siyuan-note/siyuan · error
OAuth authorization server metadata not found
Error message
OAuth authorization server metadata not found
What it means
GetAuthServerMetadata returned no error but also a nil metadata object. The library treats a missing metadata document as fatal because the whole flow (endpoints, PKCE support, registration endpoint) depends on it. This catches servers that return 200 with an empty/unparseable body in a way that yields nil instead of an error.
Solutions
- Confirm the authorization server publishes RFC 8414 metadata at /.well-known/oauth-authorization-server and that it returns a JSON document
- Correct the authorization_servers URL in the protected-resource metadata
- Upgrade or reconfigure the IdP so discovery metadata is enabled
- Clear any cached/broken protected-resource metadata (discoverProtectedResource output) and retry
Defensive patterns
Strategy: validation
Validate before calling
meta, err := auth.GetAuthServerMetadata(ctx, authServerURL, http.DefaultClient)
if err != nil || meta == nil {
return errors.New("authorization server metadata unavailable")
} Type guard
if asm == nil {
return errors.New("OAuth authorization server metadata not found")
} Try / catch
if err := h.Authorize(ctx, req, resp); err != nil && strings.Contains(err.Error(), "metadata not found") {
promptUserToVerifyIdPDiscovery()
} Prevention
- Confirm the IdP serves non-empty RFC 8414 metadata before registering the MCP server
- Avoid bare-domain issuer URLs without a discovery route
- Watch for wildcard routes that answer 200 with empty bodies on well-known paths
When it happens
Trigger: Authorize calls GetAuthServerMetadata on prm.AuthorizationServers[0] and receives (nil, nil) — e.g. the discovery helper resolves no metadata for the issuer URL without treating it as an error.
Common situations: IdP serves an empty 200 for the well-known URL; a misconfigured wildcard route returns an empty page; issuer URL is a bare domain with no metadata route; OIDC discovery disabled on the server.
Understand the failure class
Background: "empty response", "returned no data", "empty embeddings": what HTTP 200-with-empty-body errors mean across libraries — this error's family across 36 libraries.
Related errors
- discover OAuth authorization server
- OAuth authorization server does not support the…
- OAuth authorization server does not support the…
- OAuth protected resource metadata has no authorization…
- OAuth protected resource metadata not found
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/8732c50d6b653d71.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/mcp/client/oauth.go:217
if interactive {
defer func() {
if retErr != nil && !errors.Is(retErr, context.Canceled) {
setMCPRuntimeStateForContext(ctx, h.server.ID, "authorization_required", 0, retErr.Error(), "")
}
}()
}
prm, err := discoverProtectedResource(ctx, challenges, req.URL.String(), h.client)
if err != nil {
return err
}
asm, err := auth.GetAuthServerMetadata(ctx, prm.AuthorizationServers[0], h.client)
if err != nil {
return fmt.Errorf("discover OAuth authorization server: %w", err)
}
if asm == nil {
return fmt.Errorf("OAuth authorization server metadata not found")
}
credential, hasCredential := getOAuthCredential(h.server.ID, h.server.URL)
if hasCredential && credential.Issuer == asm.Issuer {
credential.TokenEndpoint = asm.TokenEndpoint
credential.RevocationEndpoint = asm.RevocationEndpoint
}
if hasCredential && credential.Issuer == asm.Issuer && credential.RefreshToken != "" &&
challengeError != "insufficient_scope" && !credential.Rejected && !oauthClientRegistrationExpired(credential) {
refreshed, permanent, refreshErr := refreshOAuthCredential(ctx, h.client, credential)
if refreshErr == nil {
if saveErr := putOAuthCredential(refreshed); saveErr != nil {
logging.LogWarnf("mcp oauth: save refreshed credentials failed: %s", saveErr)
}
h.sourceMu.Lock()
h.source = &storedOAuthTokenSource{credential: refreshed, client: h.client}
h.sourceMu.Unlock()
setMCPRuntimeStateForContext(ctx, h.server.ID, "oauth_retrying", 0, "", "")
return nilView on GitHub (pinned to 9f775e8a12)