Implements SEP-2468 for the MCP Spec 2026-07-28 release.
Tracked by umbrella #338.
Spec summary
Requires MCP authorization responses to include an explicit iss (issuer) parameter per RFC 9207. Clients MUST validate iss against the AS that initiated the flow to mitigate authorization mix-up attacks in multi-IdP environments.
PHP SDK changes
- When handling the authorization-code redirect, the client must validate the returned iss matches the AS that produced the authorization_endpoint URL.
- Required for any multi-AS scenario; cross-cuts with [Client] Implement OAuth 2.0 Authorization Code flow with PKCE (RFC 6749 + RFC 7636) #319 (Auth Code + PKCE) but filed separately because the validation logic crosses callback + AS-metadata state.
- Server-side: N/A — MCP servers are resource servers, not authorization servers; iss is emitted by the AS.
Related
Reactions are currently unavailable
Implements SEP-2468 for the MCP Spec 2026-07-28 release.
Tracked by umbrella #338.
Spec summary
PHP SDK changes
Related