This release fixes issues for SREs watching stability and regressions.
Published 27d
MCP Developer Tools
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
ai-agents
api-gateway
chatgpt
chatgpt-apps
claude
claude-connectors
+14 more
database-mcp-server
gemini
graphql-to-mcp
mcp
mcp-gateway
mcp-servers
model-context-protocol
no-code
openapi-to-mcp
rest-to-mcp
self-hosted
soap-to-mcp
sql-to-mcp
typescript
Affected surfaces
auth
Summary
AI summaryFixed MCP OAuth/OIDC discovery for third‑party clients such as Microsoft Copilot Studio.
Full changelog
Fixed
- MCP OAuth/OIDC discovery for third-party clients. Serve
/.well-known/openid-configurationand the per-serveroauth-authorization-server/oauth-protected-resourcemetadata (RFC 8414/9728). Clients that append the resource path during discovery — e.g. Microsoft Copilot Studio — can now complete the OAuth flow and connect. The401WWW-Authenticateheader now pointsresource_metadataat the per-server document. Additive only; existing clients (Dynamic Client Registration, e.g. Claude) are unaffected.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About AnythingMCP
All releases →Related context
Beta — feedback welcome: [email protected]