github / github/copilot-cli

Shared MCP Token Cache Across CLI Sessions

オープン
#2,780 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
area:authentication area:mcp
主要言語
Shell
スター
11.2k
フォーク
1.9k
平均マージ
14時間 16分
マージ済み PR(30日)
6

説明

### Describe the feature or problem you'd like to solve

_No response_

### Proposed solution

# Feature Request: Shared MCP Token Cache Across CLI Sessions

## Problem

Each Copilot CLI terminal/session maintains its own independent MCP connections and token cache. When a token expires:

1. Running `/mcp reload` in **Terminal A** does NOT fix **Terminal B**
2. Each terminal must be individually refreshed
3. Users working with multiple CLI sessions (common for parallel workflows) must reload each one

This is inconsistent with how other developer tools work — `az login`, `gh auth login`, and `docker login` all share credentials across terminal sessions on the same machine.

## Proposed Solution

**Shared token cache**: MCP server OAuth tokens should be stored in a machine-local cache (e.g., OS keychain or a file-based token cache) that all CLI sessions on the same machine can read from.

### Implementation suggestions

- Store MCP OAuth tokens in a shared location:
- **Windows**: Windows Credential Manager or `~/.copilot/mcp-token-cache/`
- **macOS**: Keychain Access
- **Linux**: `libsecret` / `gnome-keyring` or file-based fallback
- When a CLI session needs an MCP token, check the shared cache first
- When any session refreshes a token (via `/mcp reload` or auto-refresh), update the shared cache
- Include a file lock or atomic write mechanism to prevent race conditions
- Optional: a `--no-shared-cache` flag for users who want isolated sessions

### Interaction with auto-refresh (Feature Request #1)

If auto-refresh is implemented, the shared cache becomes even more valuable:

- One session refreshes the token → all sessions benefit immediately
- No "thundering herd" of multiple sessions trying to refresh simultaneously

## Environment

- Copilot CLI on Windows (PowerShell)
- Multiple terminal sessions on the same machine
- MCP servers using Entra ID (Azure AD) OAuth

## Current Workaround

When tokens expire, users must run `/mcp reload` in **every open CLI session** individually. There is no way to refresh once and have all sessions pick up the new token.

### Example prompts or workflows

_No response_

### Additional context

_No response_

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

The issue names no files or tests. Start by tracing MCP token handling and the `/mcp reload` entry point; determine how sessions currently store and refresh tokens. Done means sessions share refreshed tokens safely across Windows, macOS, and Linux, with race prevention and the requested isolation option considered.

索引モデルが issue の本文から書いたものです。

評価

領域
authentication, cli, security
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。