tools-call-audio 2025-11-25, 2026-07-28 PASS
server-sse-multiple-streams 2025-11-25, 2026-07-28 PASS
server-initialize 2025-11-25 PASS
server-stateless 2026-07-28 PASS
resources-unsubscribe 2025-11-25 PASS
resources-templates-read 2025-11-25, 2026-07-28 PASS
resources-subscribe 2025-11-25 PASS
resources-read-text 2025-11-25, 2026-07-28 PASS
resources-read-binary 2025-11-25, 2026-07-28 PASS
resources-list 2025-11-25, 2026-07-28 PASS
prompts-list 2025-11-25, 2026-07-28 PASS
prompts-get-with-image 2025-11-25, 2026-07-28 PASS
prompts-get-with-args 2025-11-25, 2026-07-28 PASS
prompts-get-simple 2025-11-25, 2026-07-28 PASS
prompts-get-embedded-resource 2025-11-25, 2026-07-28 PASS
ping 2025-11-25 PASS
logging-set-level 2025-11-25 PASS
elicitation-sep1330-enums 2025-11-25 PASS
elicitation-sep1034-defaults 2025-11-25 PASS
dns-rebinding-protection 2025-11-25, 2026-07-28 PASS
completion-complete 2025-11-25, 2026-07-28 PASS
sep-2164-resource-not-found 2026-07-28 PASS
input-required-result-validate-input 2026-07-28 PASS
input-required-result-unsupported-methods 2026-07-28 PASS
input-required-result-tampered-state 2026-07-28 PASS
input-required-result-result-type 2026-07-28 PASS
input-required-result-request-state 2026-07-28 PASS
input-required-result-non-tool-request 2026-07-28 PASS
input-required-result-multiple-input-requests 2026-07-28 PASS
input-required-result-multi-round 2026-07-28 PASS
input-required-result-missing-input-response 2026-07-28 PASS
input-required-result-ignore-extra-params 2026-07-28 PASS
input-required-result-capability-check 2026-07-28 PASS
input-required-result-basic-sampling 2026-07-28 PASS
input-required-result-basic-list-roots 2026-07-28 PASS
input-required-result-basic-elicitation 2026-07-28 PASS
caching 2026-07-28 PASS

Not scored (extension, all failing — SEP-2663 Tasks not yet implemented): tasks-wire-fields, tasks-status-notifications, tasks-required-task-error, tasks-request-state-removal, tasks-request-headers, tasks-mrtr-input, tasks-mrtr-composition, tasks-lifecycle, tasks-dispatch-and-envelope, tasks-capability-negotiation (all @ 2026-07-28).

Client — 10/50 (20%)

Suite breakdown: Core 9/11 (82%), Auth 1/39 (2.6%). Failures split as 2 core failures (sse-retry, elicitation-sep1034-client-defaults, both @ 2025-11-25) + 38 auth failures (14/14 of 2025-11-25's scored auth scenarios; 24/25 of 2026-07-28's, everything except auth/resource-mismatch). All 40 failures — every one, both revisions — match an entry in the SDK's own baseline files. This is a known, tracked OAuth gap, not silent breakage or drift; SEP-1730 still scores the raw pass rate regardless, so it remains a hard blocker for both Tier 1 and Tier 2 since auth scenarios are 39 of the 50 scored (78%) and virtually all fail.

