Summary
The server-side ClientAuthenticator reads client_id only from the token request form body and raises invalid_client: "Missing client_id" when it is absent — even when the client authenticated correctly via HTTP Basic (Authorization: Basic base64(client_id:client_secret)). Per RFC 6749 §2.3.1, a client using client_secret_basic sends its client_id and client_secret in the Authorization header and MAY omit them from the body. Servers advertising client_secret_basic in token_endpoint_auth_methods_supported therefore reject spec-compliant clients (e.g. clients that use Basic and do not duplicate client_id into the body).
Location
src/mcp/server/auth/middleware/client_auth.py, authenticate_request:
form_data = await request.form()
client_id = form_data.get("client_id")
if not client_id:
raise AuthenticationError("Missing client_id")
...
if client.token_endpoint_auth_method == "client_secret_basic":
...
basic_client_id, request_client_secret = decoded.split(":", 1)
basic_client_id = unquote(basic_client_id)
if basic_client_id != client_id: # only cross-checks; never used as fallback
raise AuthenticationError("Client ID mismatch in Basic auth")
client_id from the Basic header is only used to cross-check a body-supplied value; it is never used as a fallback source. So a request with credentials solely in the Basic header fails before the client is even looked up.
Steps to reproduce
- Register a client with
token_endpoint_auth_method=client_secret_basic.
POST /token with grant_type=authorization_code, Authorization: Basic base64(client_id:client_secret), and no client_id/client_secret in the form body.
- Response:
401 {"error":"invalid_client","error_description":"Missing client_id"}.
Sending the same credentials via client_secret_post (in the body) works.
Expected
When Authorization: Basic is present, the authenticator should derive client_id from the header if it is absent from the body (RFC 6749 §2.3.1), then verify the secret as it does today.
Notes
This is the mirror image of client-side PR #3536 (which stops MCP clients from putting client_id in the body under client_secret_basic). With that client-side change, compliant clients will send client_id only in the Basic header — which this server-side code rejects. The two need to agree.
Observed on mcp 1.27.0.
Summary
The server-side
ClientAuthenticatorreadsclient_idonly from the token request form body and raisesinvalid_client: "Missing client_id"when it is absent — even when the client authenticated correctly via HTTP Basic (Authorization: Basic base64(client_id:client_secret)). Per RFC 6749 §2.3.1, a client usingclient_secret_basicsends itsclient_idandclient_secretin theAuthorizationheader and MAY omit them from the body. Servers advertisingclient_secret_basicintoken_endpoint_auth_methods_supportedtherefore reject spec-compliant clients (e.g. clients that use Basic and do not duplicateclient_idinto the body).Location
src/mcp/server/auth/middleware/client_auth.py,authenticate_request:client_idfrom the Basic header is only used to cross-check a body-supplied value; it is never used as a fallback source. So a request with credentials solely in the Basic header fails before the client is even looked up.Steps to reproduce
token_endpoint_auth_method=client_secret_basic.POST /tokenwithgrant_type=authorization_code,Authorization: Basic base64(client_id:client_secret), and noclient_id/client_secretin the form body.401 {"error":"invalid_client","error_description":"Missing client_id"}.Sending the same credentials via
client_secret_post(in the body) works.Expected
When
Authorization: Basicis present, the authenticator should deriveclient_idfrom the header if it is absent from the body (RFC 6749 §2.3.1), then verify the secret as it does today.Notes
This is the mirror image of client-side PR #3536 (which stops MCP clients from putting
client_idin the body underclient_secret_basic). With that client-side change, compliant clients will sendclient_idonly in the Basic header — which this server-side code rejects. The two need to agree.Observed on
mcp1.27.0.