MCP OAuth client discovery: OAuth servers connect briefly then disconnect — tools never available in session
まだ誰も着手していません。
- 主要言語
- Shell
- スター
- 11.2k
- フォーク
- 1.9k
- 平均マージ
- 14時間 16分
- マージ済み PR(30日)
- 6
説明
Description
OAuth-protected MCP servers (Work IQ Calendar/Mail/Teams/OneDrive/Word + custom SkylineApi) show green/connected in the MCP servers settings page but consistently fail to provide tools in any session.
Reproduction steps
- Configure multiple OAuth-protected HTTP MCP servers in
~/.copilot/mcp-config.json(e.g. Work IQ servers atagent365.svc.cloud.microsoftand a custom Azure-hosted server) - Start the Copilot app — MCP servers settings page shows all servers with green status indicators
- Open any new session (chat or project session)
- Try to use tools from any OAuth-protected server → tools are not available
What the logs show
From process-*.log during session creation:
Phase 1: Initial connection fails with AuthRequired
Server SkylineApi requires authentication, initiating OAuth flow
OAuth authentication required for SkylineApi
Phase 2: OAuth request sent to wrong handler
[extension:...\task-housekeeping\extension.mjs] Received MCP OAuth request without a registered MCP auth handler.
OAuth handler did not provide credentials for SkylineApi (cancelled); marking as needs-auth
OAuth required for SkylineApi with no cached tokens; marking as needs-auth
The OAuth request is being routed to an unrelated local extension (task-housekeeping) instead of the app's built-in OAuth handler. The extension correctly reports it has no MCP auth handler registered, but the app interprets this as a cancellation and permanently marks the server as needs-auth.
Phase 3: Work IQ servers eventually connect after retries (~10-30s)
MCP client for Work IQ Calendar connected, took 3022ms
MCP client for Work IQ Teams connected, took 718ms
MCP client for Work IQ Word connected, took 587ms
MCP client for Work IQ Mail connected, took 690ms
Phase 4: All connections drop ~90 seconds later
MCP connection for Work IQ OneDrive closed
MCP connection for Work IQ Mail closed
MCP connection for Work IQ Word closed
MCP connection for Work IQ Teams closed
MCP connection for Work IQ Calendar closed
Phase 5 (SkylineApi): Never reconnects
OAuth required for SkylineApi with no cached tokens; marking as needs-auth
The SkylineApi uses Azure AD OAuth (api://eadfb142-206f-4a1b-a917-a719539433a0/user_impersonation). The app detects the AuthRequired response from the /.well-known/oauth-protected-resource endpoint but cannot complete the OAuth flow because the auth request is routed to the wrong handler.
Expected behavior
- The app's built-in OAuth handler should handle MCP OAuth requests, not route them to unrelated extensions
- OAuth tokens should be cached and refreshed automatically
- Once connected, MCP connections should remain open for the session lifetime (or reconnect automatically)
- The settings page green indicator should reflect actual runtime connectivity, not just config validity
Environment
- App version: 1.0.19 (
com.github.githubapp) - CLI version: 1.0.69
- OS: Windows 11
- MCP servers affected: All OAuth-protected HTTP servers (5× Work IQ at
agent365.svc.cloud.microsoft+ 1× custom Azure Container Apps server) - MCP servers working: Non-OAuth servers (
microsoft-learn,github-mcp-server,markitdownlocal) all connect fine
MCP config (sanitized)
{
"mcpServers": {
"SkylineApi": {
"type": "http",
"url": "https://<custom-azure-container-app>/mcp",
"timeout": 28800000
},
"Work IQ Calendar": {
"type": "http",
"url": "https://agent365.svc.cloud.microsoft/agents/tenants/<tenant-id>/servers/mcp_CalendarTools",
"timeout": 14400000
}
}
}
(Same pattern for Work IQ Mail, Teams, OneDrive, Word)
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
process-*.log ファイル内の OAuth および MCP 接続イベントから始め、サニタイズ済みの ~/.copilot/mcp-config.json を使用して OAuth で保護された HTTP サーバーを再現します。リクエストが task-housekeeping に到達する理由と、サーバーが needs-auth としてマークされる理由を追跡し、その後、OAuth サーバーがセッションの全期間を通じて利用可能なままであること、および設定のステータスが実行時の接続状態を反映していることを確認します。
索引モデルが issue の本文から書いたものです。
評価
- 領域
- api, authentication
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 45/100