github / github/copilot-cli

HTTP MCP server with Bearer token fails OAuth discovery instead of falling back to headers auth

Abierto
#3,100 0 comentarios 9 reacciones 0 asignados Ver en GitHub
area:authentication area:mcp
Lenguaje dominante
Shell
Estrellas
11.2k
Forks
1.9k
Merge medio
14 h 16 min
PR fusionados (30 d)
6

Descripción

### Describe the bug

When an HTTP MCP server is configured in .mcp.json with "type": "http" and "headers": { "Authorization": "Bearer " }, the CLI attempts OAuth discovery
(/.well-known/oauth-authorization-server
) and fails with:

MCPOAuthError: Failed to discover authorization server metadata

The CLI does not fall back to using the provided Bearer token from headers, causing a hard auth failure even though valid credentials are present in the config.

### Affected version

_No response_

### Steps to reproduce the behavior

1. Configure the mcp config for server which using custom token authorization
2. Run /mcp
3. Select the configured server
4. Pay attention to the error

Actual behavior: Hard fail on OAuth discovery, server stays disabled.

Image

### Expected behavior

Expected behavior: If OAuth discovery fails and headers contains Authorization: Bearer, the CLI should skip OAuth and proceed to MCP initialize using the provided token.

### Additional context

Workaround: Manually enabling the server via /mcp enable bypasses OAuth discovery and connects successfully using the Bearer token.

MCP spec reference: OAuth is optional — clients should fall back to configured credentials when authorization server metadata is not found.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start by reproducing the failure with an HTTP server configured in .mcp.json and the /mcp command. Trace the OAuth discovery path at /.well-known/oauth-authorization-server alongside the configured Authorization header handling. Done means discovery failure no longer disables the server when a Bearer token is configured, and MCP initialization succeeds using that token.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
shell
Área
api, authentication, cli
Tipo de issue
Error
Dificultad
3/5
Tiempo estimado
1-2 días
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
52/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.