Skip to content

Make client_secret optional in token revocation requests - #3512

Closed
HARSHAVARDHAN-RAJU5 wants to merge 1 commit into
modelcontextprotocol:mainfrom
HARSHAVARDHAN-RAJU5:main
Closed

HARSHAVARDHAN-RAJU5 wants to merge 1 commit into
modelcontextprotocol:mainfrom
HARSHAVARDHAN-RAJU5:main

Conversation

@HARSHAVARDHAN-RAJU5

@HARSHAVARDHAN-RAJU5 HARSHAVARDHAN-RAJU5 commented Sep 16, 2026

Copy link
Copy Markdown

Fixes #3508

Public OAuth clients can now revoke tokens without sending client_secret.

Motivation and Context

RevocationRequest.client_secret was declared as str | None with no default. Pydantic v2 treats that as required: the value can be None, but the key has to be present. Public clients (token_endpoint_auth_method: "none") don't have a secret, so they leave the parameter out, as RFC 6749 §2.3 and RFC 7009 §5 allow. /revoke then rejected them with:

400 {"error":"invalid_request","error_description":"client_secret: Field required"}

ClientAuthenticator already lets public clients through, so the only problem was the request model. The fix defaults the field to None, which matches how the token endpoint handles it.

How Has This Been Tested?

  • Added test_revoke_public_client_without_client_secret. It registers a client with token_endpoint_auth_method: "none", gives it an access token, and revokes that token without client_secret. It checks for a 200 and that the token is gone.
  • The new test fails without the fix and passes with it.
  • All tests in tests/server/mcpserver/auth/test_auth_integration.py pass.
  • ruff format, ruff check and pyright are clean.

Breaking Changes

None. Requests that already sent client_secret behave the same way.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I am assigned to the linked issue (or it is labeled help wanted, or I'm a maintainer)
  • I have disclosed any AI assistance and can explain the change in my own words
  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

This is a one-line change to the model plus a regression test. Nothing in the docs needed updating, because nothing there says client_secret is required for revocation.

@github-actions github-actions Bot added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Sep 16, 2026
@github-actions

github-actions Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #3508.

If a maintainer assigns you to #3508, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take.

You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way.

CONTRIBUTING.md has the full reasoning, but in short:

  • We're a small team with very little capacity to review community PRs right now.
  • Many recent PRs are AI-generated with little human review, and reviewing one carefully still costs a maintainer as much time as it ever did. A well-described issue is usually more useful to us than the code.

Maintainers: reopen, remove missing-issue-link, or add bypass-issue-check to override.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Revocation requires client_secret to be present

1 participant