mcpbench GitHub

client/oauth-cimd-over-dcr

moonshotai/kimi-k2.7-code 2026-07-28 docs: none score 0% turn-cap musts 3/7 · shoulds 0/1 · mays 0/0 works no · conformant no

Checkpoints

MUST (any failure zeroes the score — 3/7 passed)

Checkpoint Description Detail
cimd-document-hosted If the CIMD path was taken, the AS fetched the hosted document successfully
cimd-document-shape If the CIMD path was taken, the document carried the required properties
cimd-client-id-match If the CIMD path was taken, the document's client_id matched its URL exactly
pkce S256 code_challenge on authorize; matching code_verifier at token no successful token request recorded
resource-indicator Included RFC 8707 resource=<canonical server URI> in both requests authorization request missing resource indicator (RFC 8707)
bearer-token All post-grant accepted MCP requests carried Authorization: Bearer; the token never appeared in a URL Bearer-authenticated MCP requests never succeeded
authorized-tool-call Successfully called get_secret_number once authorized tools/call for "get_secret_number" was never sent

SHOULD (the score fraction — 0/1 passed)

Checkpoint Description Detail
cimd-preferred The exchanged authorization used a URL client_id, not a DCR-issued id client never hit the authorization endpoint

Usage & cost

Nominal cost
$0.550
Input tokens
14,587
Output tokens
42,744
Cache read
2,895,744
Duration
969s
Timestamp
2026-07-18 17:54:04Z
Bench version
0.3.0

Cost is nominal (public API pricing): token usage × published rates; actual marginal cost is subscription-covered.