Skip to content

fix(mcp): advertise the authorization server verbatim in protected-resource metadata - #50

Merged
mikipalet merged 1 commit into
developfrom
fix/prm-authorization-server-exact-issuer
Oct 6, 2026
Merged

mikipalet merged 1 commit into
developfrom
fix/prm-authorization-server-exact-issuer

Conversation

@mikipalet

Copy link
Copy Markdown
Member

Why

Every new Hermes Agent 0.21.x connection to mcp.zernio.com fails with Authorization server metadata issuer mismatch: https://zernio.com != https://zernio.com/. The SDK's ProtectedResourceMetadata types authorization_servers as AnyHttpUrl, pydantic renders the bare origin with a trailing slash, and MCP SDK 2.x clients compare it byte for byte with the issuer from zernio.com/.well-known/oauth-authorization-server (SEP-2468). Axiom shows 12 Hermes 0.21.5 IPs looping on the issuer document in the last 48h and zero registrations from that user agent. Existing installs are unaffected (a stored refresh token skips discovery).

What

  • VerbatimIssuerRemoteAuthProvider renders the RFC 9728 document itself with authorization_servers as the configured strings; route path, CORS, cache header, scopes narrowing (ChatGPT surface) and resource are unchanged.
  • Tests assert the value equals the issuer string, including against the live authorization-server metadata.
  • Reproduced with the SDK 2.0 validator: live document fails, patched server passes.

Upstream fixed the model in mcp 2.0 (url_preserve_empty_path), but fastmcp 3.x caps mcp at 1.30.0, which still lacks it. Same change landed in the dormant zernio-mcp repo as #2 before I noticed develop here is what Railway serves.

🤖 Generated with Claude Code

https://claude.ai/code/session_011CMTnkAaNe8GJksNdAwg3K

…source metadata

The SDK's ProtectedResourceMetadata types authorization_servers as AnyHttpUrl,
and pydantic renders the bare origin as "https://zernio.com/". MCP SDK 2.x
clients (Hermes Agent 0.21+) compare that byte for byte with the issuer
"https://zernio.com" from zernio.com/.well-known/oauth-authorization-server
(SEP-2468) and abort with "Authorization server metadata issuer mismatch".
Axiom shows 12 Hermes 0.21.5 IPs looping on the issuer document in the last
48h and zero registrations from that user agent.

Upstream fixed the model in mcp 2.0 (url_preserve_empty_path), which fastmcp
3.x cannot resolve to, so the document is rendered by a RemoteAuthProvider
subclass instead.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011CMTnkAaNe8GJksNdAwg3K
@mikipalet
mikipalet merged commit 8105aad into develop Oct 6, 2026
4 checks passed
@mikipalet
mikipalet deleted the fix/prm-authorization-server-exact-issuer branch October 6, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant