Remote MCP (mcp.socket.dev) rejects freshly-issued OAuth access tokens with 401 invalid_token
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- typescript
- Ambito
- api, authentication, backend
Direzione di ricerca
Inizia dall’endpoint MCP remoto https://mcp.socket.dev/ e traccia come vengono convalidati i suoi token bearer OAuth, confrontando questo percorso con la richiesta funzionante a api.socket.dev. Riproduci il problema con i comandi curl forniti e ispeziona la documentazione remota di Socket MCP e i metadati della risorsa protetta da OAuth. Il lavoro è concluso quando un token appena emesso può inizializzare MCP correttamente, con il comportamento di autenticazione e la documentazione allineati.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
The remote Socket MCP server at https://mcp.socket.dev/ rejects access tokens that its own OAuth flow just issued. The token is valid and unexpired — the same token authenticates successfully against api.socket.dev — but every MCP request returns 401 invalid_token. This makes the remote MCP server unusable with OAuth-capable MCP clients (tested with Claude Code).
Environment
- Client: Claude Code (streamable HTTP MCP client with OAuth + dynamic client registration)
- Server:
https://mcp.socket.dev/ - Account: Socket org
clivi(team plan), reproduced consistently across 2 days (2026-06-09 and 2026-06-10)
Steps to reproduce
- Add the remote server per the docs:
claude mcp add --transport http socket-mcp https://mcp.socket.dev/ - Complete the OAuth flow (DCR client, e.g.
client_id=dcr-f8TfK-9JQzUGucp7lDJCymIp, scopepackages:list,resource=https://mcp.socket.dev/). The browser flow finishes with "Authentication successful". - Client receives and stores an access token (
sktsec_…, 55 chars, ~15-minute TTL) plus a refresh token. - Immediately (>10 minutes before expiry) call the MCP endpoint with the token:
curl -X POST https://mcp.socket.dev/ \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"diag","version":"1.0"}}}'
Expected
200 with an initialize result.
Actual
HTTP/2 401
www-authenticate: Bearer error="invalid_token", error_description="Invalid or expired token", resource_metadata="https://mcp.socket.dev/.well-known/oauth-protected-resource"
{"error":"invalid_token","error_description":"Invalid or expired token"}
Evidence the token itself is valid
The exact same token, at the same moment, works against the regular API:
curl https://api.socket.dev/v0/organizations -H "Authorization: Bearer $ACCESS_TOKEN"
# 200 — returns the org as expected
So issuance, scope (packages:list, which matches the resource metadata's scopes_supported), audience/resource binding, and storage are all fine — only the MCP resource server's token validation fails.
Additional observations
- The Remote Socket MCP docs say "No API key or authentication required!" — but unauthenticated requests get
401witherror_description="Missing Authorization header". If auth is now required, the docs are stale; if it isn't, the 401s are the bug. https://mcp.socket.dev/mcp(referenced in the Windsurf section of those docs) returns404.- Workaround that works fine: local stdio server (
@socketsecurity/mcp) with a static API key of the samepackages:listscope. (Side note: itsenginesfield requires npm ≥ 11.16, which no current Node release bundles —npxfails out of the box;pnpm dlxworks.)
- Lingua principale
- JavaScript
- Stelle
- 136
- Fork
- 47
- Merge medio
- 13g 10h
- PR unite (30g)
- 1
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di SocketDev/socket-mcp
-
[fuzz] fuzz-js job failedAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
SocketDev/socket-mcp#218 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 52/100
SocketDev/socket-mcp#201 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
SocketDev/socket-mcp#186 · 1 commento ·
Tutte le issue di SocketDev/socket-mcp
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
developmentseed/deck.gl-raster#693 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
iii-hq/iii#2278 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
dependencies security
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
[DevEx]: Playground specs are excluded from both GUI and CI, so videoPlayground is unreachableApertadev experience
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
cuttle-cards/cuttle#1413 ·
I maintainer di solito rispondono entro 1 giorno
-
macOS
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
beyondcode/herd-community#1761 ·