MCP OAuth diagnostics
Observed MCP OAuth client behavior
See whether IDEs and developer tools use CIMD, fall back to Dynamic Client Registration, or send static client IDs during OAuth.
Built by @AkxenTechAuthorization server:
/.well-known/oauth-authorization-serverTest endpoint
Add this Streamable HTTP MCP server URL to the client you want to test.
https://cimd-reader.akxen.tech/mcpCodex CLI
codex mcp add cimd_reader \ --url https://cimd-reader.akxen.tech/mcp \ --oauth-resource https://cimd-reader.akxen.tech/mcp codex mcp login cimd_reader
Claude Code
claude mcp add --transport http \ cimd_reader \ https://cimd-reader.akxen.tech/mcp # then run /mcp in Claude Code
VS Code
{
"servers": {
"cimd_reader": {
"type": "http",
"url": "https://cimd-reader.akxen.tech/mcp",
"oauth": {
"clientId": "https://vscode.dev/oauth/client-metadata.json"
}
}
}
}Claude Code
CLI
- Observed result
- Claude Code authorization used client_id metadata URL https://claude.ai/oauth/claude-code-client-metadata.
- Latest user agent
- Bun/1.4.0
- Latest event
- POST /token
- Client version
- 1.4.0
- Claimed status
- verified
- Metadata name
- Claude Code
- Observed behavior
- cimd
- Metadata URL
- https://claude.ai/oauth/claude-code-client-metadata
- Client URI
- https://claude.ai
- Grant types
- authorization_code, refresh_token
- Response types
- code
- Token auth
- none
- App type
- Not observed
- Redirect URIs
- http://localhost/callback, http://127.0.0.1/callback
Last observed: 2026-08-12T23:28:29.839Z

Codex CLI
CLI
- Observed result
- Codex authorization used client_id metadata URL https://chatgpt.com/oauth/codex/52-p_8rf-z-0/client.json.
- Latest user agent
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/154.0.0.0 Safari/537.36
- Latest event
- GET /authorize
- Client version
- Unknown
- Claimed status
- unknown
- Metadata name
- Codex
- Observed behavior
- cimd
- Metadata URL
- https://chatgpt.com/oauth/codex/52-p_8rf-z-0/client.json
- Client URI
- https://chatgpt.com/codex
- Grant types
- authorization_code, refresh_token
- Response types
- code
- Token auth
- none
- App type
- native
- Redirect URIs
- http://127.0.0.1/callback/52-p_8rf-z-0, http://localhost/callback/52-p_8rf-z-0
Last observed: 2026-09-30T04:46:09.080Z
Cursor
IDE
- Observed result
- Cursor authorization used dynamically registered client_id dcr-cursor.
- Latest user agent
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Cursor/3.15.19 Chrome/144.0.7559.236 Electron/40.10.3 Safari/537.36
- Latest event
- POST /token
- Client version
- 3.15.19
- Claimed status
- unknown
- Metadata name
- Cursor
- Observed behavior
- dcr
- Metadata URL
- Unknown
- Client URI
- Not observed
- Grant types
- Not observed
- Response types
- Not observed
- Token auth
- Not observed
- App type
- Not observed
- Redirect URIs
- Not observed
Last observed: 2026-08-12T23:36:57.927Z

MCPJam
Debugger
- Observed result
- MCPJam authorization used client_id metadata URL https://www.mcpjam.com/.well-known/oauth/client-metadata.json.
- Latest user agent
- MCP-Inspector/1.0
- Latest event
- POST /token
- Client version
- 1.0
- Claimed status
- unknown
- Metadata name
- MCPJam
- Observed behavior
- cimd
- Metadata URL
- https://www.mcpjam.com/.well-known/oauth/client-metadata.json
- Client URI
- https://www.mcpjam.com
- Grant types
- authorization_code, refresh_token, urn:ietf:params:oauth:grant-type:device_code
- Response types
- code
- Token auth
- none
- App type
- native
- Redirect URIs
- http://127.0.0.1:6274/oauth/callback, http://127.0.0.1:6274/callback, http://127.0.0.1:6274/oauth/callback/debug, http://localhost:6274/oauth/callback, http://localhost:6274/callback, http://localhost:6274/oauth/callback/debug, http://127.0.0.1:5173/oauth/callback, http://127.0.0.1:5173/oauth/callback/debug, http://localhost:5173/oauth/callback, http://localhost:5173/oauth/callback/debug, https://app.mcpjam.com/oauth/callback, https://app.mcpjam.com/oauth/callback/debug, https://staging.mcpjam.com/oauth/callback, https://staging.mcpjam.com/oauth/callback/debug, https://score.mcpjam.com/oauth/callback, https://score.mcpjam.com/oauth/callback/debug, https://www.score.mcpjam.com/oauth/callback, https://www.score.mcpjam.com/oauth/callback/debug
Last observed: 2026-08-12T23:12:03.443Z

Visual Studio Code
IDE
- Observed result
- Visual Studio Code authorization used client_id metadata URL https://vscode.dev/oauth/client-metadata.json.
