Skip to main content

Changelog

MCP: Refresh Tokens, Dynamic Client Registration & Friendlier Errors

Building on Pomerium's experimental Model Context Protocol (MCP) support , the v0.32 line hardens the MCP gateway for real-world AI workflows. Sessions now survive longer thanks to OAuth refresh tokens, clients can register themselves dynamically, error pages are clearer, and a security fix in the underlying SDK closes a message-smuggling vulnerability.

Building on Pomerium's experimental Model Context Protocol (MCP) support, the v0.32 line hardens the MCP gateway for real-world AI workflows. Sessions now survive longer thanks to OAuth refresh tokens, clients can register themselves dynamically, error pages are clearer, and a security fix in the underlying SDK closes a message-smuggling vulnerability.

Highlights:

  • OAuth refresh token support – Pomerium now issues and honors refresh tokens for MCP sessions, so long-running agents and clients can stay connected without forcing repeated interactive logins.
  • Dynamic client registration – Support for client ID metadata documents lets MCP clients register with Pomerium automatically, removing manual setup steps when onboarding new clients.
  • Customizable, friendlier error pages – The MCP 401 page can be customized, and unauthorized client domains now get a clear, user-friendly error instead of a cryptic failure. Allowed client domains are also optional, simplifying configuration.
  • Security hardening – The MCP Go SDK was updated to v1.3.1 to fix a message-smuggling vulnerability caused by case-insensitive JSON unmarshalling, and Pomerium now sets a proper WWW-Authenticate header on unauthorized responses.

See the MCP documentation for configuration details.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo