Skip to main content

Controlled Test Matrix

The omitted-authorization claim needs a clean A/B test using unique names, manifest IDs, and Personal titles.

VariableA: documented omissionB: explicit Toolkit registration
mcpServerUrlSame v2 URLSame v2 URL
Tool descriptionSame fileSame file
Manifest authorizationOmittedOAuthPluginVault plus generated reference
Lifecycle DCR actionAbsentPresent
App ID and display nameUnique A valuesUnique B values
ScopePersonalPersonal

Evidence checkpoints

StageTestPassing evidence
Resource challengeUnauthenticated MCP request401 with resource_metadata
Resource metadataFetch RFC 9728 URLExact resource and issuer
Authorization metadataFetch discovered RFC 8414 URLRegistration endpoint and S256
RegistrationObserve registration endpointPOST and 201, with secrets redacted
Vault bindingStart ConnectCorrect title and auth-config ID
AuthorizationInspect generated URLDynamic client ID, state, PKCE, callback
ConsentAccept at AtlassianCallback code and matching state
Token exchangeComplete Cowork-owned callbackSuccessful token response, redacted
MCP accessRun read-only toolExpected Jira site returned
RefreshWait through expiryRefresh grant and successful MCP retry

Controls

  • Remove all previous test titles before starting.
  • Wait for catalog uninstall propagation.
  • Use a fresh browser profile for each variant.
  • Capture network traces with secrets redacted.
  • Do not infer registration from a consent screen alone.
  • Repeat each variant at least twice to distinguish caching from deterministic behavior.

Until this matrix is completed, the repository records the omission path as not working in the original reproduction, not as universally unsupported.