{"record":{"id":"d5fa858a1ee747fd","repo":"Hmbown/CodeWhale","slug":"mcp-server-rejected-the-request-with-status-and-refreshing","errorCode":null,"errorMessage":"MCP server {} rejected the request with {status} and refreshing the OAuth session failed: {refresh_error:#}. {hint}","messagePattern":"MCP server (.+?) rejected the request with (.+?) and refreshing the OAuth session failed: (.+?)\\. (.+?)","errorType":"http","errorClass":"StreamableSendError::Other","httpStatus":401,"severity":"error","filePath":"crates/tui/src/mcp/streamable_http.rs","lineNumber":119,"sourceCode":"                && self.session_id.as_deref() != Some(sid)\n            {\n                let session_ref = crate::utils::redacted_identifier_for_log(sid);\n                tracing::debug!(target: \"mcp\", session = %session_ref, \"captured MCP session ID\");\n                self.session_id = Some(sid.to_string());\n            }\n            if status == StatusCode::ACCEPTED || status == StatusCode::NO_CONTENT {\n                return Ok(());\n            }\n\n            if status == StatusCode::UNAUTHORIZED || status == StatusCode::FORBIDDEN {\n                if !retried && let Some(oauth) = self.auth.oauth.as_ref() {\n                    match oauth.force_refresh().await {\n                        Ok(()) => {\n                            retried = true;\n                            continue;\n                        }\n                        Err(refresh_error) => {\n                            return Err(StreamableSendError::Other(anyhow::anyhow!(\n                                \"MCP server {} rejected the request with {status} and refreshing the OAuth session failed: {refresh_error:#}. {hint}\",\n                                mask_url_secrets(&self.url),\n                                hint = oauth_refresh_failed_hint(),\n                            )));\n                        }\n                    }\n                }\n                let hint = unauthorized_session_hint(self.auth.oauth_configured);\n                return Err(StreamableSendError::Other(anyhow::anyhow!(\n                    \"MCP server {} rejected the request with {status}; the session is no longer accepted. {hint}\",\n                    mask_url_secrets(&self.url),\n                )));\n            }\n\n            if !status.is_success() {\n                let body_excerpt = bounded_body_excerpt(response, ERROR_BODY_PREVIEW_BYTES).await;\n                let stale_session = self.session_id.is_some()\n                    && is_streamable_http_stale_session_status(status, &body_excerpt);","sourceCodeStart":101,"sourceCodeEnd":137,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/mcp/streamable_http.rs#L101-L137","documentation":"When an MCP Streamable HTTP POST is rejected with an auth-related status, the client first attempts to force-refresh the OAuth session and retry. If the refresh itself fails, the original rejection and the refresh error are combined into this message with a hint, so the developer knows both that the server refused the request and why the automatic recovery could not proceed.","triggerScenarios":"send() receives a 401 (or similar auth rejection) on the POST to the MCP server, calls oauth.force_refresh(), and the refresh fails (token endpoint unreachable, refresh token revoked/expired, client credentials invalid).","commonSituations":"Refresh token revoked by the identity provider; OAuth token endpoint down or misconfigured; network change broke access to the IdP; expired session after long offline use.","solutions":["Re-authenticate with the MCP server (run the OAuth login flow) to obtain fresh tokens","Check reachability and configuration of the OAuth token endpoint","Verify the refresh token/client credentials are still valid with the identity provider","Retry after network connectivity to the IdP is restored"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"match client.send(request).await {\n    Err(e) if e.to_string().contains(\"refreshing the OAuth session failed\") => {\n        // automatic refresh failed; prompt a full re-authentication flow\n        reauthenticate(server)?;\n    }\n    other => other?,\n}","preventionTips":["Keep the OAuth token endpoint reachable and tested in your environment","Re-authenticate periodically instead of relying solely on refresh tokens","Watch for IdP-side revocation (password change, admin revoke) that invalidates refresh tokens"],"tags":["oauth","http","token-refresh","mcp","authentication"],"backgroundTag":"oauth-token-exchange-failed","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}