siyuan-note/siyuan · error
OAuth client registration returned an unsupported token…
Error message
OAuth client registration returned an unsupported token endpoint authentication method
What it means
During dynamic OAuth client registration (RFC 7591), the authorization server's registration response may echo back a token_endpoint_auth_method. This library only supports 'none', 'client_secret_post', and 'client_secret_basic' (see isSupportedTokenAuthMethod). If the server registers the client with any other method (e.g. 'client_secret_jwt' or 'private_key_jwt'), Authorize aborts rather than attempting a token exchange it cannot perform.
Solutions
- Use an authorization server that registers clients with public-client compatible methods (none, client_secret_post, or client_secret_basic)
- Pre-register the client manually with a compatible token_endpoint_auth_method so dynamic registration is skipped (canReuseRegistration path)
- If you control the server, change its registration policy/default token_endpoint_auth_method to client_secret_basic or none
- File/patch an upstream change to add support for the required auth method (e.g. private_key_jwt)
Example fix
// before (server-issued registration response)
{"client_id":"...","token_endpoint_auth_method":"private_key_jwt"}
// after: server must return a supported method, e.g.
{"client_id":"...","token_endpoint_auth_method":"client_secret_basic"} Defensive patterns
Strategy: validation
Validate before calling
// Before starting the flow, check the AS metadata advertises a compatible method
if !slices.ContainsAny(asm.TokenEndpointAuthMethodsSupported, []string{"none", "client_secret_post", "client_secret_basic"}) {
return fmt.Errorf("server supports none of the client's token auth methods")
} Try / catch
if err := h.Authorize(ctx, interactive); err != nil {
if strings.Contains(err.Error(), "unsupported token endpoint authentication method") {
// surface guidance: server requires JWT/private-key client auth; use a compatible IdP
}
} Prevention
- Verify the IdP's token_endpoint_auth_methods_supported includes a public-client method before enabling OAuth for the MCP server
- Prefer IdPs known to register native clients as public (token_endpoint_auth_method=none)
- Test dynamic registration with a quick curl POST before wiring up the client
When it happens
Trigger: Authorize() performs dynamic client registration (RegisterClient) and the registration response contains a TokenEndpointAuthMethod that is not empty and not one of none/client_secret_post/client_secret_basic.
Common situations: Connecting to an enterprise/legacy OAuth server whose registration endpoint defaults clients to JWT-based authentication methods (private_key_jwt, client_secret_jwt, or TLS client auth) that this native public client cannot use.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- configuration is not initialized
- discover OAuth authorization server
- exchange OAuth authorization code
- mcp oauth authorization required
- OAuth authorization failed
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/40a6cd6d44034bce.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/mcp/client/oauth.go:332
ResourceMetadataURL: prm.MetadataURL,
RedirectURL: callbackURL,
ClientID: registration.ClientID,
ClientSecret: registration.ClientSecret,
ClientSecretExpiry: registration.ClientSecretExpiresAt,
TokenEndpoint: asm.TokenEndpoint,
RevocationEndpoint: asm.RevocationEndpoint,
TokenAuthMethod: registration.TokenEndpointAuthMethod,
Scopes: scopes,
}
if registrationCredential.TokenAuthMethod == "" {
if registration.ClientSecret == "" {
registrationCredential.TokenAuthMethod = "none"
} else {
registrationCredential.TokenAuthMethod = "client_secret_basic"
}
}
if !isSupportedTokenAuthMethod(registrationCredential.TokenAuthMethod) {
return fmt.Errorf("OAuth client registration returned an unsupported token endpoint authentication method")
}
if err = putOAuthCredential(registrationCredential); err != nil {
return fmt.Errorf("save OAuth client registration: %w", err)
}
}
authMethod := registrationCredential.TokenAuthMethod
if authMethod == "" {
if registrationCredential.ClientSecret == "" {
authMethod = "none"
} else {
authMethod = "client_secret_basic"
}
}
config := &oauth2.Config{
ClientID: registrationCredential.ClientID,
ClientSecret: registrationCredential.ClientSecret,
RedirectURL: callbackURL,View on GitHub (pinned to 9f775e8a12)