Cached MCP OAuth details are rechecked against policy, so moved servers no longer authenticate stale.
What's wrong with this entry?
Cached OAuth discovery details for MCP servers are now re-checked against policy before reuse and kept only for a fixed window. If the cached authorization server fails the check, stored credentials are invalidated and the cached entry is cleared instead of being reused, so a server that has moved or been disallowed no longer silently authenticates against a stale endpoint.
Returning cached discovery state (authServer:
Strings lifted out of the shipped bundle, so the claim above can be checked against them.