validateAuthIssuer() compares the received issuer with the issuer recorded at flow start and throws MCPAuthError when missing or mismatched. Pass the decoded iss value, not the callback URL.
pickOidcApplicationType() returns native for localhost redirects or web otherwise, with an explicit override available. It selects registration metadata; it does not validate every redirect-URI policy.
needsReRegistration() returns true when either issuer is missing or they differ. Persist the issuer with registered client credentials and compare it with current trusted metadata.
The MCP adapter’s credential audience and transport restrictions are separate. See MCP v2: strict credentialed HTTP rejects redirects and cross-origin forwarding. A host-reviewed custom transport is required for a multi-origin OAuth deployment.