Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

MCP OAuth: Figma token exchange fails with "Failed to parse server response" (distinct from #4870 / #4906)

Ouverte
#4,923 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
52/100
Type d'issue
Bug
Clarté
Plutôt claire
Activité
Active
Domaine
api, authentication

Piste de recherche

Start at the /mcp → figma → Authenticate flow and trace the token exchange against https://api.figma.com/v1/oauth/token. Capture the response status, headers, and body at the parse failure, then compare it with the OAuth client’s expected response shape. Done means a successful Figma token response is parsed and authentication completes.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

triage

Summary

After the -32601/server/discover fatal-failure bug (#4870) was fixed in 1.0.87-0, the Figma remote MCP server (https://mcp.figma.com/mcp) now progresses much further through the OAuth flow — client registration succeeds, the browser consent screen works, and the CLI logs Completing authentication... — but the token exchange itself fails with:

OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response

This happens on every attempt, with fresh, unused authorization codes, correct PKCE verifiers, and a client that was successfully registered days earlier (so this is not the client_name DCR 403 described in #4906 — registration is not the failure point here).

Environment

  • GitHub Copilot CLI: 1.0.87-0
  • OS: Linux (devcontainer, aarch64)
  • Figma MCP server: https://mcp.figma.com/mcp
  • Registered OAuth client: dynamically registered days earlier via DCR, token_endpoint_auth_method unknown (both client_secret_post and client_secret_basic are advertised as supported per Figma's .well-known/oauth-authorization-server metadata)

Steps to reproduce

  1. Configure the Figma remote MCP server:
    {
      "mcpServers": {
        "figma": { "type": "http", "url": "https://mcp.figma.com/mcp", "tools": ["*"] }
      }
    }
    
  2. Trigger authentication (/mcp → figma → Authenticate, or reconnect after a 401).
  3. Complete the browser consent screen; the CLI receives the redirect and logs Completing authentication....
  4. Immediately after, authentication fails:
    ERROR OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
    

Log excerpt

2026-09-21T09:08:22.351Z [ERROR] Completing authentication...
2026-09-21T09:08:22.565Z [ERROR] OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
2026-09-21T09:08:22.566Z [WARNING] HTTP 401 challenge (WWW-Authenticate: ...authorization_uri="https://api.figma.com/.well-known/oauth-authorization-server") {"server":"figma"}

Investigation so far

  • Manually replaying the same authorization code directly against POST https://api.figma.com/v1/oauth/token (per RFC 8414 discovery, the real token endpoint is https://api.figma.com/v1/oauth/token, not /oauth/token) after the CLI's attempt returns a clean, well-formed JSON invalid_grant error — consistent with the code already being single-use-consumed by the CLI's own (failed) exchange attempt. This suggests the CLI's request did reach the token endpoint and did receive a response (invalid_grant errors from Figma are clean, parseable JSON), but something about a successful response body apparently trips up the CLI's parser — the error text is specifically "Failed to parse server response", not a network/timeout/auth error.
  • This is not the #4906 DCR client_name 403 issue — our client was registered successfully well before this session (no 403 at registration time), and the failure occurs at the token exchange step, after a successful consent screen.
  • Not fixed by re-authenticating, restarting the CLI, or using a completely fresh browser-based (non-relayed) OAuth attempt.

Suggested next step

Capture/log the raw HTTP response body (status + headers + body) when a token-exchange parse failure occurs, so the actual shape of Figma's response can be compared against what the CLI's OAuth client expects (e.g. extra/missing fields, unexpected token_type casing, non-standard field names, etc.).

Langage dominant
Shell
Étoiles
11.2k
Forks
1.9k
Merge moyen
14 h 16 min
PR mergées (30 j)
6

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de github/copilot-cli

Toutes les issues de github/copilot-cli

Issues similaires

Plus d'issues Shell/Bash

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.