From 17dfccc5ee9fe193e7621142508674c6096a99c4 Mon Sep 17 00:00:00 2001 From: "keycard-gh-workflows-access[bot]" <259488581+keycard-gh-workflows-access[bot]@users.noreply.github.com> Date: Tue, 28 Jul 2026 20:44:07 +0000 Subject: [PATCH] =?UTF-8?q?bump:=20keycardai-mcp=20=E2=86=92=200.12.1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Auto-bump for keycardai-mcp. --- packages/mcp/.cz.toml | 2 +- packages/mcp/CHANGELOG.md | 36 ++++++++++++++++++++++++++++++++++++ packages/mcp/package.json | 2 +- 3 files changed, 38 insertions(+), 2 deletions(-) diff --git a/packages/mcp/.cz.toml b/packages/mcp/.cz.toml index 6071752..afc86f6 100644 --- a/packages/mcp/.cz.toml +++ b/packages/mcp/.cz.toml @@ -1,6 +1,6 @@ [tool.commitizen] name = "cz_customize" -version = "0.12.0" +version = "0.12.1" version_files = ["package.json:version"] tag_format = "${version}-keycardai-mcp" ignored_tag_formats = ["${version}-*"] diff --git a/packages/mcp/CHANGELOG.md b/packages/mcp/CHANGELOG.md index 9d411a1..fdf8407 100644 --- a/packages/mcp/CHANGELOG.md +++ b/packages/mcp/CHANGELOG.md @@ -1,3 +1,39 @@ +## 0.12.1-keycardai-mcp (2026-07-28) + + +- fix(mcp): client provider store saves and private_key_jwt client assertion (#126) +- * fix(mcp): return store promises from saveTokens and saveCodeVerifier +- The MCP SDK awaits OAuthClientProvider.saveTokens and saveCodeVerifier +before proceeding with the OAuth flow, but both methods discarded the +result of the underlying store save. With an async store the flow could +redirect to authorization before the code verifier persisted, and +reconnects could miss freshly saved tokens. Store write failures were +also silently swallowed as floating promise rejections. +- Return the store call so callers observe completion and failures, +matching how tokens() and codeVerifier() already return store promises. +- Co-Authored-By: Claude Fable 5 +- * fix(mcp): attach client assertion params for private_key_jwt token requests +- addClientAuthentication signed a client assertion for private_key_jwt +clients but never wrote it to the request params, so token requests +went out with no client authentication at all. +- Attach the RFC 7523 section 2.2 parameters: client_assertion_type, +the signed client_assertion, and client_id. +- Also set the assertion's iss claim to the client_id as required by +RFC 7523 section 3 for client authentication. JSONWebTokenSigner +previously never set iss, leaving JWTSigner to fall back to the +keyring issuer, which is not guaranteed to equal the client_id. +FullAuthInfo gains an optional issuer field; callers that omit it +keep the keyring-issuer fallback. +- Co-Authored-By: Claude Fable 5 +- * fix(mcp): decouple the iss override from the signer's fallback semantics +- Set iss only when a caller provides it, so the keyring-issuer fallback +path never depends on how the oauth signer treats an explicit undefined. +Also widen the client assertion lifetime to 300s for clock-skew +tolerance; the jti bounds replay by uniqueness. +- Co-Authored-By: Claude Fable 5 +- --------- +- Co-authored-by: Claude Fable 5 + ## 0.12.0-keycardai-mcp (2026-07-20) diff --git a/packages/mcp/package.json b/packages/mcp/package.json index d4ef460..c3e69d9 100644 --- a/packages/mcp/package.json +++ b/packages/mcp/package.json @@ -1,6 +1,6 @@ { "name": "@keycardai/mcp", - "version": "0.12.0", + "version": "0.12.1", "description": "[Preview] High-security OAuth implementation for Model Context Protocol", "license": "MIT", "repository": {