siyuan-note/siyuan · error

OAuth client registration returned an unsupported token…

Error message

OAuth client registration returned an unsupported token endpoint authentication method

What it means

During dynamic OAuth client registration (RFC 7591), the authorization server's registration response may echo back a token_endpoint_auth_method. This library only supports 'none', 'client_secret_post', and 'client_secret_basic' (see isSupportedTokenAuthMethod). If the server registers the client with any other method (e.g. 'client_secret_jwt' or 'private_key_jwt'), Authorize aborts rather than attempting a token exchange it cannot perform.

Solutions

  1. Use an authorization server that registers clients with public-client compatible methods (none, client_secret_post, or client_secret_basic)
  2. Pre-register the client manually with a compatible token_endpoint_auth_method so dynamic registration is skipped (canReuseRegistration path)
  3. If you control the server, change its registration policy/default token_endpoint_auth_method to client_secret_basic or none
  4. File/patch an upstream change to add support for the required auth method (e.g. private_key_jwt)

Example fix

// before (server-issued registration response)
{"client_id":"...","token_endpoint_auth_method":"private_key_jwt"}
// after: server must return a supported method, e.g.
{"client_id":"...","token_endpoint_auth_method":"client_secret_basic"}
Defensive patterns

Strategy: validation

Validate before calling

// Before starting the flow, check the AS metadata advertises a compatible method
if !slices.ContainsAny(asm.TokenEndpointAuthMethodsSupported, []string{"none", "client_secret_post", "client_secret_basic"}) {
    return fmt.Errorf("server supports none of the client's token auth methods")
}

Try / catch

if err := h.Authorize(ctx, interactive); err != nil {
    if strings.Contains(err.Error(), "unsupported token endpoint authentication method") {
        // surface guidance: server requires JWT/private-key client auth; use a compatible IdP
    }
}

Prevention

When it happens

Trigger: Authorize() performs dynamic client registration (RegisterClient) and the registration response contains a TokenEndpointAuthMethod that is not empty and not one of none/client_secret_post/client_secret_basic.

Common situations: Connecting to an enterprise/legacy OAuth server whose registration endpoint defaults clients to JWT-based authentication methods (private_key_jwt, client_secret_jwt, or TLS client auth) that this native public client cannot use.

Understand the failure class

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/40a6cd6d44034bce. Report an issue: GitHub.

Appendix: source

Thrown at kernel/mcp/client/oauth.go:332

			ResourceMetadataURL: prm.MetadataURL,
			RedirectURL:         callbackURL,
			ClientID:            registration.ClientID,
			ClientSecret:        registration.ClientSecret,
			ClientSecretExpiry:  registration.ClientSecretExpiresAt,
			TokenEndpoint:       asm.TokenEndpoint,
			RevocationEndpoint:  asm.RevocationEndpoint,
			TokenAuthMethod:     registration.TokenEndpointAuthMethod,
			Scopes:              scopes,
		}
		if registrationCredential.TokenAuthMethod == "" {
			if registration.ClientSecret == "" {
				registrationCredential.TokenAuthMethod = "none"
			} else {
				registrationCredential.TokenAuthMethod = "client_secret_basic"
			}
		}
		if !isSupportedTokenAuthMethod(registrationCredential.TokenAuthMethod) {
			return fmt.Errorf("OAuth client registration returned an unsupported token endpoint authentication method")
		}
		if err = putOAuthCredential(registrationCredential); err != nil {
			return fmt.Errorf("save OAuth client registration: %w", err)
		}
	}

	authMethod := registrationCredential.TokenAuthMethod
	if authMethod == "" {
		if registrationCredential.ClientSecret == "" {
			authMethod = "none"
		} else {
			authMethod = "client_secret_basic"
		}
	}
	config := &oauth2.Config{
		ClientID:     registrationCredential.ClientID,
		ClientSecret: registrationCredential.ClientSecret,
		RedirectURL:  callbackURL,

View on GitHub (pinned to 9f775e8a12)