siyuan-note/siyuan · error

OAuth authorization server does not support the…

Error message

OAuth authorization server does not support the authorization code response type

What it means

The authorization server advertises ResponseTypesSupported and it does not contain "code". The MCP client only performs the authorization-code flow, so a server that (for example) only offers the implicit flow is incompatible and authorization is aborted before building the consent URL.

Solutions

  1. Enable the authorization_code response type (grant type) for clients on the authorization server
  2. Fix the server's metadata to include "code" in response_types_supported if the grant is actually supported
  3. Use an IdP or client configuration that supports the authorization code flow, as required by MCP
Defensive patterns

Strategy: validation

Validate before calling

if len(asm.ResponseTypesSupported) > 0 && !slices.Contains(asm.ResponseTypesSupported, "code") {
    return errors.New("IdP does not allow authorization_code response type")
}

Try / catch

if err := h.Authorize(ctx, req, resp); err != nil && strings.Contains(err.Error(), "authorization code response type") {
    reportIdPConfigIssue(err)
}

Prevention

When it happens

Trigger: Interactive Authorize passes the PKCE check but asm.ResponseTypesSupported is non-empty and lacks "code" — e.g. metadata lists only ["token"] (implicit-only server).

Common situations: IdP locked down to implicit flow for legacy SPAs; admin disabled the authorization_code grant type server-side; homemade OAuth metadata misconfigured.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/e6eb0b4fba09747e. Report an issue: GitHub.

Appendix: source

Thrown at kernel/mcp/client/oauth.go:255

		if !permanent {
			return fmt.Errorf("refresh OAuth credentials: %w", refreshErr)
		}
		credential.AccessToken = ""
		credential.RefreshToken = ""
		credential.Expiry = time.Time{}
		if saveErr := putOAuthCredential(credential); saveErr != nil {
			logging.LogWarnf("mcp oauth: clear invalid credentials failed: %s", saveErr)
		}
	}
	if !interactive {
		setMCPRuntimeStateForContext(ctx, h.server.ID, "authorization_required", 0, "", "")
		return errOAuthAuthorizationRequired
	}
	if !slices.Contains(asm.CodeChallengeMethodsSupported, "S256") {
		return fmt.Errorf("OAuth authorization server does not support PKCE S256")
	}
	if len(asm.ResponseTypesSupported) > 0 && !slices.Contains(asm.ResponseTypesSupported, "code") {
		return fmt.Errorf("OAuth authorization server does not support the authorization code response type")
	}
	if len(asm.GrantTypesSupported) > 0 && !slices.Contains(asm.GrantTypesSupported, "authorization_code") {
		return fmt.Errorf("OAuth authorization server does not support the authorization code grant")
	}

	flowID := reusableOAuthFlowID(credential)
	if flowID == "" {
		flowID, err = secureRandomString(24)
		if err != nil {
			return err
		}
	}
	state, err := secureRandomString(24)
	if err != nil {
		return err
	}
	callbackURL := fmt.Sprintf("http://127.0.0.1:%s/api/ai/mcp/oauth/callback/%s", util.ServerPort, flowID)
	scopes := append([]string(nil), prm.ScopesSupported...)

View on GitHub (pinned to 9f775e8a12)