OAuthPilfer Check
A client-side authorization test workspace that inventories approved MCP clients, executes bounded OAuth and PKCE scenarios against controlled servers, preserves requests, responses, versions, failures, remediation, retests, and signed evidence with explicit coverage limits.
The research confirms two open-source MCP conformance harnesses and a server-side certification product. It did not find a commercial client-side enterprise testing product. No structural incumbent copying cost is evidenced, so a maintained client matrix and evidence workflow are operational value rather than a protected category.
OAuth requirements depend on the exact MCP protocol version, transport, client type, authorization-server metadata, protected-resource metadata, redirect model, PKCE method, token lifecycle, scopes, resource indicators, errors, and optional versus required behavior. OAuth 2.1 remains a moving standards context and cannot be reduced to a timeless checklist. A PASS on a controlled server does not prove security, interoperability with every provider, correct deployment, absence of token theft, or production compliance.
European cyber-resilience and network-security duties do not follow automatically from protocol conformance. The source's claimed September 2026 deadline needs current primary review and product-role analysis. Evidence bundles name the client build, spec and test versions, environment, coverage, observed results, gaps, and corrections; they never certify CRA, NIS2, audit readiness, or secure implementation.
Security, identity, platform, and GRC teams that approve MCP clients and need repeatable client-side authorization evidence across versions.
Security and GRC teams approving clients are specific.
The test matrix and evidence pipeline are code-driven and reusable.
The source has moderate support around an emerging protocol-control gap.
The enterprise client-side buyer, live server-side harnesses, versioned test matrix, controlled runs, and evidence artifact are concrete.
No structural moat is shown, client automation may be brittle, standards change, vendor clients are opaque, and conformance cannot establish security or regulation.
Discussion
No comments yet — be the first to weigh in.
