MCP OAuth: Figma token exchange fails with "Failed to parse server response" (distinct from #4870 / #4906)
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 52/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 領域
- api, authentication
調査の方向性
Start at the /mcp → figma → Authenticate flow and trace the token exchange against https://api.figma.com/v1/oauth/token. Capture the response status, headers, and body at the parse failure, then compare it with the OAuth client’s expected response shape. Done means a successful Figma token response is parsed and authentication completes.
索引モデルが issue の本文から書いたものです。
説明
Summary
After the -32601/server/discover fatal-failure bug (#4870) was fixed in 1.0.87-0, the Figma remote MCP server (https://mcp.figma.com/mcp) now progresses much further through the OAuth flow — client registration succeeds, the browser consent screen works, and the CLI logs Completing authentication... — but the token exchange itself fails with:
OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
This happens on every attempt, with fresh, unused authorization codes, correct PKCE verifiers, and a client that was successfully registered days earlier (so this is not the client_name DCR 403 described in #4906 — registration is not the failure point here).
Environment
- GitHub Copilot CLI: 1.0.87-0
- OS: Linux (devcontainer, aarch64)
- Figma MCP server:
https://mcp.figma.com/mcp - Registered OAuth client: dynamically registered days earlier via DCR,
token_endpoint_auth_methodunknown (bothclient_secret_postandclient_secret_basicare advertised as supported per Figma's.well-known/oauth-authorization-servermetadata)
Steps to reproduce
- Configure the Figma remote MCP server:
{ "mcpServers": { "figma": { "type": "http", "url": "https://mcp.figma.com/mcp", "tools": ["*"] } } } - Trigger authentication (
/mcp→ figma → Authenticate, or reconnect after a 401). - Complete the browser consent screen; the CLI receives the redirect and logs
Completing authentication.... - Immediately after, authentication fails:
ERROR OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
Log excerpt
2026-09-21T09:08:22.351Z [ERROR] Completing authentication...
2026-09-21T09:08:22.565Z [ERROR] OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
2026-09-21T09:08:22.566Z [WARNING] HTTP 401 challenge (WWW-Authenticate: ...authorization_uri="https://api.figma.com/.well-known/oauth-authorization-server") {"server":"figma"}
Investigation so far
- Manually replaying the same authorization code directly against
POST https://api.figma.com/v1/oauth/token(per RFC 8414 discovery, the real token endpoint ishttps://api.figma.com/v1/oauth/token, not/oauth/token) after the CLI's attempt returns a clean, well-formed JSONinvalid_granterror — consistent with the code already being single-use-consumed by the CLI's own (failed) exchange attempt. This suggests the CLI's request did reach the token endpoint and did receive a response (invalid_grant errors from Figma are clean, parseable JSON), but something about a successful response body apparently trips up the CLI's parser — the error text is specifically "Failed to parse server response", not a network/timeout/auth error. - This is not the #4906 DCR
client_name403 issue — our client was registered successfully well before this session (no 403 at registration time), and the failure occurs at the token exchange step, after a successful consent screen. - Not fixed by re-authenticating, restarting the CLI, or using a completely fresh browser-based (non-relayed) OAuth attempt.
Suggested next step
Capture/log the raw HTTP response body (status + headers + body) when a token-exchange parse failure occurs, so the actual shape of Figma's response can be compared against what the CLI's OAuth client expects (e.g. extra/missing fields, unexpected token_type casing, non-standard field names, etc.).
- 主要言語
- Shell
- スター
- 11.2k
- フォーク
- 1.9k
- 平均マージ
- 14時間 16分
- マージ済み PR(30日)
- 6
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/copilot-cli のほかの issue
-
triage
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
github/copilot-cli#4932 ·
-
triage
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
github/copilot-cli#4909 ·
-
triage
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
github/copilot-cli#4906 ·
-
triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/copilot-cli#4848 ·
-
area:agents area:mcp
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/copilot-cli#4729 ·
github/copilot-cli の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
elastic/gradle-plugins#156 ·
-
Priority/High ready-for-agent Severity/Major Type/Bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
comp/cli P3 type/docs
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
NousResearch/hermes-agent#119756 · コメント 1 件 ·
-
comp: build/pipeline type: bug version: current (v17+)
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
angular/angularfire#3766 ·
-
out-of-date
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
CachyOS/CachyOS-PKGBUILDS#1903 ·