镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

MCP OAuth login fails with HTTP 400 when server rejects MCP-Protocol-Version (no fallback to older version) #5039

Description

@hakonz3

Summary

Logging in to a remote HTTP MCP server fails with:

Authentication failed
jira: RPC error -32603: Request session.mcp.oauth.login failed with message: MCP request failed: MCP server probe returned HTTP 400 Bad Request

The server rejects the client's protocol version with HTTP 400. The normal connection path handles this by retrying with legacy initialize, but the OAuth login probe does not retry. So the browser OAuth flow never starts and the user cannot log in at all.

Environment

  • GitHub Copilot app 1.1.26 (commit 5ab79c8), Windows x86_64
  • Copilot CLI runtime 1.0.90-0
  • Started after the app updated to 1.1.26. Login against the same server worked on the previous version.
  • MCP server config (~/.copilot/mcp-config.json):
    { "jira": { "type": "http", "url": "https://jira.mcp.spiris.ai/mcp/p/common" } }

Server behavior (reproduced with curl)

The server only accepts MCP-Protocol-Version: 2025-03-26, or no header at all:

Request Response
POST/GET, no MCP-Protocol-Version header 401 + valid WWW-Authenticate with resource_metadata
MCP-Protocol-Version: 2025-03-26 401 + valid WWW-Authenticate
MCP-Protocol-Version: 2025-06-18 400 {"error":"unsupported_protocol_version","message":"Unsupported MCP protocol version: 2025-06-18"}
MCP-Protocol-Version: 2026-07-28 400 {"error":"unsupported_protocol_version","message":"Unsupported MCP protocol version: 2026-07-28"}

The OAuth metadata is otherwise correct. /.well-known/oauth-protected-resource/... and /.well-known/oauth-authorization-server both return 200. Dynamic client registration also succeeds.

Logs

The connection path falls back as expected:

[WARNING] [rust:mcp::client] server/discover failed; retrying with legacy initialize {"error":"unexpected server response: HTTP 400 Bad Request: {\"error\":\"unsupported_protocol_version\",\"message\":\"Unsupported MCP protocol version: 2026-07-28\"}"}
[WARNING] [rust:copilot_runtime::session::mcp::agent_host] HTTP 401 challenge (WWW-Authenticate: Bearer realm="jirast-mcp", resource_metadata="https://jira.mcp.spiris.ai/.well-known/oauth-protected-resource/mcp/p/common", ...) {"server":"jira"}
[WARNING] [rust:mcp_engine::session_authorizer] MCP OAuth authorization failed; reporting the server as needing auth {"server":"jira","error":"Browser-based OAuth required for https://jira.mcp.spiris.ai/mcp/p/common"}

When the user then starts the login (session.mcp.oauth.login), the probe gets the 400 and the login aborts with no fallback.

Expected

The OAuth login probe should handle a 400 unsupported_protocol_version the same way the connection path does. It should retry with an older or legacy protocol version, or without the MCP-Protocol-Version header. That retry gets the 401 challenge, and browser OAuth can then start.

Actual

The login fails right away with MCP server probe returned HTTP 400 Bad Request. There's no workaround on the client side: clearing ~/.copilot/mcp-oauth-config and restarting doesn't help.

Side note

Before the reset, ~/.copilot/mcp-oauth-config had collected 167 orphaned <hash>.tokens.json files. They had no matching client config and no refresh token, and they covered about a month of sessions, all for one server. Possibly a separate token-cache cleanup issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:mcpMCP server configuration, discovery, connectivity, OAuth, policy, and registry

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions