github / github/copilot-cli

Automatic MCP Server Token Refresh

オープン
#2,779 コメント 2 件 リアクション 7 件 担当者 0 名 GitHub で見る
area:authentication area:mcp
主要言語
Shell
スター
11.2k
フォーク
1.9k
平均マージ
14時間 16分
マージ済み PR(30日)
6

説明

### Describe the bug

# Automatic MCP Server Token Refresh

## Problem

When using long-running autopilot workflows (e.g., multi-PR feature development via custom agents), MCP server OAuth tokens expire mid-workflow. This causes:

1. **Silent tool failures** — MCP tool calls return `AADSTS9010010` auth errors
2. **Workflow interruption** — the agent must stop and ask the user to manually run `/mcp reload`
3. **Lost autopilot momentum** — what should be a hands-off workflow becomes a babysitting exercise

### Real-world impact

During a unit test coverage feature delivered via a custom agent plugin (4 PRs, 258 tests), MCP auth expired multiple times. Each time:

- The agent retried 3× with 10s delays (workaround we built into the plugin)
- After 3 failures, it had to pause and ask the user to run `/mcp reload`
- The user had to switch context, reload, then tell the agent to continue
- Total disruption: ~2-5 minutes per occurrence, multiple occurrences per session

This completely undermines the value proposition of autopilot mode.

## Proposed Solution

**Proactive token refresh**: The CLI should detect when an MCP server's OAuth token is approaching expiry and refresh it automatically in the background, similar to how `az login` maintains a token cache with automatic refresh.

### Implementation suggestions

- Use the OAuth refresh token (if available) to obtain a new access token before expiry
- If using device code flow, detect the approaching expiry window (e.g., 5 minutes before) and initiate re-auth proactively
- Surface a non-blocking notification: "🔄 Refreshed MCP auth for [server-name]"
- If silent refresh is impossible (no refresh token), fall back to prompting — but only once, not on every tool call

## Environment

- Copilot CLI on Windows (PowerShell)
- MCP servers using Entra ID (Azure AD) OAuth
- Token lifetime: typically 1 hour
- Workflows: 2-6+ hours in autopilot mode

## Current Workaround

We built an "MCP Auth Recovery Gate" pattern into our plugin, but this requires manual intervention.

```text
Retry 3× with 10s delay → if all fail with AADSTS error → ask user to run /mcp reload
```

This works but defeats autopilot's purpose.

### Affected version

_No response_

### Steps to reproduce the behavior

_No response_

### Expected behavior

_No response_

### Additional context

_No response_

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start by tracing the MCP authentication lifecycle and the `/mcp reload` path, focusing on how OAuth access and refresh tokens are handled for Entra ID servers. Define the expiry window and background refresh behavior, then verify that silent refresh is non-blocking and that servers without refresh tokens prompt only once.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
azure, powershell
領域
authentication, cli
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
42/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。