CIMD Validator

MCP OAuth diagnostics

Observed MCP OAuth client behavior

See whether IDEs and developer tools use CIMD, fall back to Dynamic Client Registration, or send static client IDs during OAuth.

Built by @AkxenTech
Authorization server: /.well-known/oauth-authorization-server

Test endpoint

Add this Streamable HTTP MCP server URL to the client you want to test.

https://cimd-reader.akxen.tech/mcp

Codex CLI

codex mcp add cimd_reader \
  --url https://cimd-reader.akxen.tech/mcp \
  --oauth-resource https://cimd-reader.akxen.tech/mcp

codex mcp login cimd_reader

Claude Code

claude mcp add --transport http \
  cimd_reader \
  https://cimd-reader.akxen.tech/mcp

# then run /mcp in Claude Code

VS Code

{
  "servers": {
    "cimd_reader": {
      "type": "http",
      "url": "https://cimd-reader.akxen.tech/mcp",
      "oauth": {
        "clientId": "https://vscode.dev/oauth/client-metadata.json"
      }
    }
  }
}

Claude Code

CLI

cimd
Observed result
Claude Code authorization used client_id metadata URL https://claude.ai/oauth/claude-code-client-metadata.
Latest user agent
Bun/1.4.0
Latest event
POST /token
Client version
1.4.0
Claimed status
verified
Metadata name
Claude Code
Observed behavior
cimd
Metadata URL
https://claude.ai/oauth/claude-code-client-metadata
Client URI
https://claude.ai
Grant types
authorization_code, refresh_token
Response types
code
Token auth
none
App type
Not observed
Redirect URIs
http://localhost/callback, http://127.0.0.1/callback
Last observed: 2026-08-12T23:28:29.839Z

Codex CLI

CLI

cimd
Observed result
Codex authorization used client_id metadata URL https://chatgpt.com/oauth/codex/52-p_8rf-z-0/client.json.
Latest user agent
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/154.0.0.0 Safari/537.36
Latest event
GET /authorize
Client version
Unknown
Claimed status
unknown
Metadata name
Codex
Observed behavior
cimd
Metadata URL
https://chatgpt.com/oauth/codex/52-p_8rf-z-0/client.json
Client URI
https://chatgpt.com/codex
Grant types
authorization_code, refresh_token
Response types
code
Token auth
none
App type
native
Redirect URIs
http://127.0.0.1/callback/52-p_8rf-z-0, http://localhost/callback/52-p_8rf-z-0
Last observed: 2026-09-30T04:46:09.080Z

Cursor

IDE

dcr
Observed result
Cursor authorization used dynamically registered client_id dcr-cursor.
Latest user agent
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Cursor/3.15.19 Chrome/144.0.7559.236 Electron/40.10.3 Safari/537.36
Latest event
POST /token
Client version
3.15.19
Claimed status
unknown
Metadata name
Cursor
Observed behavior
dcr
Metadata URL
Unknown
Client URI
Not observed
Grant types
Not observed
Response types
Not observed
Token auth
Not observed
App type
Not observed
Redirect URIs
Not observed
Last observed: 2026-08-12T23:36:57.927Z

MCPJam

Debugger

cimd
Observed result
MCPJam authorization used client_id metadata URL https://www.mcpjam.com/.well-known/oauth/client-metadata.json.
Latest user agent
MCP-Inspector/1.0
Latest event
POST /token
Client version
1.0
Claimed status
unknown
Metadata name
MCPJam
Observed behavior
cimd
Metadata URL
https://www.mcpjam.com/.well-known/oauth/client-metadata.json
Client URI
https://www.mcpjam.com
Grant types
authorization_code, refresh_token, urn:ietf:params:oauth:grant-type:device_code
Response types
code
Token auth
none
App type
native
Redirect URIs
http://127.0.0.1:6274/oauth/callback, http://127.0.0.1:6274/callback, http://127.0.0.1:6274/oauth/callback/debug, http://localhost:6274/oauth/callback, http://localhost:6274/callback, http://localhost:6274/oauth/callback/debug, http://127.0.0.1:5173/oauth/callback, http://127.0.0.1:5173/oauth/callback/debug, http://localhost:5173/oauth/callback, http://localhost:5173/oauth/callback/debug, https://app.mcpjam.com/oauth/callback, https://app.mcpjam.com/oauth/callback/debug, https://staging.mcpjam.com/oauth/callback, https://staging.mcpjam.com/oauth/callback/debug, https://score.mcpjam.com/oauth/callback, https://score.mcpjam.com/oauth/callback/debug, https://www.score.mcpjam.com/oauth/callback, https://www.score.mcpjam.com/oauth/callback/debug
Last observed: 2026-08-12T23:12:03.443Z

Visual Studio Code

IDE

cimd
Observed result
Visual Studio Code authorization used client_id metadata URL https://vscode.dev/oauth/client-metadata.json.
Latest user agent
node
Latest event
POST /token
Client version
Unknown
Claimed status
unknown
Metadata name
Visual Studio Code
Observed behavior
cimd
Metadata URL
https://vscode.dev/oauth/client-metadata.json
Client URI
https://vscode.dev/product
Grant types
authorization_code, refresh_token, urn:ietf:params:oauth:grant-type:device_code
Response types
code
Token auth
none
App type
native
Redirect URIs
http://127.0.0.1:33418/, https://vscode.dev/redirect
Last observed: 2026-08-20T01:11:03.549Z

Bolt

Tool

dcr
Observed result
Bolt authorization used dynamically registered client_id dcr-bolt.
Latest user agent
Not observed
Latest event
POST /token
Client version
Unknown
Claimed status
unknown
Metadata name
Bolt
Observed behavior
dcr
Metadata URL
Unknown
Client URI
Not observed
Grant types
Not observed
Response types
Not observed
Token auth
Not observed
App type
Not observed
Redirect URIs
Not observed
Last observed: 2026-09-01T20:31:33.690Z

Builder

Tool

dcr
Observed result
Builder authorization used dynamically registered client_id dcr-builder.
Latest user agent
node
Latest event
POST /token
Client version
Unknown
Claimed status
unknown
Metadata name
Builder
Observed behavior
dcr
Metadata URL
Unknown
Client URI
Not observed
Grant types
Not observed
Response types
Not observed
Token auth
Not observed
App type
Not observed
Redirect URIs
Not observed
Last observed: 2026-09-01T20:42:28.372Z

cimd-reader3

Connector · Vercel Connect

cimd
Observed result
cimd-reader3 is a Vercel-hosted connector; authorization used per-connector client_id metadata URL https://connect.vercel.com/connectors/scl_Dni2tm1ap6Mekk7ffF6BZg.
Latest user agent
Vercel-Connex/1.0 (+https://openapi.vercel.sh/; marketplace@vercel.com)
Latest event
POST /token
Client version
1.0
Claimed status
unknown
Metadata name
cimd-reader3
Observed behavior
cimd
Host platform
Vercel Connect · Per-connector OAuth client
Metadata URL
https://connect.vercel.com/connectors/scl_Dni2tm1ap6Mekk7ffF6BZg
Client URI
Not observed
Grant types
authorization_code, refresh_token
Response types
Not observed
Token auth
none
App type
Not observed
Redirect URIs
https://connect.vercel.com/callback
Last observed: 2026-08-24T22:08:34.313Z

Devin CLI

CLI

dcr
Observed result
Devin CLI (8.7.1) authorization used dynamically registered client_id dcr-devin-cli.
Latest user agent
curl/8.7.1
Latest event
GET /authorize
Client version
8.7.1
Claimed status
unknown
Metadata name
Devin CLI
Observed behavior
dcr
Metadata URL
Unknown
Client URI
Not observed
Grant types
Not observed
Response types
Not observed
Token auth
Not observed
App type
Not observed
Redirect URIs
Not observed
Last observed: 2026-08-20T03:49:50.701Z