Core scenarios — 9/11 (82%)
Scenario Scored at Status Baselined?
tools_call 2025-11-25, 2026-07-28 PASS —
initialize 2025-11-25 PASS —
sse-retry 2025-11-25 FAIL Yes
elicitation-sep1034-client-defaults 2025-11-25 FAIL Yes
sep-2322-client-request-state 2026-07-28 PASS —
request-metadata 2026-07-28 PASS —
json-schema-ref-no-deref 2026-07-28 PASS —
http-standard-headers 2026-07-28 PASS —
http-invalid-tool-headers 2026-07-28 PASS —
http-custom-headers 2026-07-28 PASS —
Auth scenarios — 1/39 (2.6%) — the primary Tier 2/1 blocker (all failures baselined)
Scenario Scored at Status Baselined?
auth/resource-mismatch 2026-07-28 PASS —
auth/token-endpoint-auth-post 2025-11-25, 2026-07-28 FAIL Yes
auth/token-endpoint-auth-none 2025-11-25, 2026-07-28 FAIL Yes
auth/token-endpoint-auth-basic 2025-11-25, 2026-07-28 FAIL Yes
auth/scope-step-up 2025-11-25, 2026-07-28 FAIL Yes
auth/scope-retry-limit 2025-11-25, 2026-07-28 FAIL Yes
auth/scope-omitted-when-undefined 2025-11-25, 2026-07-28 FAIL Yes
auth/scope-from-www-authenticate 2025-11-25, 2026-07-28 FAIL Yes
auth/scope-from-scopes-supported 2025-11-25, 2026-07-28 FAIL Yes
auth/pre-registration 2025-11-25, 2026-07-28 FAIL Yes
auth/metadata-var3 2025-11-25, 2026-07-28 FAIL Yes
auth/metadata-var2 2025-11-25, 2026-07-28 FAIL Yes
auth/metadata-var1 2025-11-25, 2026-07-28 FAIL Yes
auth/metadata-default 2025-11-25, 2026-07-28 FAIL Yes
auth/basic-cimd 2025-11-25, 2026-07-28 FAIL Yes
auth/offline-access-scope 2026-07-28 FAIL Yes
auth/offline-access-not-supported 2026-07-28 FAIL Yes
auth/metadata-issuer-mismatch 2026-07-28 FAIL Yes
auth/iss-wrong-issuer 2026-07-28 FAIL Yes
auth/iss-unexpected 2026-07-28 FAIL Yes
auth/iss-supported-missing 2026-07-28 FAIL Yes
auth/iss-supported 2026-07-28 FAIL Yes
auth/iss-not-advertised 2026-07-28 FAIL Yes
auth/iss-normalized 2026-07-28 FAIL Yes
auth/authorization-server-migration 2026-07-28 FAIL Yes (partial-check entry)

Not scored (extension, both revisions): auth/wif-jwt-bearer (FAIL), auth/enterprise-managed-authorization (FAIL), auth/dpop-nonce (FAIL), auth/dpop (FAIL), auth/client-credentials-jwt (PASS), auth/client-credentials-basic (PASS).

3–4. Issue Triage and P0 Resolution — ✅

100% compliance (69/69 issues triaged within SLA), all 12 required labels present, 0 open P0s and no P0 history to audit for mislabeling or slow resolution.

5–6. Stable Release and Spec Tracking

Stable Release — ❌. Latest release is v0.7.1 (published 2026-08-14), pre-1.0. No release ≥ 1.0.0 has ever shipped. This alone blocks both Tier 1 and Tier 2 ("at least one stable release ≥ 1.0.0").

Spec Tracking — ✅. v0.7.1 shipped 17 days after the 2026-07-28 spec revision, well within the 6-month Tier 2 window and the Tier 1 timeline-agreed standard.

7. Documentation — ❌ 38/48 (79%), core 31/36 (86%)

Documentation lives in docs/ (mcp-elements.md, client.md, server-builder.md, transports.md, server-client-communication.md, events.md, extensions.md, examples.md), each generally paired with runnable examples in examples/. 10 of 48 canonical features are undocumented or under-documented — 8 outright FAIL, 2 PARTIAL:

# Feature Status Note
14 Resources - subscribing FAIL Implemented (ResourceSubscribeHandler.php), zero prose docs
15 Resources - unsubscribing FAIL Implemented (ResourceUnsubscribeRequest.php), zero prose docs
20 Prompts - embedded resources PARTIAL Generic prose exists, no dedicated example
25 Elicitation - URL mode FAIL Implemented (ElicitRequest.php, ElicitationMode::Url), zero prose docs
27 Elicitation - default values PARTIAL Example exists (ElicitationHandlers.php), no prose explanation
29 Elicitation - complete notification FAIL Not implemented — no notifications/elicitation/complete handling
36 Ping FAIL Implemented (PingHandler.php), zero prose docs
39 SSE transport - legacy (client) FAIL Not implemented
40 SSE transport - legacy (server) FAIL Not implemented
44 Cancellation FAIL Implemented (CancelledNotification.php), zero prose docs

The remaining 38/48 features (79%) are documented with prose + at least one example. Core-feature coverage (86%, 31/36) already satisfies the Tier 2 basic-docs bar.

