Skip to content

Implement SEP-990: Enterprise Managed Authorization (Extension) #949

Description

@felixweinberger

This is a tracking issue for implementation of SEP-990.

Summary

This extension enables secure authorization of MCP clients within enterprise environments by leveraging existing enterprise Identity Provider (IdP) infrastructure. The C# SDK needs to implement client-side OAuth flows including OpenID Connect/SAML integration, RFC8693 Token Exchange to obtain Identity Assertion JWT Authorization Grants (ID-JAG), and RFC7523 JWT Bearer Grant flows. Server-side implementations need JWT validation including signature verification, claims validation, and replay prevention. This extension provides seamless single sign-on for users while enabling enterprise administrators to control which MCP servers can be accessed and enforce policies through existing IdP infrastructure.

Related Issues & PRs

  • Implementation PRs: n/a
  • Related PRs: n/a
  • Related Issues: n/a

Activity

  1. mikekistler commented on Nov 21, 2025

    @mikekistler
    Contributor

    @felixweinberger Since this SEP is for an extension, is this required to be implemented for an SDK to claim compliance with the 2025-11-25 spec?

  2. felixweinberger commented on Nov 21, 2025

    @felixweinberger
    Author

    @felixweinberger Since this SEP is for an extension, is this required to be implemented for an SDK to claim compliance with the 2025-11-25 spec?

    I'm actually not 100% sure of the requirements here as the Extensions SEP wasn't finalized modelcontextprotocol/modelcontextprotocol#1724 - @pja-ant working on the extensions SEP probably has the best PoV here.

    The language of the SEP (though not merged) suggests SDKs DO NOT have to implement extensions to claim 100% compliance. I.e. implementing extensions is optional and up to SDK maintainers.

  3. pja-ant commented on Nov 21, 2025

    @pja-ant

    Since this SEP is for an extension, is this required to be implemented for an SDK to claim compliance with the 2025-11-25 spec?

    Strictly speaking, no (i.e. as far as tiering goes). However, I do expect this to be highly desirable from users!

  4. self-assigned this
    on Nov 25, 2025
  5. mikekistler commented on Nov 25, 2025

    @mikekistler
    Contributor

    I wanted to assign this to @aniket-okta but GitHub wouldn't let me. Maybe Aniket needs to be added to the ModelContextProtocol org for this to work?

    In the interim, I've assigned this to myself so we don't wind up with multiple people working on this.

  6. aniket-okta commented on Nov 27, 2025

    @aniket-okta
    Contributor

    @mikekistler Thanks for the mention! It can be assigned to me as I’ve already started the implementation.

  7. mikekistler commented on Dec 29, 2025

    @mikekistler
    Contributor

    @aniket-okta Any update on this work item?

  8. aniket-okta commented on Feb 18, 2026

    @aniket-okta
    Contributor

    I've opened a PR implementing this: #1305

  9. added
    enhancementNew feature or request
    ready for workHas enough information to start
    P2Moderate issues, valuable feature requests
    on Mar 5, 2026
  10. mikekistler commented on Apr 13, 2026

    @mikekistler
    Contributor

    Reassigning to @halter73 to drive the implementation to closure.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

P2Moderate issues, valuable feature requestsarea-authenhancementNew feature or requestready for workHas enough information to start

Type

No type

Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions