Skip to content

[Server] Fix JwtTokenValidator fetching keys only for the first issuer - #531

Open
chr-hertel wants to merge 1 commit into
modelcontextprotocol:mainfrom
chr-hertel:fix-jwt-multi-issuer-jwks
Open

chr-hertel wants to merge 1 commit into
modelcontextprotocol:mainfrom
chr-hertel:fix-jwt-multi-issuer-jwks

Conversation

@chr-hertel

Copy link
Copy Markdown
Member

Closes #530

  • read the unverified iss from the payload first and reject it unless it's one of the configured issuers - before any discovery or JWKS fetch
  • fetch the keys for that issuer, then verify signature & claims as before
  • an explicit jwksUri applies to all listed issuers, which fits the alias semantics and keeps the Keycloak & Microsoft examples working
  • docs now say the issuer list is meant for aliases of one authorization server

JwtTokenValidator always fetched the keys of the first configured issuer. Read the token's iss first, require it to be configured, and verify with that issuer's keys.
@chr-hertel chr-hertel added the Server Issues & PRs related to the Server component label Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Server Issues & PRs related to the Server component

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Server] JwtTokenValidator only fetches the keys of the first configured issuer

2 participants