Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

MCP OAuth: Figma token exchange fails with "Failed to parse server response" (distinct from #4870 / #4906)

オープン
#4,923 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
52/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発

調査の方向性

Start at the /mcp → figma → Authenticate flow and trace the token exchange against https://api.figma.com/v1/oauth/token. Capture the response status, headers, and body at the parse failure, then compare it with the OAuth client’s expected response shape. Done means a successful Figma token response is parsed and authentication completes.

索引モデルが issue の本文から書いたものです。

説明

triage

Summary

After the -32601/server/discover fatal-failure bug (#4870) was fixed in 1.0.87-0, the Figma remote MCP server (https://mcp.figma.com/mcp) now progresses much further through the OAuth flow — client registration succeeds, the browser consent screen works, and the CLI logs Completing authentication... — but the token exchange itself fails with:

OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response

This happens on every attempt, with fresh, unused authorization codes, correct PKCE verifiers, and a client that was successfully registered days earlier (so this is not the client_name DCR 403 described in #4906 — registration is not the failure point here).

Environment

  • GitHub Copilot CLI: 1.0.87-0
  • OS: Linux (devcontainer, aarch64)
  • Figma MCP server: https://mcp.figma.com/mcp
  • Registered OAuth client: dynamically registered days earlier via DCR, token_endpoint_auth_method unknown (both client_secret_post and client_secret_basic are advertised as supported per Figma's .well-known/oauth-authorization-server metadata)

Steps to reproduce

  1. Configure the Figma remote MCP server:
    {
      "mcpServers": {
        "figma": { "type": "http", "url": "https://mcp.figma.com/mcp", "tools": ["*"] }
      }
    }
    
  2. Trigger authentication (/mcp → figma → Authenticate, or reconnect after a 401).
  3. Complete the browser consent screen; the CLI receives the redirect and logs Completing authentication....
  4. Immediately after, authentication fails:
    ERROR OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
    

Log excerpt

2026-09-21T09:08:22.351Z [ERROR] Completing authentication...
2026-09-21T09:08:22.565Z [ERROR] OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
2026-09-21T09:08:22.566Z [WARNING] HTTP 401 challenge (WWW-Authenticate: ...authorization_uri="https://api.figma.com/.well-known/oauth-authorization-server") {"server":"figma"}

Investigation so far

  • Manually replaying the same authorization code directly against POST https://api.figma.com/v1/oauth/token (per RFC 8414 discovery, the real token endpoint is https://api.figma.com/v1/oauth/token, not /oauth/token) after the CLI's attempt returns a clean, well-formed JSON invalid_grant error — consistent with the code already being single-use-consumed by the CLI's own (failed) exchange attempt. This suggests the CLI's request did reach the token endpoint and did receive a response (invalid_grant errors from Figma are clean, parseable JSON), but something about a successful response body apparently trips up the CLI's parser — the error text is specifically "Failed to parse server response", not a network/timeout/auth error.
  • This is not the #4906 DCR client_name 403 issue — our client was registered successfully well before this session (no 403 at registration time), and the failure occurs at the token exchange step, after a successful consent screen.
  • Not fixed by re-authenticating, restarting the CLI, or using a completely fresh browser-based (non-relayed) OAuth attempt.

Suggested next step

Capture/log the raw HTTP response body (status + headers + body) when a token-exchange parse failure occurs, so the actual shape of Figma's response can be compared against what the CLI's OAuth client expects (e.g. extra/missing fields, unexpected token_type casing, non-standard field names, etc.).

主要言語
Shell
スター
11.2k
フォーク
1.9k
平均マージ
14時間 16分
マージ済み PR(30日)
6

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github/copilot-cli のほかの issue

github/copilot-cli の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。