github / github/copilot-cli

HTTP MCP server with Bearer token fails OAuth discovery instead of falling back to headers auth

Open
#3,100 0 comments 9 reactions 0 assignees View on GitHub
area:authentication area:mcp
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the bug

When an HTTP MCP server is configured in .mcp.json with "type": "http" and "headers": { "Authorization": "Bearer " }, the CLI attempts OAuth discovery
(/.well-known/oauth-authorization-server
) and fails with:

MCPOAuthError: Failed to discover authorization server metadata

The CLI does not fall back to using the provided Bearer token from headers, causing a hard auth failure even though valid credentials are present in the config.

### Affected version

_No response_

### Steps to reproduce the behavior

1. Configure the mcp config for server which using custom token authorization
2. Run /mcp
3. Select the configured server
4. Pay attention to the error

Actual behavior: Hard fail on OAuth discovery, server stays disabled.

Image

### Expected behavior

Expected behavior: If OAuth discovery fails and headers contains Authorization: Bearer, the CLI should skip OAuth and proceed to MCP initialize using the provided token.

### Additional context

Workaround: Manually enabling the server via /mcp enable bypasses OAuth discovery and connects successfully using the Bearer token.

MCP spec reference: OAuth is optional — clients should fall back to configured credentials when authorization server metadata is not found.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.