github / github/copilot-cli

Do not initiate redundant MCP OAuth Flows per server

Open
#2,036 0 comments 0 reactions 0 assignees View on GitHub
msft-dogfood
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the feature or problem you'd like to solve

When using multiple mcp servers which use the same client id, the user should be only prompted for auth once

### Proposed solution

**Proposed solution:**
Token deduplication: Before initiating a new OAuth flow, check if an existing valid token in the cache satisfies the requested (audience, scopes) — if so, reuse it. This would reduce N browser prompts to 1.

Verifier cleanup: On startup, remove any .verifier files whose corresponding token is absent or expired, rather than treating them as in-progress flows.

User feedback: If an OAuth flow does time out, surface a clear error message indicating which server failed and provide the remediation command.

**How will it benefit?**
Github copilot CLI users will experience less auth prompts when multiple mcp servers with the same clientId are configured.

Please refer to: https://github.com/microsoft/work-iq/issues/66

### Example prompts or workflows

1. Add 10 mcp servers to the mcp.json which use the same clientId.
2. Start GH Copilot CLI
3. The user will see 10 browser tabs popping up and will have to complete the auth flow for 10 tabs

### Additional context

More details are captured in this issue:
https://github.com/microsoft/work-iq/issues/66

Contributor guide

Open the contributing guide

Research direction

Reproduce the issue with multiple MCP servers using the same clientId in mcp.json and observe the browser prompts during startup. Trace the OAuth token cache and verifier-file handling, then verify that valid tokens are reused, stale verifiers are removed, and timeout errors identify the failed server and remediation command.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
authentication, cli, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.