mcpbench GitHub

client/oauth-cimd-over-dcr

openai/gpt-5.6-sol:medium 2026-07-28 docs: full score 0% musts 7/7 · shoulds 0/1 · mays 0/0 works yes · conformant yes

Checkpoints

MUST (any failure zeroes the score — 7/7 passed)

Checkpoint Description
cimd-document-hosted If the CIMD path was taken, the AS fetched the hosted document successfully
cimd-document-shape If the CIMD path was taken, the document carried the required properties
cimd-client-id-match If the CIMD path was taken, the document's client_id matched its URL exactly
pkce S256 code_challenge on authorize; matching code_verifier at token
resource-indicator Included RFC 8707 resource=<canonical server URI> in both requests
bearer-token All post-grant accepted MCP requests carried Authorization: Bearer; the token never appeared in a URL
authorized-tool-call Successfully called get_secret_number once authorized

SHOULD (the score fraction — 0/1 passed)

Checkpoint Description Detail
cimd-preferred The exchanged authorization used a URL client_id, not a DCR-issued id the exchanged authorization's client_id "mcpbench-8180cff4820d276e" is not a URL with a path component

Usage & cost

Nominal cost
$0.800
Input tokens
78,639
Output tokens
4,258
Cache read
557,568
Duration
264s
Timestamp
2026-07-18 12:40:16Z
Bench version
0.3.0

Cost is nominal (public API pricing): token usage × published rates; actual marginal cost is subscription-covered.