What's broken?
The spec is ambiguous or self-contradictory
Where in the spec or docs?
https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2352/changes
What should happen?
I am implementing this SEP in the Go SDK and would like to clarify a couple of cases regarding client credential management:
- The SEP states that clients that persist client credentials obtained via DCR must associate them with the specific AS keyed by the issuer identifier. Go SDK does not persist credentials but performs DCR dynamically on-demand (e.g., every time authorization is needed or after a token expires). Is persistence of DCR credentials considered a MUST or a SHOULD for compliance with this SEP?
- The SEP states clients MUST maintain separate registration state per authorization server. RFC 9728 Section 7.6 defers server selection to the client. Is a client that always selects only the first AS from authorization_servers (and never attempts others) considered compliant? Or is there an expectation that clients should attempt alternative servers on authorization failure?
What actually happens?
n/a
Anything else?
No response
What's broken?
The spec is ambiguous or self-contradictory
Where in the spec or docs?
https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2352/changes
What should happen?
I am implementing this SEP in the Go SDK and would like to clarify a couple of cases regarding client credential management:
What actually happens?
n/a
Anything else?
No response