{"record":{"id":"edd75cb8bd37fdb1","repo":"siyuan-note/siyuan","slug":"oauth-authorization-server-does-not-support-the-au-edd75c","errorCode":null,"errorMessage":"OAuth authorization server does not support the authorization code grant","messagePattern":"OAuth authorization server does not support the authorization code grant","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/mcp/client/oauth.go","lineNumber":258,"sourceCode":"\t\tcredential.AccessToken = \"\"\n\t\tcredential.RefreshToken = \"\"\n\t\tcredential.Expiry = time.Time{}\n\t\tif saveErr := putOAuthCredential(credential); saveErr != nil {\n\t\t\tlogging.LogWarnf(\"mcp oauth: clear invalid credentials failed: %s\", saveErr)\n\t\t}\n\t}\n\tif !interactive {\n\t\tsetMCPRuntimeStateForContext(ctx, h.server.ID, \"authorization_required\", 0, \"\", \"\")\n\t\treturn errOAuthAuthorizationRequired\n\t}\n\tif !slices.Contains(asm.CodeChallengeMethodsSupported, \"S256\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support PKCE S256\")\n\t}\n\tif len(asm.ResponseTypesSupported) > 0 && !slices.Contains(asm.ResponseTypesSupported, \"code\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support the authorization code response type\")\n\t}\n\tif len(asm.GrantTypesSupported) > 0 && !slices.Contains(asm.GrantTypesSupported, \"authorization_code\") {\n\t\treturn fmt.Errorf(\"OAuth authorization server does not support the authorization code grant\")\n\t}\n\n\tflowID := reusableOAuthFlowID(credential)\n\tif flowID == \"\" {\n\t\tflowID, err = secureRandomString(24)\n\t\tif err != nil {\n\t\t\treturn err\n\t\t}\n\t}\n\tstate, err := secureRandomString(24)\n\tif err != nil {\n\t\treturn err\n\t}\n\tcallbackURL := fmt.Sprintf(\"http://127.0.0.1:%s/api/ai/mcp/oauth/callback/%s\", util.ServerPort, flowID)\n\tscopes := append([]string(nil), prm.ScopesSupported...)\n\tif len(scopes) == 0 {\n\t\tscopes = append(scopes, asm.ScopesSupported...)\n\t}","sourceCodeStart":240,"sourceCodeEnd":276,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/mcp/client/oauth.go#L240-L276","documentation":"The authorization server advertises GrantTypesSupported and it does not include \"authorization_code\". Since the client exclusively uses the authorization-code grant (optionally with refresh_token), such a server cannot complete MCP authorization and the flow is aborted.","triggerScenarios":"Interactive Authorize passes PKCE and response-type checks, but asm.GrantTypesSupported is non-empty and omits \"authorization_code\" — e.g. metadata lists only [\"client_credentials\", \"refresh_token\"].","commonSituations":"IdP restricted to machine-to-machine grants (client_credentials only); admin disabled the authorization code grant in the IdP policy; metadata misconfiguration.","solutions":["Enable the authorization_code grant type on the authorization server / client policy","Correct the grant_types_supported metadata if the grant is actually available","Choose an OAuth provider configuration that supports user-interactive authorization code grants, as MCP requires"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"if len(asm.GrantTypesSupported) > 0 && !slices.Contains(asm.GrantTypesSupported, \"authorization_code\") {\n    return errors.New(\"IdP does not allow the authorization code grant\")\n}","typeGuard":null,"tryCatchPattern":"if err := h.Authorize(ctx, req, resp); err != nil && strings.Contains(err.Error(), \"authorization code grant\") {\n    reportIdPConfigIssue(err)\n}","preventionTips":["Check grant_types_supported includes authorization_code before connecting","Do not configure MCP connections against client_credentials-only IdP policies","Validate metadata after any IdP grant-policy change"],"tags":["oauth","mcp","compatibility","metadata"],"backgroundTag":"unsupported-operation","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}