Verified MCP clients: URL-based identity and admission control for MCP OAuth
Blog post from Speakeasy
Speakeasy has introduced support for Client ID Metadata Documents (CIMD) to let MCP clients identify themselves through verifiable URL-based metadata rather than Dynamic Client Registration (DCR), which relies on self-asserted client names and redirect URIs, creates separate registrations per installation, and offers no reliable client allowlisting. Under CIMD, a client vendor publishes metadata at an HTTPS URL it controls, which Speakeasy’s AI Control Plane fetches and validates before authenticating users through an identity provider and allowing MCP tool calls. Organizations can use an open policy that accepts valid CIMD URLs or a presets mode that permits only exact URLs from Speakeasy’s vendor catalog or administrator-defined custom entries, with policy controls applied separately to each MCP server issuer and recorded in audit logs. CIMD, adopted by MCP and now preferred over DCR in the specification, improves client admission control but does not verify the local client binary or replace user authentication. DCR remains supported for older clients without a planned retirement date, while the release currently focuses on public clients and leaves confidential-client support as future work.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 20 | 2,241 | 148 | 72 | -74% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.