{"record":{"id":"24639b9b67ee3d9f","repo":"googleapis/mcp-toolbox","slug":"tokeninfo-endpoint-returned-non-ok-status-d-s","errorCode":null,"errorMessage":"tokeninfo endpoint returned non-OK status %d: %s","messagePattern":"tokeninfo endpoint returned non-OK status (.+?): (.+?)","errorType":"http","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/sources/util.go","lineNumber":104,"sourceCode":"\tclient, err := google.DefaultClient(ctx,\n\t\t\"https://www.googleapis.com/auth/userinfo.email\")\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to call userinfo endpoint: %w\", err)\n\t}\n\n\t// Retrieve the email associated with the token\n\tresp, err := client.Get(\"https://oauth2.googleapis.com/tokeninfo\")\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to call tokeninfo endpoint: %w\", err)\n\t}\n\tdefer resp.Body.Close()\n\n\tbodyBytes, err := io.ReadAll(resp.Body)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"error reading response body %d: %s\", resp.StatusCode, string(bodyBytes))\n\t}\n\tif resp.StatusCode != http.StatusOK {\n\t\treturn \"\", fmt.Errorf(\"tokeninfo endpoint returned non-OK status %d: %s\", resp.StatusCode, string(bodyBytes))\n\t}\n\n\t// Unmarshal response body and get `email`\n\tvar responseJSON map[string]any\n\terr = json.Unmarshal(bodyBytes, &responseJSON)\n\tif err != nil {\n\n\t\treturn \"\", fmt.Errorf(\"error parsing JSON: %v\", err)\n\t}\n\n\temailValue, ok := responseJSON[\"email\"]\n\tif !ok {\n\t\treturn \"\", fmt.Errorf(\"email not found in response: %v\", err)\n\t}\n\n\tfullEmail, ok := emailValue.(string)\n\tif !ok {\n\t\treturn \"\", fmt.Errorf(\"email field is not a string\")","sourceCodeStart":86,"sourceCodeEnd":122,"githubUrl":"https://github.com/googleapis/mcp-toolbox/blob/8cc6e09de2ad7b8bffc77751799585a1401a48eb/internal/sources/util.go#L86-L122","documentation":"The tokeninfo endpoint replied with a non-200 status (body included in the message) — the ADC token was rejected, expired, or the request was otherwise refused by Google's OAuth infrastructure.","triggerScenarios":"Thrown at internal/sources/util.go:104 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Refresh Application Default Credentials","Check the response body in the error for the specific OAuth failure","Verify the credential has the userinfo.email scope"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"8cc6e09de2ad7b8bffc77751799585a1401a48eb","analyzedAt":"2026-09-05T01:10:36.887Z","contentChangedAt":"2026-09-05T01:10:36.887Z","schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}