8. Versioning Policy — ❌

No VERSIONING.md, docs/versioning.md, BREAKING_CHANGES.md, or CONTRIBUTING.md versioning section exists. CHANGELOG.md does tag individual entries with [BC Break] markers, which shows breaking changes are tracked in practice, but there is no standalone policy document describing what constitutes a breaking change, how it's communicated ahead of a release, or the SemVer commitment.

Dependency Policy and Roadmap — ✅

  • Dependency policy: .github/dependabot.yml — real weekly update schedules for composer and github-actions, not a stub.
  • Roadmap: ROADMAP.md — concrete, checkbox-tracked items tied to spec components (OAuth2 auth for server/client, schema generation, "achieve full spec conformance," Tasks extension), some already checked off. Functions as both a Tier 1 roadmap and a Tier 2 plan-toward-Tier-1.

Path to Tier 2

  1. Raise client conformance from 20% to ≥ 80% (Large) — almost entirely OAuth client work: metadata discovery variants, token endpoint auth methods (post/none/basic), scope handling (step-up, retry-limit, omitted, from-www-authenticate, from-scopes-supported), dynamic client registration, issuer validation, offline-access scopes, authorization-server-migration. All of this is already tracked in the repo's own baseline files and ROADMAP.md — the work is scoped, it just isn't done yet.
  2. Fix sse-retry and elicitation-sep1034-client-defaults (Medium) — the two non-auth client failures, both @ 2025-11-25.
  3. Ship a stable 1.0.0+ release (Medium).

Path to Tier 1

Everything above, plus:

  1. Raise client conformance to 100% (full OAuth coverage, not just the 80% bar).
  2. Document the 10 gaps listed above (mostly small per-feature doc additions; legacy SSE transport and elicitation-complete-notification need either an implementation or an explicit "intentionally not implemented" note, since undocumented-because-unimplemented reads the same as a real gap).
  3. Publish a versioning/breaking-change policy (new VERSIONING.md, or a "Versioning" section in a new CONTRIBUTING.md — the existing CHANGELOG.md [BC Break] convention could be formalized into it).

Recommendation: OAuth client conformance is the single highest-leverage fix — it alone blocks both tiers and accounts for 38 of 40 client failures. It's already declared as a known gap (baseline files + ROADMAP.md OAuth2 line items) and matches the in-progress auth PRs mentioned in the prior Tier 3 assessment (#2305); closing it is what actually moves the tier, since SEP-1730 doesn't credit baselined failures toward the score. Everything else needed for Tier 2 (server conformance, triage, labels, P0 handling, spec tracking, dependency policy, roadmap) already passes.

Reproduce This Assessment

git clone https://github.com/modelcontextprotocol/conformance.git && cd conformance
git checkout 74edef3 && npm install && npm run build   # 0.2.0-alpha.11 + #458

git clone https://github.com/modelcontextprotocol/php-sdk.git ../mcp-sdk
cd ../mcp-sdk && composer install && cd -
php -S 127.0.0.1:8000 ../mcp-sdk/tests/Conformance/server.php &   # one endpoint serves both eras

node dist/index.js tier-check \
  --repo modelcontextprotocol/php-sdk --branch main \
  --conformance-server-url http://localhost:8000/ \
  --client-cmd 'php ../mcp-sdk/tests/Conformance/client.php' \
  --requirements 2025-11-25,2026-07-28 --output markdown

Note: the SDK's own CI instead drives this via Docker Compose (tests/Conformance/Fixtures/docker-compose.yml) and applies tests/Conformance/conformance-baseline-*.yml as --expected-failures to the upstream @modelcontextprotocol/conformance CLI directly — this audit didn't have the SDK wired into known-sdks.ts, so it ran unadjusted via the URL fallback above and cross-referenced the baseline files manually afterward.

Or via the /mcp-sdk-tier-audit skill in Claude Code:

/mcp-sdk-tier-audit ../mcp-sdk http://localhost:8000/ "php ../mcp-sdk/tests/Conformance/client.php" --requirements 2025-11-25,2026-07-28

Automated assessment (tier-check CLI + AI subagent evaluation for documentation/policy content) — flag anything that looks wrong.

@pcarleton @felixweinberger

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL