`JwtTokenValidator` takes `issuer` as `string|list<string>`, but `getJwks()` always fetches the keys of the first issuer: https://github.com/modelcontextprotocol/php-sdk/blob/c9671c3/src/Server/Transport/Http/OAuth/JwtTokenValidator.php#L140-L141 ```php $validator = new JwtTokenValidator( issuer: ['https://first.example.com', 'https://second.example.com'], audience: 'mcp-api', jwksProvider: $jwksProvider, ); ``` => a valid token with `iss: https://second.example.com` gets rejected with `Token validation failed: "kid" invalid, unable to lookup correct key`, unless both issuers share their keys. And the keys used for the signature check are not tied to the issuer the token claims - `iss` is only compared against the whole list after decoding. The list is meant for aliases of one authorization server (see the Keycloak & Microsoft examples), so I'd read the token's `iss` first, require it to be one of the configured issuers, and verify with that issuer's keys. An explicit `jwksUri` keeps applying as is. Present since v0.5.0. Thanks @GEONWOOHAN for the report!