Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE)

News

The MCP authorization specification (November 2025) mandates OAuth 2.1 with PKCE for remote MCP servers. In practice, this security model is only achievable if MCP clients implement the OAuth refresh_token grant. Most major vendors have been lagging with support, but more progress is finally being made! As of June 2026, the ecosystem has made progress since our initial April survey, with Gemini CLI achieving full support and several clients upgrading from “not implemented” to partial. submitted by /u/mhat [link] [comments]Technical Information Security Content & DiscussionRead More