Skip to content

Client ID Metadata Document

Client ID Metadata Document (CIMD).

A Client ID Metadata Document (CIMD) is a JSON file at an HTTPS URL that serves as an OAuth client's client_id, letting an authorization server learn who the client software is without prior registration.

CIMD answers the question "which piece of software is this?" for clients an authorization server has never met. That is the normal case for AI agents and MCP clients, which may connect to thousands of servers. Pre-registration does not scale there, and Dynamic Client Registration creates a client record per connection with no stable identity behind it. A CIMD URL is stable, domain-bound, and inspectable.

CIMD also feeds the enterprise side of agent access. Per WorkOS, the client_id inside an ID-JAG is a CIMD identifier. That pairing is what enterprise-managed authorization means: CIMD says who the agent software is, and the customer's IdP decides what it may reach.

For implementation detail and the MCP angle, read Client ID Metadata Documents (CIMD): the future of MCP authentication. The MCP server identity model guide covers the surrounding authorization requirements.

Common questions

What is a Client ID Metadata Document?

It is a JSON metadata file hosted at an HTTPS URL, where the URL itself is the OAuth client_id. An authorization server that has never seen the client fetches the URL to learn the client's name, redirect URIs, and public keys, so no registration step is needed.

How is CIMD different from Dynamic Client Registration?

Dynamic Client Registration (RFC 7591) has the client POST its metadata to the server, which then stores a new client record. CIMD has the client publish its metadata at a URL it controls, and the server fetches it. CIMD avoids an unbounded pile of registered clients and ties the client's identity to a domain.

Does MCP require CIMD?

The MCP authorization specification dated 2025-11-25 says authorization servers and clients SHOULD support CIMD. Clients try a pre-registered client first, then CIMD if the server's metadata sets client_id_metadata_document_supported to true, then Dynamic Client Registration, then prompting the user.

What are the security risks of CIMD?

The server fetches a URL the client chose, so SSRF is the main risk; the draft forbids fetching special-use IP addresses. Phishing is another, so the server should display the client_id hostname. The MCP spec also warns about localhost redirect impersonation and says servers SHOULD warn on localhost-only redirect URIs.

Related terms

In the guides

Last updated 2026-10-05.