Skip to main content
Agentium exports small authorization helpers for applications that own an MCP OAuth flow. They do not implement a token vault, browser consent flow, or a complete authorization server.
validateAuthIssuer() compares the received issuer with the issuer recorded at flow start and throws MCPAuthError when missing or mismatched. Pass the decoded iss value, not the callback URL. pickOidcApplicationType() returns native for localhost redirects or web otherwise, with an explicit override available. It selects registration metadata; it does not validate every redirect-URI policy. needsReRegistration() returns true when either issuer is missing or they differ. Persist the issuer with registered client credentials and compare it with current trusted metadata. The MCP adapter’s credential audience and transport restrictions are separate. See MCP v2: strict credentialed HTTP rejects redirects and cross-origin forwarding. A host-reviewed custom transport is required for a multi-origin OAuth deployment.