MCP: Upstream OAuth, Dynamic Client Registration & Route Discovery

July 6, 2026
Share on Bluesky

Pomerium's MCP gateway now handles more of the OAuth complexity that real-world MCP servers require. This update adds upstream OAuth support with token caching and injection, Dynamic Client Registration as a fallback for clients that don't yet support Client ID Metadata Documents, auto-discovery for MCP connect flows, and the first MCP-facing configuration APIs. The result is less manual upstream OAuth configuration, more reliable session handling, and a cleaner experience in the routes portal.

Highlights:

  • Upstream OAuth for MCP routes – Pomerium can now discover upstream OAuth metadata, complete upstream authorization flows, cache client and token state, and inject upstream access tokens into MCP traffic when the target server requires them.

  • Dynamic Client Registration fallback – Pomerium now supports DCR for upstream OAuth flows, providing a practical path for tools like MCP Inspector while Client ID Metadata Document support matures across the ecosystem.

  • Issuer metadata in authorization flows – Pomerium now includes the recommended iss parameter in MCP authorization flows, aligning with the upcoming 2026-07-28 MCP spec. Pomerium's host is returned as the issuer, keeping authorization flows spec-compliant as the standard evolves.

  • Auto-discovery for MCP connect flows – MCP connect, disconnect, and authorize endpoints now support auto-discovery, reducing the static upstream OAuth configuration needed for compatible servers.

  • Safer metadata fetching – MCP metadata discovery uses SSRF-safe HTTP fetching and stricter protected-resource metadata handling, including path-prefix validation.

  • Better routes portal experience – MCP routes now show server indicators and connect/disconnect controls in the routes portal, making MCP-enabled routes easier to identify and manage.

  • More reliable upstream auth recovery – Pomerium refreshes expired upstream tokens before forcing reauthentication, recovers upstream auth after late config delivery, and surfaces clearer errors when upstream tokens can't be resolved.

  • Config API as MCP tools – A new pkg/mcp/configapi library exposes Pomerium's ConfigService as MCP tools, with generated schemas, sensitive-field handling, and update-safety checks — early building blocks for MCP-driven configuration workflows.

See the MCP support docs to learn how Pomerium secures MCP routes and manages upstream OAuth on behalf of clients.

Share: Share on Bluesky

Get our product updates delivered directly to your inbox

Revolutionize
Your Security

Embrace Seamless Resource Access, Robust Zero Trust Integration, and Streamlined Compliance with Our App.