Skip to content

Implement SEP-990: Enterprise Managed Authorization (Extension) #1593

Description

@felixweinberger

This is a tracking issue for implementation of SEP-990.

Summary

This extension enables secure authorization of MCP clients within enterprise environments by leveraging existing enterprise Identity Provider (IdP) infrastructure. The Python SDK needs to implement client-side OAuth flows including OpenID Connect/SAML integration, RFC8693 Token Exchange to obtain Identity Assertion JWT Authorization Grants (ID-JAG), and RFC7523 JWT Bearer Grant flows. Server-side implementations need JWT validation including signature verification, claims validation, and replay prevention. This extension provides seamless single sign-on for users while enabling enterprise administrators to control which MCP servers can be accessed and enforce policies through existing IdP infrastructure.

Related Issues & PRs

  • Implementation PRs: n/a
  • Related PRs: n/a
  • Related Issues: n/a

Activity

  1. felixweinberger commented on Nov 18, 2025

    @felixweinberger
    ContributorAuthor

    Hi @BinoyOza-okta, @aaronpk mentioned you're planning to work on this one? Based on GH rules I think you need to comment before I can assign it to you.

  2. added
    enhancementRequest for a new feature that's not currently supported
    authIssues and PRs related to Authentication / OAuth
    on Nov 19, 2025
  3. BinoyOza-okta commented on Nov 19, 2025

    @BinoyOza-okta

    Hi @felixweinberger, yes, I'll be working on this one. You can assign it to me.

  4. moved this from Ready to In progress in 2025-11-25 Implementationon Nov 20, 2025
  5. felixweinberger commented on Nov 20, 2025

    @felixweinberger
    ContributorAuthor

    Hi @felixweinberger, yes, I'll be working on this one. You can assign it to me.

    Awesome thanks! Done.

  6. maxisbey commented on Jun 29, 2026

    @maxisbey
    Contributor

    SEP-990 implementation landed via #2988 (RFC 8693 token exchange / ID-JAG client flows + server-side JWT validation) and #3004 (docs + examples); #3007 wired the conformance fixture and the SEP-990 scenarios run green with no expected-failure entries. Closing.

    AI Disclaimer

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

authIssues and PRs related to Authentication / OAuthenhancementRequest for a new feature that's not currently supported

Type

No type

Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions