Skip to content

Add CIMD support to MCP OAuth registration - #38089

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/4238372ca53b0f38e781e141ab5da97e0a6ddf45
Aug 12, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/4238372ca53b0f38e781e141ab5da97e0a6ddf45

Conversation

@copyberry

@copyberry copyberry Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Add CIMD support to MCP OAuth registration

What changed

  • Make automatic MCP OAuth registration prefer Client ID Metadata Documents
    (CIMD) when the authorization server advertises support for public clients and
    Codex is using its native loopback callback. Fall back to advertised Dynamic
    Client Registration (DCR) otherwise.
  • Add explicit cimd and dcr registration overrides to the CLI and app-server
    OAuth login API. Validate CIMD metadata and callback URLs before starting the
    authorization flow.
  • Use a callback-specific Codex client metadata URL for CIMD and retain the
    exact redirect URI through authorization and token exchange.

Testing

  • Cover automatic and forced CIMD selection, DCR fallback, invalid metadata and
    redirects, token refresh, authenticated MCP requests, and conformance
    regression checks.

## What changed

- Make automatic MCP OAuth registration prefer Client ID Metadata Documents
  (CIMD) when the authorization server advertises support for public clients and
  Codex is using its native loopback callback. Fall back to advertised Dynamic
  Client Registration (DCR) otherwise.
- Add explicit `cimd` and `dcr` registration overrides to the CLI and app-server
  OAuth login API. Validate CIMD metadata and callback URLs before starting the
  authorization flow.
- Use a callback-specific Codex client metadata URL for CIMD and retain the
  exact redirect URI through authorization and token exchange.

## Testing

- Cover automatic and forced CIMD selection, DCR fallback, invalid metadata and
  redirects, token refresh, authenticated MCP requests, and conformance
  regression checks.

GitOrigin-RevId: 4238372ca53b0f38e781e141ab5da97e0a6ddf45
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/4238372ca53b0f38e781e141ab5da97e0a6ddf45 branch from 7a189c6 to 4c89139 Compare August 12, 2026 00:01
@copyberry
copyberry Bot merged commit 4c89139 into main Aug 12, 2026
29 of 32 checks passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/4238372ca53b0f38e781e141ab5da97e0a6ddf45 branch August 12, 2026 00:02
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 12, 2026

This branch was previously deployed

1 inactive deployment
issue-triage — 4c89139d Deployed Aug 12, 2026 by ai-jz via Identify potential duplicates (open issues fallback) #37308
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants