Pomerium's MCP gateway now handles more of the OAuth complexity that real-world MCP servers require. This update adds upstream OAuth support with token caching and injection, Dynamic Client Registration as a fallback for clients that don't yet support Client ID Metadata Documents, auto-discovery for MCP connect flows, and the first MCP-facing configuration APIs. The result is less manual upstream OAuth configuration, more reliable session handling, and a cleaner experience in the routes portal.
Highlights:
Upstream OAuth for MCP routes – Pomerium can now discover upstream OAuth metadata, complete upstream authorization flows, cache client and token state, and inject upstream access tokens into MCP traffic when the target server requires them.
Dynamic Client Registration fallback – Pomerium now supports DCR for upstream OAuth flows, providing a practical path for tools like MCP Inspector while Client ID Metadata Document support matures across the ecosystem.
Issuer metadata in authorization flows – Pomerium now includes the recommended iss parameter in MCP authorization flows, aligning with the upcoming 2026-07-28 MCP spec. Pomerium's host is returned as the issuer, keeping authorization flows spec-compliant as the standard evolves.
Auto-discovery for MCP connect flows – MCP connect, disconnect, and authorize endpoints now support auto-discovery, reducing the static upstream OAuth configuration needed for compatible servers.
Safer metadata fetching – MCP metadata discovery uses SSRF-safe HTTP fetching and stricter protected-resource metadata handling, including path-prefix validation.
Better routes portal experience – MCP routes now show server indicators and connect/disconnect controls in the routes portal, making MCP-enabled routes easier to identify and manage.
More reliable upstream auth recovery – Pomerium refreshes expired upstream tokens before forcing reauthentication, recovers upstream auth after late config delivery, and surfaces clearer errors when upstream tokens can't be resolved.
Config API as MCP tools – A new pkg/mcp/configapi library exposes Pomerium's ConfigService as MCP tools, with generated schemas, sensitive-field handling, and update-safety checks — early building blocks for MCP-driven configuration workflows.
See the MCP support docs to learn how Pomerium secures MCP routes and manages upstream OAuth on behalf of clients.
Embrace Seamless Resource Access, Robust Zero Trust Integration, and Streamlined Compliance with Our App.