OAuth Client ID Metadata Documents (CIMD)
OAuth Client ID Metadata Documents (CIMD) let an OAuth client use an HTTPS URL as its
client_id. The URL points to a document that describes the client, including information
such as its redirect URIs and authentication method.
When the client connects, Qlik Cloud retrieves the metadata document. A tenant administrator must approve the client through the OAuth consent form before it can be used on the tenant.
CIMD is defined by the IETF OAuth Client ID Metadata Document Internet-Draft.
The CIMD specification is still an Internet-Draft and hasn’t been finalized as an RFC. The specification may change as the draft evolves.
When to use CIMD
Use CIMD when an OAuth client application supports CIMD and publishes a client ID metadata document.
For Model Context Protocol (MCP) integrations that support both CIMD and Dynamic Client Registration (DCR), use CIMD.
Unlike DCR, CIMD doesn’t require DCR to be enabled on the tenant.
For applications that don’t support CIMD, use another OAuth registration method.
CIMD doesn’t support the client_credentials grant type. For machine-to-machine
authentication, use an M2M OAuth client
instead.
Prerequisites
To connect using CIMD:
- The OAuth client must support CIMD.
- The client must publish its metadata document at the HTTPS URL used as its
client_id. - The metadata document must conform to the OAuth Client ID Metadata Document specification.
- A tenant administrator must approve the client the first time it connects to a tenant.
How CIMD works with Qlik Cloud
A CIMD connection is initiated from the OAuth client application. A tenant administrator doesn’t create a CIMD client manually from the Qlik Cloud Administration activity center. Instead, the administrator approves the client for the tenant when it first connects.
When a client connects:
- The client starts the OAuth authorization flow using its client metadata document URL as
the
client_id. - Qlik Cloud retrieves and validates the metadata document.
- The tenant administrator authenticates and approves the client.
- Qlik Cloud creates the OAuth client connection for the tenant.
After approval, the client appears on the OAuth page in the Administration activity center with CIMD as its source.
Other users on the tenant can then authorize access through the approved client when their application uses the same CIMD document URL. Each user authenticates with their own Qlik Cloud account and permissions.
Client type
Qlik Cloud determines the OAuth client type from the token endpoint authentication method specified in the client metadata document.
| Token endpoint authentication method | OAuth client type |
|---|---|
private_key_jwt | Web (confidential) |
none | Native (public) |
Default scopes
For Qlik MCP Server connections using CIMD, the following scopes are selected by default:
user_defaultmcp:executeoffline_access
A tenant administrator can add or remove OAuth scopes after the client is approved.
Discover CIMD support
Qlik Cloud advertises its OAuth capabilities in the authorization server metadata document.
The document includes:
{ "client_id_metadata_document_supported": true}The authorization server metadata is available at:
https://<tenant-hostname>/.well-known/oauth-authorization-serverOAuth clients that support CIMD publish their client metadata at the URL they use
as their client_id. Qlik Cloud retrieves this document to determine the client’s
metadata and OAuth configuration.
For example:
- Claude:
https://claude.ai/oauth/mcp-oauth-client-metadata - Claude Code:
https://claude.ai/oauth/claude-code-client-metadata - ChatGPT:
https://chatgpt.com/oauth/client.json
OAuth clients can use the Qlik Cloud authorization server metadata to discover supported OAuth capabilities, including CIMD and token endpoint authentication methods.
Manage CIMD clients
A tenant administrator can manage an approved CIMD client from the OAuth page in the Administration activity center.
They can:
- Add or remove OAuth scopes assigned to the client.
- Remove the CIMD connection from the tenant.
Properties supplied by the client metadata document can’t be changed in Qlik Cloud. These include:
- Client name and description
- Redirect URIs
- Authentication method
CIMD clients use the Required consent method. A tenant administrator can’t change the consent method to Trusted.
Identify CIMD clients using the API
CIMD clients have createdByType set to cimd in the
OAuth clients API.
For example, to list CIMD clients:
curl -X GET \ 'https://<tenant-hostname>/api/v1/oauth-clients?filter=createdByType eq "cimd"' \ -H 'Authorization: Bearer <ACCESS_TOKEN>'For more information about filtering and listing OAuth clients, see the OAuth clients API reference.
Related resources
- OAuth overview: OAuth client types and registration methods
- OAuth dynamic client registration: Register compatible OAuth clients using DCR
- OAuth clients API: List and manage OAuth clients
- Connecting to the Qlik MCP server: Configure supported Large Language Model (LLM) clients to connect to the Qlik MCP server
- OAuth Client ID Metadata Document: IETF Internet-Draft defining CIMD
- MCP authorization specification: Model Context Protocol authorization guidance