Authorization flow documentation still talks about DCR (deprecated) and does not mention CIMD

Author: udbhav-sCreated Sep 3, 2026Updated Sep 9, 2026
Labelsbug

What's broken?

The documentation is wrong or misleading

Where in the spec or docs?

https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/authorization

What should happen?

The docs should mention new authorization flow using Client ID Metadata Documents (CIMD) and mention that Dynamic Client Registration (DCR) is deprecated.

What actually happens?

The docs do not mention CIMD anywhere, and still describe DCR as one of the primary ways for an MCP client to gain authorization.

Anything else?

No response

Source: modelcontextprotocol/modelcontextprotocol