{"record":{"id":"40a6cd6d44034bce","repo":"siyuan-note/siyuan","slug":"oauth-client-registration-returned-an-unsupported","errorCode":null,"errorMessage":"OAuth client registration returned an unsupported token endpoint authentication method","messagePattern":"OAuth client registration returned an unsupported token endpoint authentication method","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":332,"sourceCode":"\t\t\tResourceMetadataURL: prm.MetadataURL,\n\t\t\tRedirectURL:         callbackURL,\n\t\t\tClientID:            registration.ClientID,\n\t\t\tClientSecret:        registration.ClientSecret,\n\t\t\tClientSecretExpiry:  registration.ClientSecretExpiresAt,\n\t\t\tTokenEndpoint:       asm.TokenEndpoint,\n\t\t\tRevocationEndpoint:  asm.RevocationEndpoint,\n\t\t\tTokenAuthMethod:     registration.TokenEndpointAuthMethod,\n\t\t\tScopes:              scopes,\n\t\t}\n\t\tif registrationCredential.TokenAuthMethod == \"\" {\n\t\t\tif registration.ClientSecret == \"\" {\n\t\t\t\tregistrationCredential.TokenAuthMethod = \"none\"\n\t\t\t} else {\n\t\t\t\tregistrationCredential.TokenAuthMethod = \"client_secret_basic\"\n\t\t\t}\n\t\t}\n\t\tif !isSupportedTokenAuthMethod(registrationCredential.TokenAuthMethod) {\n\t\t\treturn fmt.Errorf(\"OAuth client registration returned an unsupported token endpoint authentication method\")\n\t\t}\n\t\tif err = putOAuthCredential(registrationCredential); err != nil {\n\t\t\treturn fmt.Errorf(\"save OAuth client registration: %w\", err)\n\t\t}\n\t}\n\n\tauthMethod := registrationCredential.TokenAuthMethod\n\tif authMethod == \"\" {\n\t\tif registrationCredential.ClientSecret == \"\" {\n\t\t\tauthMethod = \"none\"\n\t\t} else {\n\t\t\tauthMethod = \"client_secret_basic\"\n\t\t}\n\t}\n\tconfig := &oauth2.Config{\n\t\tClientID:     registrationCredential.ClientID,\n\t\tClientSecret: registrationCredential.ClientSecret,\n\t\tRedirectURL:  callbackURL,","sourceCodeStart":314,"sourceCodeEnd":350,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L314-L350","documentation":"During dynamic OAuth client registration (RFC 7591), the authorization server's registration response may echo back a token_endpoint_auth_method. This library only supports 'none', 'client_secret_post', and 'client_secret_basic' (see isSupportedTokenAuthMethod). If the server registers the client with any other method (e.g. 'client_secret_jwt' or 'private_key_jwt'), Authorize aborts rather than attempting a token exchange it cannot perform.","triggerScenarios":"Authorize() performs dynamic client registration (RegisterClient) and the registration response contains a TokenEndpointAuthMethod that is not empty and not one of none/client_secret_post/client_secret_basic.","commonSituations":"Connecting to an enterprise/legacy OAuth server whose registration endpoint defaults clients to JWT-based authentication methods (private_key_jwt, client_secret_jwt, or TLS client auth) that this native public client cannot use.","solutions":["Use an authorization server that registers clients with public-client compatible methods (none, client_secret_post, or client_secret_basic)","Pre-register the client manually with a compatible token_endpoint_auth_method so dynamic registration is skipped (canReuseRegistration path)","If you control the server, change its registration policy/default token_endpoint_auth_method to client_secret_basic or none","File/patch an upstream change to add support for the required auth method (e.g. private_key_jwt)"],"exampleFix":"// before (server-issued registration response)\n{\"client_id\":\"...\",\"token_endpoint_auth_method\":\"private_key_jwt\"}\n// after: server must return a supported method, e.g.\n{\"client_id\":\"...\",\"token_endpoint_auth_method\":\"client_secret_basic\"}","handlingStrategy":"validation","validationCode":"// Before starting the flow, check the AS metadata advertises a compatible method\nif !slices.ContainsAny(asm.TokenEndpointAuthMethodsSupported, []string{\"none\", \"client_secret_post\", \"client_secret_basic\"}) {\n    return fmt.Errorf(\"server supports none of the client's token auth methods\")\n}","typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, interactive); err != nil {\n    if strings.Contains(err.Error(), \"unsupported token endpoint authentication method\") {\n        // surface guidance: server requires JWT/private-key client auth; use a compatible IdP\n    }\n}","preventionTips":["Verify the IdP's token_endpoint_auth_methods_supported includes a public-client method before enabling OAuth for the MCP server","Prefer IdPs known to register native clients as public (token_endpoint_auth_method=none)","Test dynamic registration with a quick curl POST before wiring up the client"],"tags":["oauth","mcp","unsupported-auth-method","dynamic-client-registration"],"backgroundTag":"unsupported-enum-value","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}