Vault credential background refresh now supported for mcp_oauth
AI Impact Summary
Vault now supports automatic background renewal of credentials used by mcp_oauth, eliminating the need for manual refresh interrupts. This reduces the risk of service outages caused by expired credentials during long-running processes and lowers operational overhead for credential rotation. Ensure the Vault lease renewal permissions are enabled for the mcp_oauth role and that client libraries can renew leases in the background; add monitoring for renewal failures to detect edge cases where renewals stall.
Affected Systems
- Date
- Date not specified
- Change type
- capability
- Severity
- medium