- Latest user agent
- node
- Latest event
- POST /token
- Client version
- Unknown
- Claimed status
- unknown
- Metadata name
- Visual Studio Code
- Observed behavior
- cimd
- Metadata URL
- https://vscode.dev/oauth/client-metadata.json
- Client URI
- https://vscode.dev/product
- Grant types
- authorization_code, refresh_token, urn:ietf:params:oauth:grant-type:device_code
- Response types
- code
- Token auth
- none
- App type
- native
- Redirect URIs
- http://127.0.0.1:33418/, https://vscode.dev/redirect
Last observed: 2026-08-20T01:11:03.549Z
Bolt
Tool
- Observed result
- Bolt authorization used dynamically registered client_id dcr-bolt.
- Latest user agent
- Not observed
- Latest event
- POST /token
- Client version
- Unknown
- Claimed status
- unknown
- Metadata name
- Bolt
- Observed behavior
- dcr
- Metadata URL
- Unknown
- Client URI
- Not observed
- Grant types
- Not observed
- Response types
- Not observed
- Token auth
- Not observed
- App type
- Not observed
- Redirect URIs
- Not observed
Last observed: 2026-09-01T20:31:33.690Z
Builder
Tool
- Observed result
- Builder authorization used dynamically registered client_id dcr-builder.
- Latest user agent
- node
- Latest event
- POST /token
- Client version
- Unknown
- Claimed status
- unknown
- Metadata name
- Builder
- Observed behavior
- dcr
- Metadata URL
- Unknown
- Client URI
- Not observed
- Grant types
- Not observed
- Response types
- Not observed
- Token auth
- Not observed
- App type
- Not observed
- Redirect URIs
- Not observed
Last observed: 2026-09-01T20:42:28.372Z
cimd-reader3
Connector · Vercel Connect
- Observed result
- cimd-reader3 is a Vercel-hosted connector; authorization used per-connector client_id metadata URL https://connect.vercel.com/connectors/scl_Dni2tm1ap6Mekk7ffF6BZg.
- Latest user agent
- Vercel-Connex/1.0 (+https://openapi.vercel.sh/; marketplace@vercel.com)
- Latest event
- POST /token
- Client version
- 1.0
- Claimed status
- unknown
- Metadata name
- cimd-reader3
- Observed behavior
- cimd
- Host platform
- Vercel Connect · Per-connector OAuth client
- Metadata URL
- https://connect.vercel.com/connectors/scl_Dni2tm1ap6Mekk7ffF6BZg
- Client URI
- Not observed
- Grant types
- authorization_code, refresh_token
- Response types
- Not observed
- Token auth
- none
- App type
- Not observed
- Redirect URIs
- https://connect.vercel.com/callback
Last observed: 2026-08-24T22:08:34.313Z
Devin CLI
CLI
- Observed result
- Devin CLI (8.7.1) authorization used dynamically registered client_id dcr-devin-cli.
- Latest user agent
- curl/8.7.1
- Latest event
- GET /authorize
- Client version
- 8.7.1
- Claimed status
- unknown
- Metadata name
- Devin CLI
- Observed behavior
- dcr
- Metadata URL
- Unknown
- Client URI
- Not observed
- Grant types
- Not observed
- Response types
- Not observed
- Token auth
- Not observed
- App type
- Not observed
- Redirect URIs
- Not observed
Last observed: 2026-08-20T03:49:50.701Z
InvestigateAI
Tool
- Observed result
- InvestigateAI authorization used client_id metadata URL https://bendable-voltametric-lyndsay.ngrok-free.dev/oauth/client-metadata.json.