InvestigateAI

Tool

cimd
Observed result
InvestigateAI authorization used client_id metadata URL https://bendable-voltametric-lyndsay.ngrok-free.dev/oauth/client-metadata.json.
Latest user agent
python-httpx2/2.13.0
Latest event
POST /token
Client version
2.13.0
Claimed status
unknown
Metadata name
InvestigateAI
Observed behavior
cimd
Metadata URL
https://bendable-voltametric-lyndsay.ngrok-free.dev/oauth/client-metadata.json
Client URI
https://bendable-voltametric-lyndsay.ngrok-free.dev
Grant types
authorization_code, refresh_token
Response types
code
Token auth
none
App type
Not observed
Redirect URIs
https://bendable-voltametric-lyndsay.ngrok-free.dev/oauth/callback
Last observed: 2026-10-02T09:42:51.874Z

Lovable

Tool

cimd
Observed result
Lovable authorization used client_id metadata URL https://api.lovable.dev/.well-known/oauth-client.
Latest user agent
Go-http-client/2.0
Latest event
POST /token
Client version
2.0
Claimed status
unknown
Metadata name
Lovable
Observed behavior
cimd
Metadata URL
https://api.lovable.dev/.well-known/oauth-client
Client URI
https://lovable.dev
Grant types
authorization_code, refresh_token
Response types
code
Token auth
none
App type
Not observed
Redirect URIs
https://api.lovable.dev/workspaces/connectors/mcp/oauth/callback
Last observed: 2026-08-19T19:46:52.652Z

mcp-use Inspector

Tool

dcr
Observed result
mcp-use Inspector authorization used dynamically registered client_id dcr-mcp-use-inspector.
Latest user agent
node
Latest event
POST /token
Client version
Unknown
Claimed status
unknown
Metadata name
mcp-use Inspector
Observed behavior
dcr
Metadata URL
Unknown
Client URI
Not observed
Grant types
Not observed
Response types
Not observed
Token auth
Not observed
App type
Not observed
Redirect URIs
Not observed
Last observed: 2026-09-21T13:00:59.267Z

Replit MCP Connector

Tool

dcr
Observed result
Replit MCP Connector authorization used dynamically registered client_id dcr-replit-mcp-connector.
Latest user agent
node
Latest event
POST /token
Client version
Unknown
Claimed status
unknown
Metadata name
Replit MCP Connector
Observed behavior
dcr
Metadata URL
Unknown
Client URI
Not observed
Grant types
Not observed
Response types
Not observed
Token auth
Not observed
App type
Not observed
Redirect URIs
Not observed
Last observed: 2026-09-01T20:38:44.369Z

Stella

Tool

cimd
Observed result
Stella authorization used client_id metadata URL https://stella.maz.ix.is/.well-known/oauth-client.
Latest user agent
node
Latest event
POST /token
Client version
Unknown
Claimed status
unknown
Metadata name
Stella
Observed behavior
cimd
Metadata URL
https://stella.maz.ix.is/.well-known/oauth-client
Client URI
https://stella.maz.ix.is
Grant types
authorization_code, refresh_token
Response types
code
Token auth
none
App type
Not observed
Redirect URIs
https://stella.maz.ix.is/mcp/oauth/callback
Last observed: 2026-09-06T19:55:06.533Z

v0

Tool

cimd
Observed result
v0 authorization used client_id metadata URL https://v0.app/api/chat/integrations/oauth/client-metadata.json.
Latest user agent
arctic
Latest event
POST /token
Client version
Unknown
Claimed status
unknown
Metadata name
v0
Observed behavior
cimd
Metadata URL
https://v0.app/api/chat/integrations/oauth/client-metadata.json
Client URI
https://v0.app
Grant types
authorization_code, refresh_token
Response types
code
Token auth
none
App type
Not observed
Redirect URIs
https://v0.app/api/chat/integrations/oauth/callback, https://api.v0.dev/v1/mcp-servers/oauth/callback
Last observed: 2026-09-17T16:39:30.134Z