Skip to content

OTel: prefer AccessToken.subject over client_id for enduser.id #5563

Description

@omikader

get_auth_span_attributes() sets enduser.id = token.client_id, as documented in docs/servers/telemetry.mdx. When telemetry was added (#2869), client_id was the only identity field on AccessToken, so this made sense.

Since then AccessToken.subject exists (MCP SDK), and FastMCP's JWTVerifier populates it from sub. For OIDC-backed servers (e.g. OIDCProxy), client_id resolves via client_id or azp or sub. ID tokens always carry azp, so every user's spans get the same enduser.id: the server's upstream OAuth client ID. Per-user attribution isn't possible from FastMCP's spans.

The OTel enduser.id attribute describes the end user, which here is sub. Proposal:

attrs["enduser.id"] = token.subject or token.client_id

Client-credentials and opaque-token setups without a subject keep today's behavior. If the client identity is still useful on spans, it could move to a separate attribute.

Was reporting client_id intentional for a case we're missing? If so, a supported hook to customize auth span attributes would also solve this. (Happy to send a PR.)

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    authRelated to authentication (Bearer, JWT, OAuth, WorkOS) for client or server.bugSomething isn't working. Reports of errors, unexpected behavior, or broken functionality.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions