{"record":{"id":"8b3ce135fa508daf","repo":"Hmbown/CodeWhale","slug":"mcp-server-rejected-the-request-with-status-the-session-is","errorCode":null,"errorMessage":"MCP server {} rejected the request with {status}; the session is no longer accepted. {hint}","messagePattern":"MCP server (.+?) rejected the request with (.+?); the session is no longer accepted\\. (.+?)","errorType":"http","errorClass":"StreamableSendError::Other","httpStatus":401,"severity":"error","filePath":"crates/tui/src/mcp/streamable_http.rs","lineNumber":128,"sourceCode":"\n            if status == StatusCode::UNAUTHORIZED || status == StatusCode::FORBIDDEN {\n                if !retried && let Some(oauth) = self.auth.oauth.as_ref() {\n                    match oauth.force_refresh().await {\n                        Ok(()) => {\n                            retried = true;\n                            continue;\n                        }\n                        Err(refresh_error) => {\n                            return Err(StreamableSendError::Other(anyhow::anyhow!(\n                                \"MCP server {} rejected the request with {status} and refreshing the OAuth session failed: {refresh_error:#}. {hint}\",\n                                mask_url_secrets(&self.url),\n                                hint = oauth_refresh_failed_hint(),\n                            )));\n                        }\n                    }\n                }\n                let hint = unauthorized_session_hint(self.auth.oauth_configured);\n                return Err(StreamableSendError::Other(anyhow::anyhow!(\n                    \"MCP server {} rejected the request with {status}; the session is no longer accepted. {hint}\",\n                    mask_url_secrets(&self.url),\n                )));\n            }\n\n            if !status.is_success() {\n                let body_excerpt = bounded_body_excerpt(response, ERROR_BODY_PREVIEW_BYTES).await;\n                let stale_session = self.session_id.is_some()\n                    && is_streamable_http_stale_session_status(status, &body_excerpt);\n                let body_excerpt = self.auth.server_error_preview(&body_excerpt);\n                if stale_session {\n                    return Err(StreamableSendError::StaleSession(format!(\n                        \"status={status} body={body_excerpt}\"\n                    )));\n                }\n                if is_streamable_http_incompatible_status(status) {\n                    return Err(StreamableSendError::Incompatible(format!(\n                        \"status={status} body={body_excerpt}\"","sourceCodeStart":110,"sourceCodeEnd":146,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/mcp/streamable_http.rs#L110-L146","documentation":"After a failed OAuth refresh attempt (previous case) is exhausted, or when the auth path is exhausted, a rejected status on the MCP POST means the server no longer accepts the session. The client surfaces the masked server URL, the status, and a hint tailored to whether OAuth is configured, telling the developer the session must be re-established.","triggerScenarios":"send() receives an auth-rejection status (e.g. 401/403) from the MCP server's POST response after the refresh-and-retry path did not apply or completed, and unauthorized_session_hint() builds guidance based on whether OAuth is configured.","commonSituations":"Server restarted and invalidated the session id; session revoked server-side; tokens expired and no OAuth configured; stale session id replayed after server state loss.","solutions":["Re-authenticate / re-run the OAuth flow for the MCP server","If OAuth is not configured but the server requires auth, configure OAuth credentials","Retry the request so a fresh session id is negotiated","Check server-side session/auth configuration and logs"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"match client.send(request).await {\n    Err(e) if e.to_string().contains(\"session is no longer accepted\") => {\n        // start a fresh session (drop stale session id) and retry once\n        client.reset_session();\n        client.send(request).await\n    }\n    other => other,\n}","preventionTips":["Re-negotiate the session id after any server restart or 4xx session rejection","Configure OAuth when the server requires authentication","Don't cache session ids across long idle periods"],"tags":["http","session","authentication","mcp"],"backgroundTag":"unexpected-http-status","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}