{"record":{"id":"e6eb0b4fba09747e","repo":"siyuan-note/siyuan","slug":"oauth-authorization-server-does-not-support-the-au","errorCode":null,"errorMessage":"OAuth authorization server does not support the authorization code response type","messagePattern":"OAuth authorization server does not support the authorization code response type","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":255,"sourceCode":"\t\tif !permanent {\n\t\t\treturn fmt.Errorf(\"refresh OAuth credentials: %w\", refreshErr)\n\t\t}\n\t\tcredential.AccessToken = \"\"\n\t\tcredential.RefreshToken = \"\"\n\t\tcredential.Expiry = time.Time{}\n\t\tif saveErr := putOAuthCredential(credential); saveErr != nil {\n\t\t\tlogging.LogWarnf(\"mcp oauth: clear invalid credentials failed: %s\", saveErr)\n\t\t}\n\t}\n\tif !interactive {\n\t\tsetMCPRuntimeStateForContext(ctx, h.server.ID, \"authorization_required\", 0, \"\", \"\")\n\t\treturn errOAuthAuthorizationRequired\n\t}\n\tif !slices.Contains(asm.CodeChallengeMethodsSupported, \"S256\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support PKCE S256\")\n\t}\n\tif len(asm.ResponseTypesSupported) > 0 && !slices.Contains(asm.ResponseTypesSupported, \"code\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support the authorization code response type\")\n\t}\n\tif len(asm.GrantTypesSupported) > 0 && !slices.Contains(asm.GrantTypesSupported, \"authorization_code\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support the authorization code grant\")\n\t}\n\n\tflowID := reusableOAuthFlowID(credential)\n\tif flowID == \"\" {\n\t\tflowID, err = secureRandomString(24)\n\t\tif err != nil {\n\t\t\treturn err\n\t\t}\n\t}\n\tstate, err := secureRandomString(24)\n\tif err != nil {\n\t\treturn err\n\t}\n\tcallbackURL := fmt.Sprintf(\"http://127.0.0.1:%s/api/ai/mcp/oauth/callback/%s\", util.ServerPort, flowID)\n\tscopes := append([]string(nil), prm.ScopesSupported...)","sourceCodeStart":237,"sourceCodeEnd":273,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L237-L273","documentation":"The authorization server advertises ResponseTypesSupported and it does not contain \"code\". The MCP client only performs the authorization-code flow, so a server that (for example) only offers the implicit flow is incompatible and authorization is aborted before building the consent URL.","triggerScenarios":"Interactive Authorize passes the PKCE check but asm.ResponseTypesSupported is non-empty and lacks \"code\" — e.g. metadata lists only [\"token\"] (implicit-only server).","commonSituations":"IdP locked down to implicit flow for legacy SPAs; admin disabled the authorization_code grant type server-side; homemade OAuth metadata misconfigured.","solutions":["Enable the authorization_code response type (grant type) for clients on the authorization server","Fix the server's metadata to include \"code\" in response_types_supported if the grant is actually supported","Use an IdP or client configuration that supports the authorization code flow, as required by MCP"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"if len(asm.ResponseTypesSupported) > 0 && !slices.Contains(asm.ResponseTypesSupported, \"code\") {\n    return errors.New(\"IdP does not allow authorization_code response type\")\n}","typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, req, resp); err != nil && strings.Contains(err.Error(), \"authorization code response type\") {\n    reportIdPConfigIssue(err)\n}","preventionTips":["Check response_types_supported in the metadata before connecting","Do not restrict the IdP to implicit-only flows for MCP use","Re-check metadata after IdP hardening changes"],"tags":["oauth","mcp","compatibility","metadata"],"backgroundTag":"unsupported-operation","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}