Authorization flow documentation still talks about DCR (deprecated) and does not mention CIMD
Author: udbhav-sCreated Sep 3, 2026Updated Sep 9, 2026
Labelsbug
What's broken?
The documentation is wrong or misleading
Where in the spec or docs?
https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/authorization
What should happen?
The docs should mention new authorization flow using Client ID Metadata Documents (CIMD) and mention that Dynamic Client Registration (DCR) is deprecated.
What actually happens?
The docs do not mention CIMD anywhere, and still describe DCR as one of the primary ways for an MCP client to gain authorization.
Anything else?
No response
Source: modelcontextprotocol/modelcontextprotocol