Skip to content

docs(mcp): correct PROD client_id to the shared IAS client (not retired XSUAA id) - #2700

Merged
jung-thomas merged 1 commit into
DEVfrom
worktree-mcp-quickstart-clientid-doc
Oct 8, 2026
Merged

jung-thomas merged 1 commit into
DEVfrom
worktree-mcp-quickstart-clientid-doc

Conversation

@jung-thomas

Copy link
Copy Markdown
Contributor

What

Fixes the MCP quickstart: PROD users were told to use the XSUAA client_id sb-tutorials-prod!t676072, which fails live on PROD.

Why it failed

Since MCP_ISSUER_KIND: ias landed in both mtaexts (#2593, 2026-10-04), PROD discovery advertises IAS. IAS rejects an XSUAA sb-… id at the authorize endpoint — "client_id … must match the configuration" — before PKCE is even evaluated (confirmed live 2026-10-08: that's why the error wasn't a PKCE error).

DEV and PROD share one IAS tenant (atxgsg7zi) and one tutorials-identity app, both approuter hosts registered as redirect URIs → a single client UUID 0b1e8b56-5f5d-4ebf-a9e9-28aae2964236 for both envs. The XSUAA ids are retired relics.

Changes (doc only)

  • Both mcp-remote JSON snippets → the IAS UUID
  • Env table: both PROD + DEV rows → the IAS UUID (same id)
  • Prose: IAS public client, XSUAA ids retired + why, how to re-read the UUID from the IAS console

Verified connect (PROD)

npx mcp-remote https://developers.sap.com/mcp-auth/api --static-oauth-client-info '{"client_id":"0b1e8b56-5f5d-4ebf-a9e9-28aae2964236"}'

…ed XSUAA id)

The quickstart told PROD users to connect with the XSUAA client_id
sb-tutorials-prod!t676072, but since MCP_ISSUER_KIND:ias landed in both mtaexts
(#2593, 2026-10-04) PROD discovery advertises IAS — and IAS rejects an XSUAA
sb-... id at the authorize endpoint ("client_id must match the configuration")
before PKCE is even evaluated. Live PROD failure confirmed 2026-10-08.

DEV and PROD share ONE IAS tenant (atxgsg7zi) and ONE tutorials-identity app,
with both approuter hosts registered as redirect URIs, so there is a SINGLE
client UUID for both: 0b1e8b56-5f5d-4ebf-a9e9-28aae2964236.

Updates: the two mcp-remote JSON snippets, the env table (both rows → the IAS
UUID), and the explanatory prose (IAS public client, XSUAA ids retired, how to
re-read the UUID from the IAS console). No code change.
@jung-thomas
jung-thomas marked this pull request as ready for review October 8, 2026 22:24
@jung-thomas
jung-thomas merged commit b27634c into DEV Oct 8, 2026
4 checks passed
@jung-thomas
jung-thomas deleted the worktree-mcp-quickstart-clientid-doc branch October 8, 2026 22:24
jung-thomas added a commit that referenced this pull request Oct 9, 2026
Resolves the 1.37.0 vs 1.37.1 overlap on the two release-managed files:
- .deploy/mta.yaml: keep 1.37.1 (supersedes main's 1.37.0 bump).
- hugo/data/whats_new.json: keep the 757-entry digest, which already
  incorporates main's 752-entry 1.37.0 digest (rebased onto it) plus the
  4 new 1.37.1 PRs (#2700/#2701/#2704/#2705). Verified superset: all
  1.37.0 entries retained, 4 new entries added, no duplicates.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant