From a0d5df21dae230892c7758c2b26e7cd2b043ae67 Mon Sep 17 00:00:00 2001 From: Tin Chi Lo Date: Tue, 14 Jul 2026 18:08:55 -0700 Subject: [PATCH] fix(mcp): do not persist authorization_url from the DCR path; the build hook is the provenance-guarded writer --- .../proxy/_experimental/mcp_server/discoverable_endpoints.py | 1 - .../_experimental/mcp_server/test_discoverable_endpoints.py | 2 +- 2 files changed, 1 insertion(+), 2 deletions(-) diff --git a/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py b/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py index 0cd217ec96e..54aff86aab2 100644 --- a/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py +++ b/litellm/proxy/_experimental/mcp_server/discoverable_endpoints.py @@ -1133,7 +1133,6 @@ async def _persist_dcr_client_registration( credentials=credentials, oauth2_flow="authorization_code", **({"token_url": mcp_server.token_url} if mcp_server.token_url else {}), - **({"authorization_url": mcp_server.authorization_url} if mcp_server.authorization_url else {}), ), touched_by="mcp_oauth_dcr", ) diff --git a/tests/test_litellm/proxy/_experimental/mcp_server/test_discoverable_endpoints.py b/tests/test_litellm/proxy/_experimental/mcp_server/test_discoverable_endpoints.py index 66a14741fb1..f5ac229d119 100644 --- a/tests/test_litellm/proxy/_experimental/mcp_server/test_discoverable_endpoints.py +++ b/tests/test_litellm/proxy/_experimental/mcp_server/test_discoverable_endpoints.py @@ -657,7 +657,7 @@ async def test_register_client_persists_dcr_client_identity(): update_data = mock_update.call_args.kwargs["data"] assert update_data.server_id == "remote_server" assert update_data.token_url == "https://provider.example/oauth/token" - assert update_data.authorization_url == "https://provider.example/oauth/authorize" + assert "authorization_url" not in update_data.fields_set() assert update_data.credentials["client_id"] == "generated-client" assert update_data.credentials["client_secret"] == "generated-secret" assert update_data.credentials["token_endpoint_auth_method"] == "client_secret_basic"