Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Remote MCP (mcp.socket.dev) rejects freshly-issued OAuth access tokens with 401 invalid_token

Aperta
#185 6 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
45/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
typescript

Direzione di ricerca

Inizia dall’endpoint MCP remoto https://mcp.socket.dev/ e traccia come vengono convalidati i suoi token bearer OAuth, confrontando questo percorso con la richiesta funzionante a api.socket.dev. Riproduci il problema con i comandi curl forniti e ispeziona la documentazione remota di Socket MCP e i metadati della risorsa protetta da OAuth. Il lavoro è concluso quando un token appena emesso può inizializzare MCP correttamente, con il comportamento di autenticazione e la documentazione allineati.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Summary

The remote Socket MCP server at https://mcp.socket.dev/ rejects access tokens that its own OAuth flow just issued. The token is valid and unexpired — the same token authenticates successfully against api.socket.dev — but every MCP request returns 401 invalid_token. This makes the remote MCP server unusable with OAuth-capable MCP clients (tested with Claude Code).

Environment

  • Client: Claude Code (streamable HTTP MCP client with OAuth + dynamic client registration)
  • Server: https://mcp.socket.dev/
  • Account: Socket org clivi (team plan), reproduced consistently across 2 days (2026-06-09 and 2026-06-10)

Steps to reproduce

  1. Add the remote server per the docs: claude mcp add --transport http socket-mcp https://mcp.socket.dev/
  2. Complete the OAuth flow (DCR client, e.g. client_id=dcr-f8TfK-9JQzUGucp7lDJCymIp, scope packages:list, resource=https://mcp.socket.dev/). The browser flow finishes with "Authentication successful".
  3. Client receives and stores an access token (sktsec_…, 55 chars, ~15-minute TTL) plus a refresh token.
  4. Immediately (>10 minutes before expiry) call the MCP endpoint with the token:
curl -X POST https://mcp.socket.dev/ \
  -H "Authorization: Bearer $ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"diag","version":"1.0"}}}'

Expected

200 with an initialize result.

Actual

HTTP/2 401
www-authenticate: Bearer error="invalid_token", error_description="Invalid or expired token", resource_metadata="https://mcp.socket.dev/.well-known/oauth-protected-resource"
{"error":"invalid_token","error_description":"Invalid or expired token"}

Evidence the token itself is valid

The exact same token, at the same moment, works against the regular API:

curl https://api.socket.dev/v0/organizations -H "Authorization: Bearer $ACCESS_TOKEN"
# 200 — returns the org as expected

So issuance, scope (packages:list, which matches the resource metadata's scopes_supported), audience/resource binding, and storage are all fine — only the MCP resource server's token validation fails.

Additional observations

  • The Remote Socket MCP docs say "No API key or authentication required!" — but unauthenticated requests get 401 with error_description="Missing Authorization header". If auth is now required, the docs are stale; if it isn't, the 401s are the bug.
  • https://mcp.socket.dev/mcp (referenced in the Windsurf section of those docs) returns 404.
  • Workaround that works fine: local stdio server (@socketsecurity/mcp) with a static API key of the same packages:list scope. (Side note: its engines field requires npm ≥ 11.16, which no current Node release bundles — npx fails out of the box; pnpm dlx works.)
Lingua principale
JavaScript
Stelle
136
Fork
47
Merge medio
13g 10h
PR unite (30g)
1

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di SocketDev/socket-mcp

Tutte le issue di SocketDev/socket-mcp

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.