bug(desktop): MCP OAuth authorization URL is not surfaced before callback timeout
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 65/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- typescript
- 領域
- desktop
調査の方向性
Start by tracing the Desktop UI's handling of live tool updates from the MCP authentication flow, which can be invoked through /mcp-config; the report says the tool emits an authorization-URL update before waiting for the callback. Done means Desktop surfaces the URL or opens it in the browser while the callback listener is still active, so authorization can finish before timeout.
索引モデルが issue の本文から書いたものです。
説明
What version of Kimi Code is running?
Desktop app 1.0.2 (Windows x64, packaged), embedded server host_version 2.0.1.
Which model were you using?
K2.8 Preview.
What platform is your computer?
Windows 11 x64.
What issue are you seeing?
For a project-level remote HTTP MCP server that requires OAuth, Kimi Code Desktop exposes the generated mcp__<server>__authenticate tool, but invoking the login flow does not surface the fresh authorization URL to the user while the callback listener is still active.
Observed behavior:
mcp__cloudflare-api__authenticatestarts and the UI remains atWaiting for output....- No browser window is opened.
- No authorization URL is shown while the flow is live.
- After the OAuth callback wait times out, the tool finally returns an error that includes the authorization URL.
- Opening that URL at that point reaches the provider's authorization page, but the redirect back to
127.0.0.1:<port>/callbackfails because the local callback listener has already timed out and closed.
This was reproduced twice with different callback ports.
The remote MCP server itself and the OAuth provider are working. The same OAuth flow completes successfully through the documented local MCP management API when the authorization URL is retrieved immediately and opened while the callback listener is live.
What steps can reproduce the bug?
-
On Windows 11, configure a project-level remote HTTP MCP server in:
<workspace>\.kimi-code\mcp.json -
Trust the workspace so the project MCP server is loaded.
-
Start a fresh Kimi Code Desktop session.
-
Confirm that the server requires OAuth and that the generated authentication tool is visible, for example:
mcp__example-api__authenticate -
Invoke the MCP login flow (for example through
/mcp-config). -
Observe that Desktop remains on:
Waiting for output...without opening a browser and without showing the fresh authorization URL.
-
Wait for the callback timeout.
-
Observe that only after timeout does the tool output include an authorization URL.
-
Open that returned URL and authorize promptly.
-
Observe that the final redirect to the local callback endpoint fails because the listener has already closed.
What is the expected behavior?
As soon as the MCP OAuth flow creates the authorization URL and local callback listener, Desktop should surface the authorization URL immediately (or open it in the user's browser), while the listener is active.
The user must be able to complete authorization before the callback timeout.
The tool implementation already emits an authorization-url update before waiting for the callback, so Desktop should render that live update rather than exposing the URL only after the tool finishes with a timeout.
Verified workaround
The underlying server-side OAuth flow works through the documented MCP management API:
-
Begin the flow:
POST /api/v2/mcp/auth:begin?cwd=<workspace> Content-Type: application/json { "source": "global", "name": "example-api" } -
Read the returned
authorizationUrlimmediately and open it in the browser while the callback listener is active. -
Complete the provider authorization.
-
Wait for completion:
POST /api/v2/mcp/auth:complete Content-Type: application/json { "flowId": "<flow-id>", "timeoutMs": 900000 } -
The completion returns
code: 0, and an offline auth-status check reports:oauth-authorized
This confirms that OAuth, PKCE, local callback handling, and credential persistence all work when the authorization URL is surfaced in time. The failure appears specific to the Desktop UI/live tool-update path.
Additional information
I searched existing issues before filing and did not find a duplicate for this Desktop-specific symptom.
This is separate from #3949, which concerns the missing Workspace Trust prompt for project MCP configuration.
No OAuth URLs, callback state values, credentials, tokens, account identifiers, local usernames, production domains, or request IDs are included in this report.
- 主要言語
- TypeScript
- スター
- 7.7k
- フォーク
- 1.3k
- 平均マージ
- 12時間 35分
- マージ済み PR(30日)
- 311
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
MoonshotAI/kimi-code のほかの issue
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
MoonshotAI/kimi-code#4040 ·
メンテナーはふだん 1 日以内に返信
-
顶栏字体不随字体大小缩放bugオープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
MoonshotAI/kimi-code#4039 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
MoonshotAI/kimi-code#4010 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
MoonshotAI/kimi-code#4008 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
MoonshotAI/kimi-code#3947 ·
メンテナーはふだん 1 日以内に返信
MoonshotAI/kimi-code の issue をすべて見る
似ている issue
-
priority: P2
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
prime-radiant-inc/evener#3291 ·
メンテナーはふだん 1 日以内に返信
-
accessibility bug revealjs
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
quarto-dev/quarto-cli#14961 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
supabase/agent-skills#614 ·
-
Content
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
RunestoneInteractive/rs#1559 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信