{"record":{"id":"466d789b14739c2d","repo":"siyuan-note/siyuan","slug":"oauth-token-endpoint-returned-unsupported-token-ty","errorCode":null,"errorMessage":"OAuth token endpoint returned unsupported token type %q","messagePattern":"OAuth token endpoint returned unsupported token type %q","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":403,"sourceCode":"\tif callback.Error != \"\" {\n\t\treturn fmt.Errorf(\"OAuth authorization failed: %s\", callback.Error)\n\t}\n\tif callback.State != state {\n\t\treturn fmt.Errorf(\"OAuth state mismatch\")\n\t}\n\tif callback.Code == \"\" {\n\t\treturn fmt.Errorf(\"OAuth callback did not include an authorization code\")\n\t}\n\n\texchangeCtx := context.WithValue(ctx, oauth2.HTTPClient, h.client)\n\ttoken, err := config.Exchange(exchangeCtx, callback.Code,\n\t\toauth2.VerifierOption(verifier),\n\t\toauth2.SetAuthURLParam(\"resource\", prm.Resource))\n\tif err != nil {\n\t\treturn fmt.Errorf(\"exchange OAuth authorization code: %w\", err)\n\t}\n\tif token.TokenType != \"\" && !strings.EqualFold(token.TokenType, \"Bearer\") {\n\t\treturn fmt.Errorf(\"OAuth token endpoint returned unsupported token type %q\", token.TokenType)\n\t}\n\tcredential = registrationCredential\n\tcredential.TokenAuthMethod = authMethod\n\tcredential.AccessToken = token.AccessToken\n\tcredential.RefreshToken = token.RefreshToken\n\tcredential.TokenType = token.TokenType\n\tcredential.Expiry = token.Expiry\n\tcredential.Scopes = scopes\n\tcredential.Rejected = false\n\tif err = putOAuthCredential(credential); err != nil {\n\t\treturn fmt.Errorf(\"save OAuth credentials: %w\", err)\n\t}\n\th.sourceMu.Lock()\n\th.source = &storedOAuthTokenSource{credential: credential, client: h.client}\n\th.sourceMu.Unlock()\n\tsetMCPRuntimeStateForContext(ctx, h.server.ID, \"oauth_retrying\", 0, \"\", \"\")\n\treturn nil\n}","sourceCodeStart":385,"sourceCodeEnd":421,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L385-L421","documentation":"This client only accepts Bearer access tokens (comparison is case-insensitive; an empty token_type is tolerated). If the token endpoint returns a token of another type (e.g. 'N_A', 'pop', 'DPoP', or a MAC token), the obtained token cannot be used as a bearer credential and the flow fails with the offending type in the message.","triggerScenarios":"config.Exchange succeeds, but token.TokenType is non-empty and not equal (case-insensitively) to \"Bearer\".","commonSituations":"Non-standard IdPs that return token_type values like N_A (some legacy Azure AD responses), MAC tokens, or DPoP-bound tokens; server misconfiguration returning wrong token_type in the JSON response.","solutions":["Configure the authorization server to issue Bearer (access) tokens for this client","If the server sends a nonstandard constant like N_A while tokens are effectively bearer tokens, normalize/patch the token endpoint response or file upstream for tolerance","Switch to an authorization server that supports standard RFC 6750 bearer tokens","Check server token profile settings (e.g. JWT vs reference token type settings) and set them to bearer"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Inspect the token endpoint response profile during server onboarding\n// and confirm token_type is bearer:\nif tt := token.TokenType; tt != \"\" && !strings.EqualFold(tt, \"Bearer\") {\n    return fmt.Errorf(\"server issues %q tokens; bearer required\", tt)\n}","typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, true); err != nil {\n    if strings.Contains(err.Error(), \"unsupported token type\") {\n        // reconfigure the IdP to issue bearer tokens or choose a different server\n    }\n}","preventionTips":["Onboard only IdPs that issue RFC 6750 bearer access tokens","Check server token profile settings (JWT/reference/MAC/DPoP) before wiring the client","Watch for legacy IdPs returning token_type=N_A and normalize server-side"],"tags":["oauth","mcp","token-type","bearer"],"backgroundTag":"unsupported-enum-value","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}