- Latest user agent
- python-httpx2/2.13.0
- Latest event
- POST /token
- Client version
- 2.13.0
- Claimed status
- unknown
- Metadata name
- InvestigateAI
- Observed behavior
- cimd
- Metadata URL
- https://bendable-voltametric-lyndsay.ngrok-free.dev/oauth/client-metadata.json
- Client URI
- https://bendable-voltametric-lyndsay.ngrok-free.dev
- Grant types
- authorization_code, refresh_token
- Response types
- code
- Token auth
- none
- App type
- Not observed
- Redirect URIs
- https://bendable-voltametric-lyndsay.ngrok-free.dev/oauth/callback
Last observed: 2026-10-02T09:42:51.874Z
Lovable
Tool
- Observed result
- Lovable authorization used client_id metadata URL https://api.lovable.dev/.well-known/oauth-client.
- Latest user agent
- Go-http-client/2.0
- Latest event
- POST /token
- Client version
- 2.0
- Claimed status
- unknown
- Metadata name
- Lovable
- Observed behavior
- cimd
- Metadata URL
- https://api.lovable.dev/.well-known/oauth-client
- Client URI
- https://lovable.dev
- Grant types
- authorization_code, refresh_token
- Response types
- code
- Token auth
- none
- App type
- Not observed
- Redirect URIs
- https://api.lovable.dev/workspaces/connectors/mcp/oauth/callback
Last observed: 2026-08-19T19:46:52.652Z
mcp-use Inspector
Tool
- Observed result
- mcp-use Inspector authorization used dynamically registered client_id dcr-mcp-use-inspector.
- Latest user agent
- node
- Latest event
- POST /token
- Client version
- Unknown
- Claimed status
- unknown
- Metadata name
- mcp-use Inspector
- Observed behavior
- dcr
- Metadata URL
- Unknown
- Client URI
- Not observed
- Grant types
- Not observed
- Response types
- Not observed
- Token auth
- Not observed
- App type
- Not observed
- Redirect URIs
- Not observed
Last observed: 2026-09-21T13:00:59.267Z
Replit MCP Connector
Tool
- Observed result
- Replit MCP Connector authorization used dynamically registered client_id dcr-replit-mcp-connector.
- Latest user agent
- node
- Latest event
- POST /token
- Client version
- Unknown
- Claimed status
- unknown
- Metadata name
- Replit MCP Connector
- Observed behavior
- dcr
- Metadata URL
- Unknown
- Client URI
- Not observed
- Grant types
- Not observed
- Response types
- Not observed
- Token auth
- Not observed
- App type
- Not observed
- Redirect URIs
- Not observed
Last observed: 2026-09-01T20:38:44.369Z
Stella
Tool
- Observed result
- Stella authorization used client_id metadata URL https://stella.maz.ix.is/.well-known/oauth-client.
- Latest user agent
- node
- Latest event
- POST /token
- Client version
- Unknown
- Claimed status
- unknown
- Metadata name
- Stella
- Observed behavior
- cimd
- Metadata URL
- https://stella.maz.ix.is/.well-known/oauth-client
- Client URI
- https://stella.maz.ix.is
- Grant types
- authorization_code, refresh_token
- Response types
- code
- Token auth
- none
- App type
- Not observed
- Redirect URIs
- https://stella.maz.ix.is/mcp/oauth/callback
Last observed: 2026-09-06T19:55:06.533Z
v0
Tool
- Observed result
- v0 authorization used client_id metadata URL https://v0.app/api/chat/integrations/oauth/client-metadata.json.
- Latest user agent
- arctic
- Latest event
- POST /token
- Client version
- Unknown
- Claimed status
- unknown
- Metadata name
- v0
- Observed behavior
- cimd
- Metadata URL
- https://v0.app/api/chat/integrations/oauth/client-metadata.json
- Client URI
- https://v0.app
- Grant types
- authorization_code, refresh_token
- Response types
- code
- Token auth
- none
- App type
- Not observed
- Redirect URIs
- https://v0.app/api/chat/integrations/oauth/callback, https://api.v0.dev/v1/mcp-servers/oauth/callback
Last observed: 2026-09-17T16:39:30.134Z