Summary
For MCP OAuth with a symmetric key, symmetric_algorithm: HS512 does not reject a token signed with HS256 using the same key. The explicit algorithms: [HS512] workaround is rejected by the configuration schema for symmetric-key entries.
Reproduced with both official images:
ghcr.io/wundergraph/cosmo/router:0.335.0
ghcr.io/wundergraph/cosmo/router:0.347.1
Reproduction
On a working router with MCP enabled and its normal execution config/operations storage, configure:
mcp:
enabled: true
server:
listen_addr: '0.0.0.0:5025'
base_url: 'https://mcp.example.com'
oauth:
enabled: true
authorization_server_url: 'https://app.example.com'
jwks:
- secret: 'disposable-test-key-not-a-deployed-secret-123456789012345678901234567890'
symmetric_algorithm: 'HS512'
header_key_id: ''
audiences: ['https://mcp.example.com/mcp']
Keep the normal MCP storage configuration. Generate two JWTs with the same disposable secret and audience, a current expiration, and no kid; sign one with HS512 and the other with HS256. For each, POST /mcp with Authorization: Bearer <token>, Content-Type: application/json, Accept: application/json, text/event-stream, and:
{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"algorithm-repro","version":"1"}}}
Observed in isolated tests of both images:
| Token algorithm |
HTTP status |
| HS512 |
200 (successful initialize) |
| HS256 |
200 (successful initialize) |
An unauthenticated request returned 401, and an unrelated audience returned 401 in the 0.335.0 test, confirming that OAuth middleware was active.
Adding algorithms: [HS512] to the symmetric entry prevents startup: configuration validation reports oneOf failed because the symmetric-key branch forbids algorithms. Omitting header_key_id also prevents startup; an empty value accepts tokens without kid.
Relevant 0.347.1 source
Expected behavior and impact
Configuring HS512 should reject HS256. This is a defense-in-depth gap for symmetric deployments: the algorithm setting suggests a restriction that is not actually enforced. The reproduction still requires a correctly signed token with the configured secret; this report does not claim authentication bypass without that key.
Please enforce symmetric_algorithm as an algorithm allowlist, or permit the explicit algorithms field on symmetric entries. A regression test covering HS512 acceptance and HS256 rejection would pin the intended behavior.
Summary
For MCP OAuth with a symmetric key,
symmetric_algorithm: HS512does not reject a token signed with HS256 using the same key. The explicitalgorithms: [HS512]workaround is rejected by the configuration schema for symmetric-key entries.Reproduced with both official images:
ghcr.io/wundergraph/cosmo/router:0.335.0ghcr.io/wundergraph/cosmo/router:0.347.1Reproduction
On a working router with MCP enabled and its normal execution config/operations storage, configure:
Keep the normal MCP storage configuration. Generate two JWTs with the same disposable secret and audience, a current expiration, and no
kid; sign one with HS512 and the other with HS256. For each, POST/mcpwithAuthorization: Bearer <token>,Content-Type: application/json,Accept: application/json, text/event-stream, and:{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"algorithm-repro","version":"1"}}}Observed in isolated tests of both images:
An unauthenticated request returned 401, and an unrelated audience returned 401 in the 0.335.0 test, confirming that OAuth middleware was active.
Adding
algorithms: [HS512]to the symmetric entry prevents startup: configuration validation reportsoneOf failedbecause the symmetric-key branch forbidsalgorithms. Omittingheader_key_idalso prevents startup; an empty value accepts tokens withoutkid.Relevant 0.347.1 source
AllowedAlgorithmslist.secret,symmetric_algorithm, andheader_key_id, but forbidalgorithms.Expected behavior and impact
Configuring HS512 should reject HS256. This is a defense-in-depth gap for symmetric deployments: the algorithm setting suggests a restriction that is not actually enforced. The reproduction still requires a correctly signed token with the configured secret; this report does not claim authentication bypass without that key.
Please enforce
symmetric_algorithmas an algorithm allowlist, or permit the explicitalgorithmsfield on symmetric entries. A regression test covering HS512 acceptance and HS256 rejection would pin the intended behavior.