OAuth redirect URI port mismatch breaks login to most MCP servers
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 52/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- node.js
- Área
- authentication, cli
Línea de trabajo
Start with the /mcp add OAuth flow and inspect the published client-metadata.json alongside the loopback listener in the shipped SEA binary. Compare the advertised redirect URI with the runtime redirect_uri, then verify the chosen behavior against a strict-matching MCP OAuth server and the RFC 8252 loopback requirement.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
OAuth redirect URI port mismatch breaks login to most MCP servers
Summary
copilot CLI publishes a CIMD (Client ID Metadata Document) that declares a
single loopback redirect URI on a fixed port, but at runtime the CLI binds an
ephemeral loopback port and sends that port in the OAuth redirect_uri
parameter. GitHub's own OAuth server accepts the mismatch (per RFC 8252 §7.3
loopback matching), but many third-party OAuth servers — including
Entra/Azure-fronted MCP servers — do strict string matching against the
registered redirect_uris and reject the request.
The result is that authentication fails against almost every non-GitHub MCP
server users try to connect. Claude Code and Codex CLI are not affected in
the same environments.
Environment
- CLI version:
GitHub Copilot CLI 1.0.88 - OS: macOS (arm64)
- Install: Homebrew cask
copilot-cli(SEA binary)
Reproducer
- Configure any MCP server whose OAuth authorize endpoint validates
redirect_uriby exact match against the CIMD'sredirect_urislist.
(Entra/Azure-fronted services typically behave this way.) - Trigger the OAuth flow from Copilot CLI:
/mcp add <server-url>(or however the server is registered), then log in. - The browser lands on the authorize endpoint, which returns:
{
"error": "invalid_request",
"error_description": "Redirect URI 'http://127.0.0.1:52752/' does not match CIMD redirect_uris.",
"state": "..."
}
The port (52752 above) changes on every attempt.
Expected behavior
The redirect_uri sent to the authorize endpoint should either:
- (a) match the port published in the CIMD, i.e.
http://127.0.0.1:33418/, so
strict-matching servers accept it; or - (b) rely on RFC 8252 §7.3 loopback matching and have the CIMD advertise
http://127.0.0.1/(no port), making clear to server implementers that
port-agnostic matching is expected.
Today it does neither: it publishes a specific port and then uses a different
one.
Actual behavior / root cause
The CLI's published metadata at
https://github.com/copilot/cli/client-metadata.json:
{
"client_id": "https://github.com/copilot/cli/client-metadata.json",
"client_name": "GitHub Copilot CLI",
"application_type": "native",
"redirect_uris": ["http://127.0.0.1:33418/"],
...
}
But the CLI's OAuth loopback listener is bound with port 0 (verifiable by
inspecting the SEA blob inside the shipped binary):
// Port 0 = let the OS pick a free ephemeral port. Bind to loopback only.
await new Promise((resolve) => server.listen(0, "127.0.0.1", resolve));
const address = server.address();
const port = typeof address === "object" && address ? address.port : 0;
The dynamically-assigned port then flows into the OAuth redirect_uri, which
never equals 33418.
Impact
- Blocks Copilot CLI from authenticating against most third-party MCP servers,
which is a large and growing set as MCP adoption widens. - Internal reports at multiple organisations indicate the same failure pattern
across every non-GitHub MCP they've tried, with Claude Code / Codex CLI
unaffected in the same environments. - Users have no clean local workaround. The one lever we found —
COPILOT_MCP_CIMD_CLIENT_ID_URLoverriding the CIMD document URL — requires
self-hosting a metadata file that enumerates every ephemeral loopback port,
which is fragile and requires the MCP server to dynamically trust arbitrary
CIMDs.
Suggested fixes (either is sufficient)
- Bind the published port. Change the listener to
server.listen(33418, "127.0.0.1", …)with a fallback strategy (retry with
an ephemeral port only if 33418 is in use, and clearly document the
fallback), so the common case matches the CIMD exactly. - Publish port-agnostic CIMD. Change
redirect_urisin
client-metadata.jsonto["http://127.0.0.1/"]and rely on the RFC 8252
§7.3 loopback rule. This shifts the responsibility to non-conformant OAuth
servers, which is arguably correct, but will not fix real-world usage until
those servers are updated.
Option 1 is the most defensive; option 2 is the most spec-pure. A combination
(bind 33418 first, publish 127.0.0.1/) would maximise interoperability.
References
- RFC 8252 §7.3 (Loopback Interface Redirection): loopback redirects SHOULD be
matched ignoring the port component. - OAuth 2.0 for Native Apps client identity metadata document (CIMD) spec.
Drafted with GitHub Copilot CLI.
- Lenguaje dominante
- Shell
- Estrellas
- 11.2k
- Forks
- 1.9k
- Merge medio
- 17 h 6 min
- PR fusionados (30 d)
- 5
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/copilot-cli
-
triage
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
github/copilot-cli#4963 ·
Los mantenedores suelen responder en 1 día
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
github/copilot-cli#4932 ·
Los mantenedores suelen responder en 1 día
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
github/copilot-cli#4909 ·
Los mantenedores suelen responder en 1 día
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
github/copilot-cli#4906 ·
Los mantenedores suelen responder en 1 día
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/copilot-cli#4848 ·
Los mantenedores suelen responder en 1 día
Todos los issues de github/copilot-cli
Issues similares
-
limine: new version 12.9.1Abiertoout-of-date
Dificultad 1/5 Menos de una hora Aptitud para principiantes 82/100
CachyOS/CachyOS-PKGBUILDS#1917 ·
Los mantenedores suelen responder en 1 día
-
package-update
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
bug needs triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
EmbarkStudios/cargo-about#323 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
vllm-project/vllm-metal#841 ·
Los mantenedores suelen responder en 1 día