Skip to content

RFC 7662 introspection drops custom claims needed by Cedar policies #6705

Description

@ngocketit

Bug description

When an opaque access token is validated through RFC 7662 introspection, ToolHive drops non-standard claims from the introspection response. Consequently, Cedar policies cannot reference claims such as roles, even though the introspection endpoint returns them.

Reproduction

Given an introspection response containing:

{
  "active": true,
  "sub": "user-123",
  "roles": ["admin"]
}

and a Cedar policy:

permit(
  principal,
  action == Action::"call_tool",
  resource == Tool::"example_admin-tool"
) when {
  principal has claim_roles &&
  principal.claim_roles.contains("admin")
};

the tool is excluded from tools/list.

The gateway logs show:

Client::"user-123" does not have the attribute claim_roles

Expected behavior

Custom fields returned by a successful RFC 7662 introspection response should be exposed to Cedar using the existing claim_ prefix, consistent with claims obtained from JWT access tokens.

In this example, roles should become principal.claim_roles

Actual behavior

Only the explicitly modeled fields survive introspection:

exp
sub
aud
scope
iss

All other fields are discarded.

Environment (if relevant)

  • ToolHive version: vmcp:v0.49.0

Suggested direction

Decode the introspection response into a generic map, or implement custom unmarshalling, so extension fields are retained alongside the standard RFC 7662 fields.

This would make Cedar claim behavior consistent between JWT and introspected opaque access tokens.

Activity

  1. jstar0 commented on Sep 23, 2026

    @jstar0
    Contributor

    I'd like to work on this.

  2. added a commit that references this issue on Sep 29, 2026
    f450a82
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingneeds-triageIssue needs initial triage by a maintainer

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions