Summary
Logging in to a remote HTTP MCP server fails with:
Authentication failed
jira: RPC error -32603: Request session.mcp.oauth.login failed with message: MCP request failed: MCP server probe returned HTTP 400 Bad Request
The server rejects the client's protocol version with HTTP 400. The normal connection path handles this by retrying with legacy initialize, but the OAuth login probe does not retry. So the browser OAuth flow never starts and the user cannot log in at all.
Environment
- GitHub Copilot app 1.1.26 (commit 5ab79c8), Windows x86_64
- Copilot CLI runtime 1.0.90-0
- Started after the app updated to 1.1.26. Login against the same server worked on the previous version.
- MCP server config (
~/.copilot/mcp-config.json):
{ "jira": { "type": "http", "url": "https://jira.mcp.spiris.ai/mcp/p/common" } }
Server behavior (reproduced with curl)
The server only accepts MCP-Protocol-Version: 2025-03-26, or no header at all:
| Request |
Response |
POST/GET, no MCP-Protocol-Version header |
401 + valid WWW-Authenticate with resource_metadata |
MCP-Protocol-Version: 2025-03-26 |
401 + valid WWW-Authenticate |
MCP-Protocol-Version: 2025-06-18 |
400 {"error":"unsupported_protocol_version","message":"Unsupported MCP protocol version: 2025-06-18"} |
MCP-Protocol-Version: 2026-07-28 |
400 {"error":"unsupported_protocol_version","message":"Unsupported MCP protocol version: 2026-07-28"} |
The OAuth metadata is otherwise correct. /.well-known/oauth-protected-resource/... and /.well-known/oauth-authorization-server both return 200. Dynamic client registration also succeeds.
Logs
The connection path falls back as expected:
[WARNING] [rust:mcp::client] server/discover failed; retrying with legacy initialize {"error":"unexpected server response: HTTP 400 Bad Request: {\"error\":\"unsupported_protocol_version\",\"message\":\"Unsupported MCP protocol version: 2026-07-28\"}"}
[WARNING] [rust:copilot_runtime::session::mcp::agent_host] HTTP 401 challenge (WWW-Authenticate: Bearer realm="jirast-mcp", resource_metadata="https://jira.mcp.spiris.ai/.well-known/oauth-protected-resource/mcp/p/common", ...) {"server":"jira"}
[WARNING] [rust:mcp_engine::session_authorizer] MCP OAuth authorization failed; reporting the server as needing auth {"server":"jira","error":"Browser-based OAuth required for https://jira.mcp.spiris.ai/mcp/p/common"}
When the user then starts the login (session.mcp.oauth.login), the probe gets the 400 and the login aborts with no fallback.
Expected
The OAuth login probe should handle a 400 unsupported_protocol_version the same way the connection path does. It should retry with an older or legacy protocol version, or without the MCP-Protocol-Version header. That retry gets the 401 challenge, and browser OAuth can then start.
Actual
The login fails right away with MCP server probe returned HTTP 400 Bad Request. There's no workaround on the client side: clearing ~/.copilot/mcp-oauth-config and restarting doesn't help.
Side note
Before the reset, ~/.copilot/mcp-oauth-config had collected 167 orphaned <hash>.tokens.json files. They had no matching client config and no refresh token, and they covered about a month of sessions, all for one server. Possibly a separate token-cache cleanup issue.
Summary
Logging in to a remote HTTP MCP server fails with:
The server rejects the client's protocol version with HTTP 400. The normal connection path handles this by retrying with legacy
initialize, but the OAuth login probe does not retry. So the browser OAuth flow never starts and the user cannot log in at all.Environment
~/.copilot/mcp-config.json):{ "jira": { "type": "http", "url": "https://jira.mcp.spiris.ai/mcp/p/common" } }Server behavior (reproduced with curl)
The server only accepts
MCP-Protocol-Version: 2025-03-26, or no header at all:MCP-Protocol-Versionheader401+ validWWW-Authenticatewithresource_metadataMCP-Protocol-Version: 2025-03-26401+ validWWW-AuthenticateMCP-Protocol-Version: 2025-06-18400 {"error":"unsupported_protocol_version","message":"Unsupported MCP protocol version: 2025-06-18"}MCP-Protocol-Version: 2026-07-28400 {"error":"unsupported_protocol_version","message":"Unsupported MCP protocol version: 2026-07-28"}The OAuth metadata is otherwise correct.
/.well-known/oauth-protected-resource/...and/.well-known/oauth-authorization-serverboth return 200. Dynamic client registration also succeeds.Logs
The connection path falls back as expected:
When the user then starts the login (
session.mcp.oauth.login), the probe gets the 400 and the login aborts with no fallback.Expected
The OAuth login probe should handle a 400
unsupported_protocol_versionthe same way the connection path does. It should retry with an older or legacy protocol version, or without theMCP-Protocol-Versionheader. That retry gets the 401 challenge, and browser OAuth can then start.Actual
The login fails right away with
MCP server probe returned HTTP 400 Bad Request. There's no workaround on the client side: clearing~/.copilot/mcp-oauth-configand restarting doesn't help.Side note
Before the reset,
~/.copilot/mcp-oauth-confighad collected 167 orphaned<hash>.tokens.jsonfiles. They had no matching client config and no refresh token, and they covered about a month of sessions, all for one server. Possibly a separate token-cache cleanup issue.