github / github/copilot-cli

CIMD declares callback port 33418 but Copilot CLI uses an ephemeral port

Open
#4,793 1 comment 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

triage
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

Describe the bug

Copilot CLI’s Client ID Metadata Document declares a fixed loopback callback port, but the CLI sends a different ephemeral port in the OAuth authorization request.

Client metadata: https://github.com/copilot/cli/client-metadata.json

{
  "client_id": "https://github.com/copilot/cli/client-metadata.json",
  "application_type": "native",
  "redirect_uris": [
    "http://127.0.0.1:33418/"
  ]
}

The authorization request generated by Copilot CLI instead contains a callback such as:

  redirect_uri=http://127.0.0.1:60005/

My authorization server rejects the request with:

  unauthorized_client: Callback URL mismatch.
  http://127.0.0.1:60005/ is not in the list of allowed callback URLs
Affected version

GitHub Copilot CLI 1.0.83

Steps to reproduce the behavior
  1. Configure a remote MCP server protected by an Auth0 authorization server.
  2. Register Copilot CLI in Auth0 using: https://github.com/copilot/cli/client-metadata.json
  3. Add the remote MCP server to Copilot CLI.
  4. Start authentication.
  5. Inspect the generated /authorize request.

The request uses an ephemeral loopback port rather than the 33418 port declared in the metadata document.

Expected behavior

The redirect URI used by Copilot CLI should be compatible with its published metadata.

Either:

  1. Copilot CLI should bind to the declared callback:

      http://127.0.0.1:33418/
    
  2. The metadata should declare a portless loopback callback compatible with ephemeral ports:

      "redirect_uris": [
        "http://127.0.0.1/"
      ]
    

There should not be a requirement for every MCP server operator or Copilot user to configure a callback-port override.

Additional context
  • Operating system: macOS 26.5.1
  • MCP transport: Streamable HTTP
  • Authorization server: Auth0
  • Client registration: Client ID Metadata Document

For reference, Claude Code also uses an ephemeral loopback but its metadata document declares port-less loopback callbacks:

  "redirect_uris": [
    "http://localhost/callback",
    "http://127.0.0.1/callback"
  ]

The same Auth0 authorization server accepts Claude Code’s runtime callback while rejecting Copilot CLI’s callback because Copilot’s metadata explicitly pins port 33418.

Claude's metadata: https://claude.ai/oauth/claude-code-client-metadata

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the published client-metadata.json and the Copilot CLI OAuth authorization flow that generates the /authorize request. Compare the declared redirect URI with the runtime loopback callback and determine which behavior should be aligned; done means an authorization server accepts the callback without a per-user port override.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, cli
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.