Skip to content

MCP OAuth refresh fails for discovered endpoints and dynamically registered clients #1101

Description

@PierrunoYT

Found in the 2026-09-28 code audit (finding N-6).

Where: internal/mcp/oauth_store.go:26-32 (StoredToken), internal/mcp/network_client.go:842-847 (config()), :860-869 (Refresh), internal/mcp/oauth.go:334-340, :449-463; internal/oauth/flow.go:167-169.

Problem: Login discovers TokenEndpoint (RFC 9728 / 8414) and obtains ClientID/ClientSecret through dynamic registration, but none of it is persisted. On a 401, Refresh reads only the config-file OAuthConfig, whose TokenEndpoint is empty for the standard auth: oauth setup, giving "no token endpoint configured for refresh". Users must re-run zero mcp oauth login each time the access token expires. No test covers refresh after a discovery-based login.

Suggested fix: add TokenEndpoint, ClientID, ClientSecret to StoredToken, fall back to them in Refresh, and re-validate the stored endpoint with ValidateEndpointURL / validateProtectedDiscoveredEndpoints before use.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions