{"record":{"id":"bbff901229eac6be","repo":"siyuan-note/siyuan","slug":"oauth-authorization-server-does-not-support-a-comp","errorCode":null,"errorMessage":"OAuth authorization server does not support a compatible token endpoint authentication method","messagePattern":"OAuth authorization server does not support a compatible token endpoint authentication method","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":291,"sourceCode":"\tscopes := append([]string(nil), prm.ScopesSupported...)\n\tif len(scopes) == 0 {\n\t\tscopes = append(scopes, asm.ScopesSupported...)\n\t}\n\tfor _, scope := range strings.Fields(bearerChallengeParam(challenges, \"scope\")) {\n\t\tif !slices.Contains(scopes, scope) {\n\t\t\tscopes = append(scopes, scope)\n\t\t}\n\t}\n\tregistrationCredential := credential\n\tcanReuseRegistration := hasCredential && credential.Issuer == asm.Issuer && credential.RedirectURL == callbackURL &&\n\t\tcredential.ClientID != \"\" && !oauthClientRegistrationExpired(credential) && oauthScopesContain(credential.Scopes, scopes)\n\tif !canReuseRegistration {\n\t\tif asm.RegistrationEndpoint == \"\" {\n\t\t\treturn fmt.Errorf(\"OAuth authorization server does not support dynamic client registration\")\n\t\t}\n\t\ttokenAuthMethod := preferredTokenAuthMethod(asm.TokenEndpointAuthMethodsSupported)\n\t\tif len(asm.TokenEndpointAuthMethodsSupported) > 0 && tokenAuthMethod == \"\" {\n\t\t\treturn fmt.Errorf(\"OAuth authorization server does not support a compatible token endpoint authentication method\")\n\t\t}\n\t\tgrantTypes := []string{\"authorization_code\"}\n\t\tif len(asm.GrantTypesSupported) == 0 || slices.Contains(asm.GrantTypesSupported, \"refresh_token\") {\n\t\t\tgrantTypes = append(grantTypes, \"refresh_token\")\n\t\t}\n\t\tregistration, registerErr := oauthex.RegisterClient(ctx, asm.RegistrationEndpoint, &oauthex.ClientRegistrationMetadata{\n\t\t\tRedirectURIs:            []string{callbackURL},\n\t\t\tTokenEndpointAuthMethod: tokenAuthMethod,\n\t\t\tGrantTypes:              grantTypes,\n\t\t\tResponseTypes:           []string{\"code\"},\n\t\t\tClientName:              \"SiYuan\",\n\t\t\tScope:                   strings.Join(scopes, \" \"),\n\t\t\tApplicationType:         \"native\",\n\t\t}, h.client)\n\t\tif registerErr != nil {\n\t\t\treturn fmt.Errorf(\"register OAuth client: %w\", registerErr)\n\t\t}\n\t\tregistrationCredential = oauthCredential{","sourceCodeStart":273,"sourceCodeEnd":309,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L273-L309","documentation":"Dynamic client registration is about to run, but none of the token_endpoint_auth_methods_supported advertised by the authorization server is one the client can perform (preferredTokenAuthMethod returned empty for a non-empty list). The client supports a fixed set (e.g. none, client_secret_basic, client_secret_post) and refuses to register with an auth method it cannot use.","triggerScenarios":"Interactive Authorize with canReuseRegistration == false, a non-empty asm.RegistrationEndpoint, and asm.TokenEndpointAuthMethodsSupported containing only methods outside the client's supported set (e.g. [\"tls_client_auth\", \"private_key_jwt\"]).","commonSituations":"Enterprise IdPs mandating mutual-TLS or JWT-based client authentication; hardening policies that disabled client_secret_basic/post and unauthenticated (public) clients.","solutions":["Reconfigure the authorization server to also allow client_secret_basic, client_secret_post, or none (public client) as token endpoint auth methods","Use an IdP policy/profile that supports standard shared-secret or public-client authentication for native apps","If forced onto strong auth methods, connect via a gateway/proxy IdP that accepts them and exposes standard methods"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"if len(asm.TokenEndpointAuthMethodsSupported) > 0 && preferredTokenAuthMethod(asm.TokenEndpointAuthMethodsSupported) == \"\" {\n    return errors.New(\"IdP only offers token auth methods this client cannot perform\")\n}","typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, req, resp); err != nil && strings.Contains(err.Error(), \"token endpoint authentication method\") {\n    suggestIdPPolicyRelaxation(err)\n}","preventionTips":["Inspect token_endpoint_auth_methods_supported in metadata before connecting","Enable client_secret_basic / client_secret_post / none in the IdP policy for native apps","Avoid IdP profiles that mandate mTLS or private_key_jwt for MCP clients"],"tags":["oauth","mcp","dcr","compatibility"],"backgroundTag":"unsupported-operation","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}