github / github/copilot-cli

MCP OAuth: 'needs authentication' link never launches any visible auth flow (Atlassian/Jira, macOS, CLI 1.0.83)

オープン
#4,768 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

area:authentication area:mcp
主要言語
Shell
スター
11.2k
フォーク
1.9k
平均マージ
14時間 16分
マージ済み PR(30日)
6

説明

Describe the bug

The Atlassian (Rovo) MCP server repeatedly shows a "Jira MCP needs authentication" prompt, but clicking the provided authentication link — or attempting to authenticate manually — never launches any visible auth flow. No browser window/tab opens, no OAuth consent page appears, and nothing surfaces in the UI. The prompt simply reappears, so the server can never be authenticated and its tools are never usable.

This is the browser-launch / auth-hand-off side of MCP OAuth, not the token-bridging bug in #4096 (which is fixed on my version). It looks related to #4400 (browser login URL wrapping/fallback) and #3130 (unable to open browser for auth).

Affected version

GitHub Copilot CLI 1.0.83 (bundled engine used by the Copilot desktop app "agents" window).

Environment
  • macOS (Apple Silicon)
  • The failing flow is in the app / agents window, which manages its own MCP configuration.
  • The standalone terminal CLI has no MCP servers configured (~/.copilot/mcp-config.json = {"mcpServers":{}}, copilot mcp list = "No MCP servers configured", and ~/.copilot/mcp-oauth-config/ does not exist). So the Atlassian server exists only on the app side, and it is the app-side "authenticate" link that dead-ends.
Steps to reproduce the behavior
  1. In the Copilot app (agents window), add/enable the Atlassian Remote MCP server (https://mcp.atlassian.com/v1/mcp).
  2. When prompted with "Jira MCP needs authentication", click the provided authentication link (or choose to authenticate manually).
  3. Observe: no browser opens, no OAuth consent page appears, nothing visible happens.
  4. The "needs authentication" prompt returns; the server never becomes authenticated and no atlassian-* tools are exposed.
Expected behavior

Clicking the authentication link should open the system default browser to the OAuth consent URL (or, if the browser cannot be launched, print/copy the raw URL so it can be opened manually) and complete the callback so the server authenticates.

Additional notes
  • This consistently blocks my workflow — the Atlassian/Jira MCP tools are never available because auth can never be completed.
  • A raw-URL fallback (print the login URL to stdout / provide a copyable link) would at minimum unblock manual authentication when auto-launch fails.

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

https://mcp.atlassian.com/v1/mcp を有効にした状態で Copilot アプリのエージェントウィンドウのフローを再現し、その後、/.copilot/mcp-config.json、copilot mcp list、/.copilot/mcp-oauth-config/ に記述されたスタンドアロン CLI の状態と比較します。認証リンクの受け渡しとブラウザー起動のエントリポイントを追跡します。完了条件は、リンクによってシステムブラウザーが開くか、コピー可能な raw URL が表示され、コールバック後に Atlassian ツールが利用可能になることです。

索引モデルが issue の本文から書いたものです。

評価

領域
api, authentication, cli
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。