Patch Changes
- c30f279: Verify OAuth JWT access tokens from the authorization server (Clerk) strictly on the hosted HTTP transport: signature, issuer, a
typofat+jwt, expiry with a minute of clock tolerance, and the token'saud. Clerk ID tokens and session JWTs, which share the issuer, now get HTTP 401. The audience is compared against theRESOURCE_URLorigin,/mcpand/mcp/oauth(override withMCP_OAUTH_ALLOWED_AUDIENCES);MCP_OAUTH_AUDIENCE_ENFORCEMENTdefaults toobserve, which admits a mismatch and logs the OAuth client ID and audience (once per token every ten minutes), andrequiredanswers 401. These JWTs count asoauthin authentication telemetry, a token the Context7 API rejects on a tool call is challenged on the next request, and a rejected OAuth token now stays rejected in the per-replica cache for ten minutes instead of thirty seconds. - dd48abc: query-docs now sets
isErroron its result when the documentation request fails (invalid library ID, API or network error), so clients that branch onisErrorno longer treat the error text as documentation. - 6116042: Report the actual assigned HTTP port when
--port 0requests an ephemeral port.