upstash/context7 · error
Authentication discovery was redirected. Pass the final…
Error message
Authentication discovery was redirected. Pass the final deployment URL instead of ${deployment.baseUrl}. What it means
Thrown by getOnPremMcpAuthStatus when the GET to `${deployment.baseUrl}/api/auth/mcp` (fetched with redirect: 'manual') returns a 3xx redirect. Because authentication discovery follows redirects would hide a misconfigured base URL, the CLI fails fast and asks for the final deployment URL.
Solutions
- Follow the redirect manually (curl -I) and re-run setup with the final destination URL.
- Prefer the https:// canonical host if the redirect was scheme upgrade.
- Fix reverse-proxy/ingress rewrite rules so the configured URL is served directly without redirecting.
Example fix
// before ctx7 setup --url http://my-onprem.internal # 301 -> https://my-onprem.internal // after curl -sI http://my-onprem.internal/api/auth/mcp # note Location header ctx7 setup --url https://my-onprem.internal
Defensive patterns
Strategy: validation
Validate before calling
// Pre-check that the discovery endpoint is served without a redirect:
const res = await fetch(`${base}/api/auth/mcp`, { redirect: 'manual' });
if (res.status >= 300 && res.status < 400) {
throw new Error(`Use the final URL: ${res.headers.get('location')}`);
} Try / catch
try {
const enabled = await getOnPremMcpAuthStatus(deployment);
} catch (e) {
if ((e as Error).message.includes('redirected')) {
console.error('Resolve the redirect (curl -I) and pass the final https URL.');
}
} Prevention
- Configure the canonical https URL of the deployment, not a redirecting alias.
- Check ingress/proxy rules for rewrites on the configured hostname.
- Verify with `curl -sI <base>/api/auth/mcp` expecting 200, not 3xx.
When it happens
Trigger: getOnPremMcpAuthStatus(deployment) is called (via resolveAuth) for a custom deployment and the auth discovery endpoint responds with status 300-399 — typically an HTTP→HTTPS or host rewrite redirect.
Common situations: On-prem server redirects http:// to https://; a load balancer or ingress rewrites to a canonical hostname or adds/removes a path prefix; a trailing-slash redirect at the proxy.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- HTTP from /api/auth/mcp
- errorBody.error ?? "http_error"
- Failed to fetch
- Failed to fetch user info
- network_error
AI-assisted analysis of upstash/context7@4416fb855b (2026-09-16).
Data as JSON: /api/errors/f7adb960225c0022.
Report an issue: GitHub.
Appendix: source
Thrown at packages/cli/src/setup/deployment.ts:63
export function getMcpUrl(deployment: SetupDeployment, auth: AuthOptions): string {
if (deployment.kind === "hosted") {
return auth.mode === "oauth"
? `${HOSTED_MCP_BASE_URL}/mcp/oauth`
: `${HOSTED_MCP_BASE_URL}/mcp`;
}
return `${deployment.baseUrl}/mcp`;
}
export async function getOnPremMcpAuthStatus(deployment: CustomSetupDeployment): Promise<boolean> {
const response = await fetch(`${deployment.baseUrl}/api/auth/mcp`, {
headers: { Accept: "application/json" },
redirect: "manual",
signal: AbortSignal.timeout(10_000),
});
if (response.status >= 300 && response.status < 400) {
throw new Error(
`Authentication discovery was redirected. Pass the final deployment URL instead of ${deployment.baseUrl}.`
);
}
if (!response.ok) {
throw new Error(`HTTP ${response.status} from ${deployment.baseUrl}/api/auth/mcp`);
}
const body = (await response.json()) as { enabled?: unknown };
if (typeof body.enabled !== "boolean") {
throw new Error(`Invalid response from ${deployment.baseUrl}/api/auth/mcp`);
}
return body.enabled;
}
View on GitHub (pinned to 4416fb855b)