Best fit
MCP server and client teams debug 401 challenges, protected-resource metadata, issuer discovery, resource indicators, PKCE, scopes, and token audience from ad hoc traces.
Preflight redacted MCP 2026-07-28 OAuth evidence for issuer discovery, registration, PKCE, scopes, token audience, refresh behavior, and role-specific gaps.
MCP client, server, gateway, and platform teams need to catch authorization-contract regressions before a migration reaches production. This offline gate turns owner-supplied, redacted metadata, registration records, and transcripts into deterministic findings for the stable MCP 2026-07-28 profile.
MCP server and client teams debug 401 challenges, protected-resource metadata, issuer discovery, resource indicators, PKCE, scopes, and token audience from ad hoc traces.
findings.csv with stable codes and evidence sources. review-manifest.csv with every reviewed record.
The pinned MCP-2026-07-28 rule snapshot can become stale and must be reviewed against later MCP revisions.
No. It reads one normalized local JSON packet and makes no network request.
No. It produces evidence findings; the responsible owner makes every decision and action outside the package.
Yes. Stable finding codes, sorted records, and a SHA-256 receipt make repeated review inspectable.
It returns CANNOT_ASSESS when the supplied packet lacks evidence required for the declared client, server, or combined implementation role.
Unreadable JSON, missing arrays, duplicate core identifiers, invalid timestamps, and invalid core numbers fail closed.
No. READY means no automated finding appeared in the supplied normalized packet; source truth still requires human review.
Version 1.1.0 includes the tested offline package, realistic fixtures, declared permissions, explicit evidence gaps, and a checksum-pinned buyer receipt.
Get MCP OAuth & Authorization Contract Preflight v1.1