Client ID Metadata Document Support for OAuth Clients
- Services: IAM
- Release Date: September 23, 2026
IAM with identity domains now supports Client ID Metadata Documents (CIMD). An OAuth client can publish its metadata at a stable HTTPS URL and use that URL as its client_id, reducing the need to maintain a persistent client registration in every identity domain.
This enhancement provides the following capabilities:
- Authorization server metadata advertises CIMD support, enabling discovery by AI agents, Model Context Protocol (MCP) clients, developer tools, desktop applications, and other OAuth clients.
- Public clients can use the authorization code flow with Proof Key for Code Exchange (PKCE), including refresh token support and approved loopback redirect URIs with dynamically selected ports.
- Confidential clients can use the client credentials grant with
private_key_jwtauthentication and public keys published through a JSON Web Key Set (JWKS) endpoint. - The same client metadata URL can be used across multiple identity domains. Each identity domain controls trusted metadata locations, and each protected resource application separately controls which CIMD clients can access it.
- Metadata and key retrieval include HTTPS and URL validation, DNS and network destination protection, redirect restrictions, bounded retrieval and caching, and fail-closed response handling.
For more information, see Client ID Metadata Documents.