MCP: Refresh Tokens, Dynamic Client Registration & Friendlier Errors

January 20, 2026
Share on Bluesky

Building on Pomerium's experimental Model Context Protocol (MCP) support, the v0.32 line hardens the MCP gateway for real-world AI workflows. Sessions now survive longer thanks to OAuth refresh tokens, clients can register themselves dynamically, error pages are clearer, and a security fix in the underlying SDK closes a message-smuggling vulnerability.

Highlights:

  • OAuth refresh token support – Pomerium now issues and honors refresh tokens for MCP sessions, so long-running agents and clients can stay connected without forcing repeated interactive logins.

  • Dynamic client registration – Support for client ID metadata documents lets MCP clients register with Pomerium automatically, removing manual setup steps when onboarding new clients.

  • Customizable, friendlier error pages – The MCP 401 page can be customized, and unauthorized client domains now get a clear, user-friendly error instead of a cryptic failure. Allowed client domains are also optional, simplifying configuration.

  • Security hardening – The MCP Go SDK was updated to v1.3.1 to fix a message-smuggling vulnerability caused by case-insensitive JSON unmarshalling, and Pomerium now sets a proper WWW-Authenticate header on unauthorized responses.

See the MCP documentation for configuration details.

Share: Share on Bluesky

Get our product updates delivered directly to your inbox

Revolutionize
Your Security

Embrace Seamless Resource Access, Robust Zero Trust Integration, and Streamlined Compliance with Our App.