siyuan-note/siyuan · error
OAuth authorization server does not support a compatible…
Error message
OAuth authorization server does not support a compatible token endpoint authentication method
What it means
Dynamic client registration is about to run, but none of the token_endpoint_auth_methods_supported advertised by the authorization server is one the client can perform (preferredTokenAuthMethod returned empty for a non-empty list). The client supports a fixed set (e.g. none, client_secret_basic, client_secret_post) and refuses to register with an auth method it cannot use.
Solutions
- Reconfigure the authorization server to also allow client_secret_basic, client_secret_post, or none (public client) as token endpoint auth methods
- Use an IdP policy/profile that supports standard shared-secret or public-client authentication for native apps
- If forced onto strong auth methods, connect via a gateway/proxy IdP that accepts them and exposes standard methods
Defensive patterns
Strategy: validation
Validate before calling
if len(asm.TokenEndpointAuthMethodsSupported) > 0 && preferredTokenAuthMethod(asm.TokenEndpointAuthMethodsSupported) == "" {
return errors.New("IdP only offers token auth methods this client cannot perform")
} Try / catch
if err := h.Authorize(ctx, req, resp); err != nil && strings.Contains(err.Error(), "token endpoint authentication method") {
suggestIdPPolicyRelaxation(err)
} Prevention
- Inspect token_endpoint_auth_methods_supported in metadata before connecting
- Enable client_secret_basic / client_secret_post / none in the IdP policy for native apps
- Avoid IdP profiles that mandate mTLS or private_key_jwt for MCP clients
When it happens
Trigger: Interactive Authorize with canReuseRegistration == false, a non-empty asm.RegistrationEndpoint, and asm.TokenEndpointAuthMethodsSupported containing only methods outside the client's supported set (e.g. ["tls_client_auth", "private_key_jwt"]).
Common situations: Enterprise IdPs mandating mutual-TLS or JWT-based client authentication; hardening policies that disabled client_secret_basic/post and unauthenticated (public) clients.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- OAuth authorization server does not support dynamic client…
- OAuth authorization server does not support PKCE S256
- OAuth authorization server does not support the…
- OAuth authorization server does not support the…
- register OAuth client
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/bbff901229eac6be.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/mcp/client/oauth.go:291
scopes := append([]string(nil), prm.ScopesSupported...)
if len(scopes) == 0 {
scopes = append(scopes, asm.ScopesSupported...)
}
for _, scope := range strings.Fields(bearerChallengeParam(challenges, "scope")) {
if !slices.Contains(scopes, scope) {
scopes = append(scopes, scope)
}
}
registrationCredential := credential
canReuseRegistration := hasCredential && credential.Issuer == asm.Issuer && credential.RedirectURL == callbackURL &&
credential.ClientID != "" && !oauthClientRegistrationExpired(credential) && oauthScopesContain(credential.Scopes, scopes)
if !canReuseRegistration {
if asm.RegistrationEndpoint == "" {
return fmt.Errorf("OAuth authorization server does not support dynamic client registration")
}
tokenAuthMethod := preferredTokenAuthMethod(asm.TokenEndpointAuthMethodsSupported)
if len(asm.TokenEndpointAuthMethodsSupported) > 0 && tokenAuthMethod == "" {
return fmt.Errorf("OAuth authorization server does not support a compatible token endpoint authentication method")
}
grantTypes := []string{"authorization_code"}
if len(asm.GrantTypesSupported) == 0 || slices.Contains(asm.GrantTypesSupported, "refresh_token") {
grantTypes = append(grantTypes, "refresh_token")
}
registration, registerErr := oauthex.RegisterClient(ctx, asm.RegistrationEndpoint, &oauthex.ClientRegistrationMetadata{
RedirectURIs: []string{callbackURL},
TokenEndpointAuthMethod: tokenAuthMethod,
GrantTypes: grantTypes,
ResponseTypes: []string{"code"},
ClientName: "SiYuan",
Scope: strings.Join(scopes, " "),
ApplicationType: "native",
}, h.client)
if registerErr != nil {
return fmt.Errorf("register OAuth client: %w", registerErr)
}
registrationCredential = oauthCredential{View on GitHub (pinned to 9f775e8a12)