JustHandled Labs
// AI Agents & LLM Ops

MCP OAuth & Authorization Contract Preflight

Preflight redacted MCP 2026-07-28 OAuth evidence for issuer discovery, registration, PKCE, scopes, token audience, refresh behavior, and role-specific gaps.

What problem does MCP OAuth & Authorization Contract Preflight solve?

MCP client, server, gateway, and platform teams need to catch authorization-contract regressions before a migration reaches production. This offline gate turns owner-supplied, redacted metadata, registration records, and transcripts into deterministic findings for the stable MCP 2026-07-28 profile.

Use it to

What it returns

A representative input and result

fixture-backed sample
input Pin `rule_snapshot` to `MCP-2026-07-28`, `spec_status` to `stable`, and the documented official source digests. Supply role-appropriate metadata documents, registrations, and redacted transcripts with opaque evidence references.
result A deterministic READY, REVIEW, CANNOT_ASSESS, or BLOCK result with stable finding codes, a complete review manifest, a human-readable report, and a SHA-256 receipt.

Access and approval boundaries

Known limitations

Questions

Does it connect to a live account or provider?

No. It reads one normalized local JSON packet and makes no network request.

Does it make the final decision or external change?

No. It produces evidence findings; the responsible owner makes every decision and action outside the package.

Is the result deterministic?

Yes. Stable finding codes, sorted records, and a SHA-256 receipt make repeated review inspectable.

When does it return CANNOT_ASSESS?

It returns CANNOT_ASSESS when the supplied packet lacks evidence required for the declared client, server, or combined implementation role.

What happens with malformed input?

Unreadable JSON, missing arrays, duplicate core identifiers, invalid timestamps, and invalid core numbers fail closed.

Does READY prove the underlying evidence is true?

No. READY means no automated finding appeared in the supplied normalized packet; source truth still requires human review.

Preflight the MCP authorization contract before deployment.

Version 1.1.0 includes the tested offline package, realistic fixtures, declared permissions, explicit evidence gaps, and a checksum-pinned buyer receipt.

Get MCP OAuth & Authorization Contract Preflight v1.1