Loading live status…
Loading live status…
Between July and September 2026, Clerk shipped the pieces an MCP server needs to let AI agents sign in: Client ID Metadata Documents, custom OAuth scopes, a device authorization flow and a one-command MCP installer. What each one does and why it matters.
When Clerk raised a $50 million Series C in October 2025, led by Menlo Ventures and Anthropic's Anthology Fund, it said the money would build a new product line around agent identity. In its announcement, Clerk wrote that "agents need a new authentication solution: one that lets them act on behalf of humans with fine-grained permissions."
Eleven months later, that work is now in the product. Between late July and late September 2026, Clerk shipped a run of OAuth features. Most are aimed at one use case: letting an AI client, such as Claude, Cursor or a coding agent, connect to your MCP server and act as a signed-in user.
Here is what shipped, in order, and what it means. For the rest of Clerk's recent releases, see What's new at Clerk: August–September 2026.
| Date | Release | What it solves |
|---|---|---|
| 22 Jul | clerk mcp install |
Connect Clerk's own MCP server to ten AI clients |
| 22 Jul | Configurable default OAuth scopes for Dynamic Client Registration | Sensible scopes for clients that register themselves |
| 6 Aug | Client ID Metadata Documents (beta) | Clients that were never registered in advance |
| 21 Aug | Custom OAuth scopes | Permissions that match your API |
| 8 Sep | OAuth Device Authorization Grant | Sign-in for CLIs and devices without a browser |
| 21 Sep | Client ID Metadata Documents GA | The above, out of beta |
The hard part of OAuth for MCP is that your server does not know the client ahead of time. Traditional OAuth expects every app to be registered first and given a client ID and secret. That works for a handful of partners. It does not work when any user can point any AI tool at your server.
Client ID Metadata Documents (CIMD) fix this by making the client ID an HTTPS URL. The client publishes a small metadata document at that URL, and Clerk reads it to check the client's details and allowed redirect URIs. Clerk says this gives MCP and other public OAuth clients "a stable identity without a pre-issued client ID, client secret, or Dynamic Client Registration."
CIMD entered beta on 6 August and became generally available on 21 September. Clerk says it is now available in every application, but it stays off until you turn it on:
The third step is the important one. With open admission, any client that publishes valid metadata can start an OAuth flow. Your users still have to consent, but you have not approved the client in advance.
Before 21 August, scopes were mostly about identity: profile, email and so on. Custom OAuth scopes let you define names that match your API, with Clerk's examples being messages:read, tools:execute, resources/files:read and mcp_all. You choose which scopes each OAuth application may request and which ones appear in your OAuth metadata.
Clerk is explicit about one thing: your API has to enforce them. Clerk issues a token that lists the granted scopes, and your server must verify the token and check the scopes before it runs a tool. If you skip that step, a messages:read token can do anything.
On 8 September Clerk added the OAuth Device Authorization Grant (RFC 8628). This is the familiar "go to this URL and enter this code" flow. The device or CLI shows a short code, the user approves it in a browser on another device, and the client polls until it gets a token. Clerk's Account Portal shows the approval screen, including the app, the requested permissions and, if needed, which organization to use. Approve and deny buttons get equal weight on that screen.
It works with both public clients (client ID only) and confidential ones (ID and secret). It does not need PKCE or redirect URIs. For agents this matters because many run in a terminal or on a server with no browser of their own.
The 22 July release is aimed at developers who use Clerk rather than their end users. clerk mcp install detects which AI clients are on your machine and registers Clerk's MCP server in them. Clerk lists ten: Claude Code, Cursor, GitHub Copilot (VS Code), Windsurf, Gemini CLI, Codex, opencode, OpenClaw, Warp and Hermes Agent. It uses a stdio-to-HTTP bridge built into the CLI instead of npx mcp-remote, and a new clerk doctor command checks the connection. This builds on the Clerk CLI that launched in April.
If your agents suddenly can't authenticate, check Clerk's live status first. If your MCP server also runs on a platform we monitor, such as Vercel or Cloudflare, check that too before you start debugging your own code.
Sources
Checked continuously against each provider's own status feed.