github / github/copilot-cli

[BUG]: MCP OAuth callback unreachable when running in remote container / Codespaces — no manual token paste fallback

Open
#3,009 2 comments 1 reaction 0 assignees View on GitHub
area:authentication area:mcp
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the bug

When running Copilot CLI inside a remote container (e.g., GitHub Codespaces, Dev Containers), the MCP OAuth flow redirects to a `localhost` callback URL that is unreachable from the user's browser. There is no mechanism to manually paste the authorization code/callback URL back into the CLI, unlike Claude Desktop which provides a dialog for this.

### Affected version

1.0.36

### Steps to reproduce

1. Run Copilot CLI inside a GitHub Codespace or remote dev container
2. Add an HTTP MCP server that requires OAuth
3. Run `/mcp` → trigger auth → browser opens and user authorises
4. Browser attempts to redirect to `http://127.0.0.1:/?code=...&state=...`
5. Redirect fails — localhost resolves to the user's local machine, not the container
6. OAuth handshake never completes; MCP server remains unauthenticated

### Expected behavior

The CLI should either: (a) detect that the callback was not received and prompt the user to paste the callback URL manually, or (b) provide a `/mcp auth paste` style command to accept the code out-of-band.

### Workaround

Paste the callback URL to an AI agent running inside the container and have it `curl` the URL against the local listener. Not a user-friendly solution.

### Additional context

Claude Desktop handles this via a dedicated token paste dialog. Related to #1491 (random port issue) but distinct — this is specifically about remote container environments where localhost is unreachable from the browser.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.