Remote HTTP MCP server OAuth fails with false "issuer mismatch" when RFC 9728 resource URL differs from authorization server issuer
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- rust
- Ambito
- api, authentication, cli
Direzione di ricerca
Inizia dalla configurazione MCP HTTP remota in ~/.kiro/settings/mcp.json e riproduci il fallimento usando kiro-cli chat con l’esempio GitLab Dedicated. Traccia il rilevamento della risorsa protetta da OAuth e del server di autorizzazione, quindi verifica che un URL della risorsa diverso dall’issuer completi il flusso OAuth senza il falso mancato riscontro.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Checks
- I have searched github.com/aws/amazon-q-developer-cli/issues and there are no duplicates of my issue
- I have run
q doctorin the affected terminal session - I have run
q restartand replicated the issue again
Operating system
macOS 26.6.2 (25G83)
Expected behaviour
When connecting to a remote HTTP MCP server that uses OAuth, kiro-cli should follow RFC 9728 (Protected Resource Metadata) and RFC 8414 (Authorization Server Metadata). The MCP resource identifier and the authorization server's issuer are distinct values and are not required to match. The CLI should discover the authorization server listed in the protected-resource metadata and validate its issuer against that authorization server's own metadata document — not against the MCP resource URL. The connection should succeed and complete the OAuth flow, exactly as the Kiro IDE does with the same configuration.
Actual behaviour
kiro-cli rejects the connection with:
GitLab ✗ failed Authorization server issuer mismatch:
expected https://X.gitlab-dedicated.com/api/v4/mcp,
received https://X.gitlab-dedicated.com
The CLI incorrectly expects the authorization server's issuer to equal the MCP resource URL (.../api/v4/mcp). GitLab correctly advertises a resource of https://X.gitlab-dedicated.com/api/v4/mcp with an authorization server / issuer of https://X.gitlab-dedicated.com. These are supposed to differ per spec, so the CLI raises a false mismatch and refuses to connect. The identical configuration works in the Kiro IDE.
Steps to reproduce
-
Configure a remote HTTP MCP server in ~/.kiro/settings/mcp.json that uses OAuth where the authorization server issuer differs from the MCP resource URL. Example (GitLab Dedicated):
"GitLab": {
"type": "http",
"url": "https://X.gitlab-dedicated.com/api/v4/mcp",
"oauthScopes": ["mcp"]
} -
The server's OAuth discovery returns (both spec-compliant):
- GET /.well-known/oauth-protected-resource/api/v4/mcp
{ "resource": "https://X.gitlab-dedicated.com/api/v4/mcp",
"authorization_servers": ["https://X.gitlab-dedicated.com"],
"scopes_supported": ["mcp"] } - GET /.well-known/oauth-authorization-server
{ "issuer": "https://X.gitlab-dedicated.com", ... }
- GET /.well-known/oauth-protected-resource/api/v4/mcp
-
Start a chat / trigger the MCP connection:
kiro-cli chat -
Observe the "Authorization server issuer mismatch" error and the server failing to connect.
Note: The same config connects successfully in the Kiro IDE, confirming the discovery documents are valid and the defect is in the CLI's issuer validation.
Environment
<This will be visible to anyone. Do not include personal or sensitive information>
[q-details]
version = "2.19.2"
hash = "80d5aeb353825e5fbbe66c5e5c07084979af0262"
date = "2026-08-25T02:48:27.049726Z (2d ago)"
variant = "full"
[system-info]
os = "macOS 26.6.2 (25G83)"
chip = "Apple M4 Pro"
total-cores = 14
memory = "24.00 GB"
[environment]
cwd = "/Users/USER"
cli-path = "/Users/USER"
os = "Mac"
shell-path = "/bin/zsh"
shell-version = "5.9"
terminal = "iTerm 2"
install-method = "unknown"
[env-vars]
PATH = "/Users/USER/.local/bin:/Library/Frameworks/Python.framework/Versions/3.10/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/local/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/bin:/var/run/com.apple.security.cryptexd/codex.system/bootstrap/usr/appleinternal/bin:/pkg/env/global/bin:/Applications/iTerm.app/Contents/Resources/utilities:/Users/USER/.local/bin"
QTERM_SESSION_ID = "b40ddb9c90db46f1aafbc571a36d5564"
Q_SET_PARENT_CHECK = "1"
Q_TERM = "2.15.2"
SHELL = "/bin/zsh"
TERM = "xterm-256color"
__CFBundleIdentifier = "com.googlecode.iterm2"
- Lingua principale
- Rust
- Stelle
- 2k
- Fork
- 441
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di aws/amazon-q-developer-cli
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
aws/amazon-q-developer-cli#3898 ·
-
bug: invalid JSON in agent-format.md `allowedTools` Examples block (JS `//` comments + unquoted `@builtin`) breaks copy-pasteForse già presa @ken-jo l’ha presa 112 giorni fa. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
aws/amazon-q-developer-cli#3851 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
aws/amazon-q-developer-cli#3316 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
aws/amazon-q-developer-cli#3023 · 2 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 20/100
aws/amazon-q-developer-cli#3925 · 1 commento ·
Tutte le issue di aws/amazon-q-developer-cli
Issue simili
-
bug user-priority/P2
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
rescript-lang/rescript#8765 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
nautechsystems/nautilus_trader#5287 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
farion1231/cc-switch#8072 ·
I maintainer di solito rispondono entro 1 giorno
-
Python 3.15 supportForse già presa @amnesiaof l’ha presa oggi. ApertaL: python L: python:uv
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
dependabot/dependabot-core#16524 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno