upstash/context7 · error

Authentication discovery was redirected. Pass the final…

Error message

Authentication discovery was redirected. Pass the final deployment URL instead of ${deployment.baseUrl}.

What it means

Thrown by getOnPremMcpAuthStatus when the GET to `${deployment.baseUrl}/api/auth/mcp` (fetched with redirect: 'manual') returns a 3xx redirect. Because authentication discovery follows redirects would hide a misconfigured base URL, the CLI fails fast and asks for the final deployment URL.

Solutions

  1. Follow the redirect manually (curl -I) and re-run setup with the final destination URL.
  2. Prefer the https:// canonical host if the redirect was scheme upgrade.
  3. Fix reverse-proxy/ingress rewrite rules so the configured URL is served directly without redirecting.

Example fix

// before
ctx7 setup --url http://my-onprem.internal   # 301 -> https://my-onprem.internal

// after
curl -sI http://my-onprem.internal/api/auth/mcp   # note Location header
ctx7 setup --url https://my-onprem.internal
Defensive patterns

Strategy: validation

Validate before calling

// Pre-check that the discovery endpoint is served without a redirect:
const res = await fetch(`${base}/api/auth/mcp`, { redirect: 'manual' });
if (res.status >= 300 && res.status < 400) {
  throw new Error(`Use the final URL: ${res.headers.get('location')}`);
}

Try / catch

try {
  const enabled = await getOnPremMcpAuthStatus(deployment);
} catch (e) {
  if ((e as Error).message.includes('redirected')) {
    console.error('Resolve the redirect (curl -I) and pass the final https URL.');
  }
}

Prevention

When it happens

Trigger: getOnPremMcpAuthStatus(deployment) is called (via resolveAuth) for a custom deployment and the auth discovery endpoint responds with status 300-399 — typically an HTTP→HTTPS or host rewrite redirect.

Common situations: On-prem server redirects http:// to https://; a load balancer or ingress rewrites to a canonical hostname or adds/removes a path prefix; a trailing-slash redirect at the proxy.

Understand the failure class

Related errors


AI-assisted analysis of upstash/context7@4416fb855b (2026-09-16). Data as JSON: /api/errors/f7adb960225c0022. Report an issue: GitHub.

Appendix: source

Thrown at packages/cli/src/setup/deployment.ts:63

export function getMcpUrl(deployment: SetupDeployment, auth: AuthOptions): string {
  if (deployment.kind === "hosted") {
    return auth.mode === "oauth"
      ? `${HOSTED_MCP_BASE_URL}/mcp/oauth`
      : `${HOSTED_MCP_BASE_URL}/mcp`;
  }
  return `${deployment.baseUrl}/mcp`;
}

export async function getOnPremMcpAuthStatus(deployment: CustomSetupDeployment): Promise<boolean> {
  const response = await fetch(`${deployment.baseUrl}/api/auth/mcp`, {
    headers: { Accept: "application/json" },
    redirect: "manual",
    signal: AbortSignal.timeout(10_000),
  });

  if (response.status >= 300 && response.status < 400) {
    throw new Error(
      `Authentication discovery was redirected. Pass the final deployment URL instead of ${deployment.baseUrl}.`
    );
  }

  if (!response.ok) {
    throw new Error(`HTTP ${response.status} from ${deployment.baseUrl}/api/auth/mcp`);
  }

  const body = (await response.json()) as { enabled?: unknown };
  if (typeof body.enabled !== "boolean") {
    throw new Error(`Invalid response from ${deployment.baseUrl}/api/auth/mcp`);
  }
  return body.enabled;
}

View on GitHub (pinned to 4416fb855b)