siyuan-note/siyuan · error
OAuth authorization server does not support the…
Error message
OAuth authorization server does not support the authorization code response type
What it means
The authorization server advertises ResponseTypesSupported and it does not contain "code". The MCP client only performs the authorization-code flow, so a server that (for example) only offers the implicit flow is incompatible and authorization is aborted before building the consent URL.
Solutions
- Enable the authorization_code response type (grant type) for clients on the authorization server
- Fix the server's metadata to include "code" in response_types_supported if the grant is actually supported
- Use an IdP or client configuration that supports the authorization code flow, as required by MCP
Defensive patterns
Strategy: validation
Validate before calling
if len(asm.ResponseTypesSupported) > 0 && !slices.Contains(asm.ResponseTypesSupported, "code") {
return errors.New("IdP does not allow authorization_code response type")
} Try / catch
if err := h.Authorize(ctx, req, resp); err != nil && strings.Contains(err.Error(), "authorization code response type") {
reportIdPConfigIssue(err)
} Prevention
- Check response_types_supported in the metadata before connecting
- Do not restrict the IdP to implicit-only flows for MCP use
- Re-check metadata after IdP hardening changes
When it happens
Trigger: Interactive Authorize passes the PKCE check but asm.ResponseTypesSupported is non-empty and lacks "code" — e.g. metadata lists only ["token"] (implicit-only server).
Common situations: IdP locked down to implicit flow for legacy SPAs; admin disabled the authorization_code grant type server-side; homemade OAuth metadata misconfigured.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- OAuth authorization server does not support the…
- OAuth authorization server does not support a compatible…
- OAuth authorization server does not support dynamic client…
- OAuth authorization server does not support PKCE S256
- OAuth authorization server metadata not found
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/e6eb0b4fba09747e.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/mcp/client/oauth.go:255
if !permanent {
return fmt.Errorf("refresh OAuth credentials: %w", refreshErr)
}
credential.AccessToken = ""
credential.RefreshToken = ""
credential.Expiry = time.Time{}
if saveErr := putOAuthCredential(credential); saveErr != nil {
logging.LogWarnf("mcp oauth: clear invalid credentials failed: %s", saveErr)
}
}
if !interactive {
setMCPRuntimeStateForContext(ctx, h.server.ID, "authorization_required", 0, "", "")
return errOAuthAuthorizationRequired
}
if !slices.Contains(asm.CodeChallengeMethodsSupported, "S256") {
return fmt.Errorf("OAuth authorization server does not support PKCE S256")
}
if len(asm.ResponseTypesSupported) > 0 && !slices.Contains(asm.ResponseTypesSupported, "code") {
return fmt.Errorf("OAuth authorization server does not support the authorization code response type")
}
if len(asm.GrantTypesSupported) > 0 && !slices.Contains(asm.GrantTypesSupported, "authorization_code") {
return fmt.Errorf("OAuth authorization server does not support the authorization code grant")
}
flowID := reusableOAuthFlowID(credential)
if flowID == "" {
flowID, err = secureRandomString(24)
if err != nil {
return err
}
}
state, err := secureRandomString(24)
if err != nil {
return err
}
callbackURL := fmt.Sprintf("http://127.0.0.1:%s/api/ai/mcp/oauth/callback/%s", util.ServerPort, flowID)
scopes := append([]string(nil), prm.ScopesSupported...)View on GitHub (pinned to 9f775e8a12)