@@ -43,6 +43,11 @@ export interface PreregisteredClient {
4343 configurationFingerprint ?: string
4444 scope ?: string
4545 tokenEndpointAuthMethod ?: 'client_secret_basic' | 'client_secret_post'
46+ /**
47+ * Authorization server the credentials are registered with. When unset, they are bound to
48+ * the issuer of the current grant, so the SDK never presents the secret to another server.
49+ */
50+ issuer ?: string
4651}
4752
4853interface SimMcpOauthProviderInit {
@@ -107,6 +112,7 @@ export class SimMcpOauthProvider implements OAuthClientProvider {
107112 token_endpoint_auth_method :
108113 this . preregistered . tokenEndpointAuthMethod ??
109114 ( this . preregistered . clientSecret ? 'client_secret_post' : 'none' ) ,
115+ issuer : this . preregistered . issuer ?? this . row . tokens ?. issuer ,
110116 }
111117 }
112118 return undefined
@@ -226,6 +232,8 @@ export async function loadPreregisteredClient(
226232 if ( ! row . clientId || ! row . clientSecret )
227233 throw new Error ( 'HubSpot OAuth registration is incomplete' )
228234 }
235+ const issuer =
236+ row . connectorId === 'hubspot' ? MANAGED_MCP_CONNECTORS . hubspot . authorizationServer : undefined
229237 if ( ! row . clientId ) return undefined
230238 let clientSecret : string | undefined
231239 if ( row . clientSecret ) {
@@ -240,5 +248,5 @@ export async function loadPreregisteredClient(
240248 throw new Error ( 'Failed to decrypt preregistered MCP OAuth client secret' )
241249 }
242250 }
243- return { clientId : row . clientId , clientSecret }
251+ return { clientId : row . clientId , clientSecret, issuer }
244252}
0 commit comments