Repository navigation
Add CIMD support to MCP OAuth registration - #38089
Merged
copyberry[bot] merged 1 commit intoAug 12, 2026
Merged
copyberry[bot] merged 1 commit into
copyberry[bot] merged 1 commit into
Conversation
## What changed - Make automatic MCP OAuth registration prefer Client ID Metadata Documents (CIMD) when the authorization server advertises support for public clients and Codex is using its native loopback callback. Fall back to advertised Dynamic Client Registration (DCR) otherwise. - Add explicit `cimd` and `dcr` registration overrides to the CLI and app-server OAuth login API. Validate CIMD metadata and callback URLs before starting the authorization flow. - Use a callback-specific Codex client metadata URL for CIMD and retain the exact redirect URI through authorization and token exchange. ## Testing - Cover automatic and forced CIMD selection, DCR fallback, invalid metadata and redirects, token refresh, authenticated MCP requests, and conformance regression checks. GitOrigin-RevId: 4238372ca53b0f38e781e141ab5da97e0a6ddf45
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/4238372ca53b0f38e781e141ab5da97e0a6ddf45
branch
from
August 12, 2026 00:01
7a189c6 to
4c89139
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/4238372ca53b0f38e781e141ab5da97e0a6ddf45
branch
August 12, 2026 00:02
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add CIMD support to MCP OAuth registration
What changed
(CIMD) when the authorization server advertises support for public clients and
Codex is using its native loopback callback. Fall back to advertised Dynamic
Client Registration (DCR) otherwise.
cimdanddcrregistration overrides to the CLI and app-serverOAuth login API. Validate CIMD metadata and callback URLs before starting the
authorization flow.
exact redirect URI through authorization and token exchange.
Testing
redirects, token refresh, authenticated MCP requests, and conformance
regression checks.