Building on Pomerium's experimental Model Context Protocol (MCP) support, the v0.32 line hardens the MCP gateway for real-world AI workflows. Sessions now survive longer thanks to OAuth refresh tokens, clients can register themselves dynamically, error pages are clearer, and a security fix in the underlying SDK closes a message-smuggling vulnerability.
Highlights:
OAuth refresh token support – Pomerium now issues and honors refresh tokens for MCP sessions, so long-running agents and clients can stay connected without forcing repeated interactive logins.
Dynamic client registration – Support for client ID metadata documents lets MCP clients register with Pomerium automatically, removing manual setup steps when onboarding new clients.
Customizable, friendlier error pages – The MCP 401 page can be customized, and unauthorized client domains now get a clear, user-friendly error instead of a cryptic failure. Allowed client domains are also optional, simplifying configuration.
Security hardening – The MCP Go SDK was updated to v1.3.1 to fix a message-smuggling vulnerability caused by case-insensitive JSON unmarshalling, and Pomerium now sets a proper WWW-Authenticate header on unauthorized responses.
See the MCP documentation for configuration details.
Embrace Seamless Resource Access, Robust Zero Trust Integration, and Streamlined Compliance with Our App.