CourseModel Context Protocol · Module 7: Authorization · part 40 of 83
Part 40 · Module 7: Authorization

Topic 1: Module 7 at a glance

3 min read·22 Sept 2026

By the end of this module, you'll have:

  • A notes server that runs over streamable HTTP as a real OAuth 2.1 resource server: it answers 401 with a pointer to its discovery document, verifies every bearer token, and refuses tokens minted for any other server.
  • notes_assistant/auth.py (the JWTTokenVerifier, mint_dev_token, and auth_from_env) and the final notes_assistant/server.py, with a scope check that keeps create_note behind notes:write.
  • A working understanding of the whole authorization code flow: protected resource metadata, authorization server discovery, PKCE with S256, resource indicators, and the iss check, backed by a script that computes the PKCE values for real.
  • The ability to choose between Client ID Metadata Documents, pre-registration, and the now deprecated dynamic client registration, and to write a client metadata document.
  • A least-privilege scope design for the notes tools, a client that works out which scopes to ask for from a WWW-Authenticate challenge, and a concrete demonstration of why token passthrough is forbidden.
  • A path to production: swapping the development HS256 key for a provider's RS256 keys fetched from its JWKS endpoint, plus an overview of enterprise identity provider integration with ID-JAG.

Prerequisites: Modules 1 to 6. You need the server from Module 5 (build_server, main, the environment settings in config.py) and the HTTP client skills from Module 6 (Client, streamable_http_client, httpx2). You should know what an HTTP header is and have seen a JWT before, even if only in a debugger. No OAuth experience is assumed.

Where we are: Module 6 gave Nare a host that talks to the notes server over stdio or HTTP. Over stdio that is fine: the server runs as her own process. Over HTTP, though, anyone who can reach the port can read her lab notes and write new ones. Priya and Tomas want to use the server from their laptops, so in this module we lock the HTTP door properly.

The rest of this course is yours to keep

This course is bought on its own, once, and stays readable afterwards, including the parts added to it later.