{"record":{"id":"347f0d1194fbe4d4","repo":"siyuan-note/siyuan","slug":"oauth-authorization-server-does-not-support-pkce-s","errorCode":null,"errorMessage":"OAuth authorization server does not support PKCE S256","messagePattern":"OAuth authorization server does not support PKCE S256","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":252,"sourceCode":"\t\t\tsetMCPRuntimeStateForContext(ctx, h.server.ID, \"oauth_retrying\", 0, \"\", \"\")\n\t\t\treturn nil\n\t\t}\n\t\tif !permanent {\n\t\t\treturn fmt.Errorf(\"refresh OAuth credentials: %w\", refreshErr)\n\t\t}\n\t\tcredential.AccessToken = \"\"\n\t\tcredential.RefreshToken = \"\"\n\t\tcredential.Expiry = time.Time{}\n\t\tif saveErr := putOAuthCredential(credential); saveErr != nil {\n\t\t\tlogging.LogWarnf(\"mcp oauth: clear invalid credentials failed: %s\", saveErr)\n\t\t}\n\t}\n\tif !interactive {\n\t\tsetMCPRuntimeStateForContext(ctx, h.server.ID, \"authorization_required\", 0, \"\", \"\")\n\t\treturn errOAuthAuthorizationRequired\n\t}\n\tif !slices.Contains(asm.CodeChallengeMethodsSupported, \"S256\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support PKCE S256\")\n\t}\n\tif len(asm.ResponseTypesSupported) > 0 && !slices.Contains(asm.ResponseTypesSupported, \"code\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support the authorization code response type\")\n\t}\n\tif len(asm.GrantTypesSupported) > 0 && !slices.Contains(asm.GrantTypesSupported, \"authorization_code\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support the authorization code grant\")\n\t}\n\n\tflowID := reusableOAuthFlowID(credential)\n\tif flowID == \"\" {\n\t\tflowID, err = secureRandomString(24)\n\t\tif err != nil {\n\t\t\treturn err\n\t\t}\n\t}\n\tstate, err := secureRandomString(24)\n\tif err != nil {\n\t\treturn err","sourceCodeStart":234,"sourceCodeEnd":270,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L234-L270","documentation":"During an interactive authorization the discovered authorization-server metadata's CodeChallengeMethodsSupported does not include S256. SiYuan's MCP client always uses PKCE with S256 (plain is rejected as insecure), so a server lacking S256 cannot complete the flow and the client refuses to start it.","triggerScenarios":"Interactive Authorize (user-triggered) reaches the capability checks after metadata discovery, and asm.CodeChallengeMethodsSupported omits \"S256\" (or is empty/absent for plain-PKCE-only or pre-PKCE servers).","commonSituations":"Legacy OAuth server or old IdP version predating PKCE support; IdP configured with PKCE disabled; homemade OAuth implementation that only supports plain or no PKCE.","solutions":["Upgrade or reconfigure the authorization server to enable PKCE with the S256 code challenge method","Check IdP settings (e.g. client/policy config) that toggle supported code_challenge_methods","If the IdP genuinely cannot support S256, use a different OAuth provider or a non-OAuth connection method for this MCP server"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"asm, err := auth.GetAuthServerMetadata(ctx, authServerURL, client)\nif err == nil && asm != nil && !slices.Contains(asm.CodeChallengeMethodsSupported, \"S256\") {\n    return errors.New(\"IdP lacks PKCE S256; fix or replace before connecting\")\n}","typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, req, resp); err != nil && strings.Contains(err.Error(), \"PKCE S256\") {\n    showIncompatibleServerDialog(err)\n}","preventionTips":["Verify CodeChallengeMethodsSupported includes S256 when choosing an IdP for MCP","Enable PKCE S256 in IdP client/authorization policies before first connect","Treat plain-PKCE-only or pre-PKCE OAuth servers as incompatible with MCP"],"tags":["oauth","mcp","pkce","compatibility"],"backgroundTag":"unsupported-operation","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}