Skip to content

[Server] Fix JwtTokenValidator fetching keys only for the first issuer - #531

Merged
chr-hertel merged 1 commit into
modelcontextprotocol:mainfrom
chr-hertel:fix-jwt-multi-issuer-jwks
Oct 6, 2026
Merged

chr-hertel merged 1 commit into
modelcontextprotocol:mainfrom
chr-hertel:fix-jwt-multi-issuer-jwks

Conversation

@chr-hertel

Copy link
Copy Markdown
Member

Closes #530

  • read the unverified iss from the payload first and reject it unless it's one of the configured issuers - before any discovery or JWKS fetch
  • fetch the keys for that issuer, then verify signature & claims as before
  • an explicit jwksUri applies to all listed issuers, which fits the alias semantics and keeps the Keycloak & Microsoft examples working
  • docs now say the issuer list is meant for aliases of one authorization server

@chr-hertel chr-hertel added the Server Issues & PRs related to the Server component label Oct 5, 2026
soyuka
soyuka previously approved these changes Oct 6, 2026
JwtTokenValidator always fetched the keys of the first configured issuer. Read the token's iss first, require it to be configured, and verify with that issuer's keys.
@chr-hertel
chr-hertel force-pushed the fix-jwt-multi-issuer-jwks branch from 33d49ed to 05c6efa Compare October 6, 2026 21:17
@chr-hertel
chr-hertel merged commit ad0bc26 into modelcontextprotocol:main Oct 6, 2026
27 checks passed
@chr-hertel
chr-hertel deleted the fix-jwt-multi-issuer-jwks branch October 6, 2026 21:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Server Issues & PRs related to the Server component

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Server] JwtTokenValidator only fetches the keys of the first configured issuer

2 participants