Skip to content

[POC DO NOT MERGE] docs: MCP token exchange - #7521

Draft
yangleyland wants to merge 1 commit into
mainfrom
leyland/mcp-token-exchange-poc
Draft

yangleyland wants to merge 1 commit into
mainfrom
leyland/mcp-token-exchange-poc

Conversation

@yangleyland

Copy link
Copy Markdown
Contributor

Summary

  • POC docs for a proposed RFC 8693 token-exchange grant on /authed/mcp/oauth/token, letting a customer's server get a per-user, group-scoped MCP token without a browser redirect (asks from TRM Labs and EliseAI)
  • Covers OAuth subject tokens (validated via the deployment's user info API URL) and JWT subject tokens (signed with the existing JWT auth key)
  • The feature is not built yet. Do not merge.

Test plan

  • Open the preview and read AI > Model Context Protocol > Token exchange; confirm the steps, tabs, and anchor links (client credentials, groups, user data format) render and resolve correctly

@yangleyland yangleyland added the POC DO NOT MERGE Proof of concept, do not merge label Sep 25, 2026
@mintlify

mintlify Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
mintlify 🟢 Ready View Preview Sep 25, 2026, 7:26 PM

This branch was successfully deployed

1 active deployment
staging — 85cf7aa2 Deployed Sep 25, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

POC DO NOT MERGE Proof of concept, do not merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant