fix: advertise the audience scope so tokens actually carry aud
The OAuth path to /api/mcp has never worked end to end. Every access token arrived without an `aud` claim and jwt.ts rejected it with "claim invalid: aud" (401), even though the handshake, consent and PKCE all succeeded. Only the CLI HMAC path worked, because cli-token.ts sets the audience itself — which is why this went unnoticed. Cause: Authentik evaluates a scope mapping only when the client REQUESTS that scope by name. An MCP client learns which scopes to request from `scopes_supported` in our RFC 9728 protected-resource metadata, and we only advertised openid/profile/email. So the `aud-shared-memory` mapping was attached to the provider but never evaluated. Advertise the audience scope in that metadata. Name is derived as `aud-<OIDC_AUDIENCE>` to match the README convention, overridable with the new optional OIDC_AUDIENCE_SCOPE for deployments that named it differently. Also documents that Claude Code's RFC 8707 `resource` parameter is ignored by Authentik 2026.5, so it cannot be relied on for audience binding. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -35,6 +35,12 @@ OIDC_CLIENT_ID_WEB=replace-me
|
||||
OIDC_CLIENT_SECRET_WEB=replace-me
|
||||
OIDC_CLIENT_ID_MCP=replace-me
|
||||
OIDC_AUDIENCE=shared-memory
|
||||
# Scope whose IdP mapping emits `aud: <OIDC_AUDIENCE>`. Advertised in
|
||||
# /.well-known/oauth-protected-resource so MCP clients request it — without
|
||||
# that, Authentik never evaluates the mapping and every token 401s with
|
||||
# "claim invalid: aud". Defaults to aud-<OIDC_AUDIENCE>; set only if you
|
||||
# named the scope mapping something else.
|
||||
#OIDC_AUDIENCE_SCOPE=aud-shared-memory
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# Database (Postgres 16 + pgvector — pgvector/pgvector:pg16 image)
|
||||
|
||||
Reference in New Issue
Block a user