Add enterprise ID-JAG exchange for MCP OAuth (#40722)
## What changed - Add a non-interactive two-step exchange that obtains an ID-JAG from an enterprise identity provider and trades it for a resource-bound MCP bearer token. - Validate trusted endpoint URLs, request inputs, ID-JAG claims, resource and scope bindings, and token responses before credentials are forwarded or a bearer token is returned. - Expose structured authentication failures while redacting credentials and provider-controlled error details from diagnostics. ## Testing - Cover successful exchanges, signed scope narrowing, invalid claims and token responses, request validation, and error redaction. GitOrigin-RevId: d716e0e1c2dc6b230cecbc0e9cc09afeee81d599
N
Nick Steele committed
f6805328c434eebb032bced0da29e39ba6dc3aee
Parent: d6174a8
Committed by copyberry <copyberry@app.openai.com>
on 8/25/2026, 10:12:41 PM