Problem
The CLI's stored-auth flags can't see a token the shared OAuth store actually holds:
--use-stored-auth exits 3 with no_stored_token, and its message lists the very URL it failed to match under "Stored keys".
--list-stored-auth returns "storedServerUrls": [].
--wait-for-auth goes through the same lookup (findStoredToken), so going by the code it waits until it times out even after the token lands. I haven't run this one.
The lookups in clients/cli/src/cli.ts read the token at the server level: state.tokens?.access_token / state.tokens?.refresh_token (on v2/main: L325 findStoredToken, L388, L1010 --list-stored-auth, L1120–1121 --use-stored-auth). Since the OAuth store was re-keyed per issuer (#1625), acquired tokens are stored at servers[url].byIssuer[activeIssuer].tokens, so none of these lookups ever matches. --stored-auth-only is unaffected because it goes through the normal auth provider path, which does read byIssuer.
Found while smoke testing #2482, where it reproduced identically on v2/main (30a9a897) and on the PR head (fc55e11a). So it is not caused by that PR. The PR does change where the tokens live, since they move to the secret store and are joined back on read, so a fix should read the joined view.
Reproduce
- Start an OAuth test server:
node test-servers/build/server-composable.js --config test-servers/configs/oauth-revocation-http.json (:8083).
- With an isolated
MCP_STORAGE_DIR, complete an interactive CLI login: mcp-inspector --cli --server-url http://localhost:8083/mcp --method tools/list.
- Check the token is there:
--stored-auth-only --method tools/list succeeds, and oauth.json shows servers["http://localhost:8083/mcp"].byIssuer["http://localhost:8083"].tokens.
mcp-inspector --cli --list-stored-auth prints storedServerUrls: [].
mcp-inspector --cli --server-url http://localhost:8083/mcp --use-stored-auth --method tools/list exits 3 with {"error":{"code":"no_stored_token",…"Stored keys: http://localhost:8083/mcp."}}.
Expected
--list-stored-auth lists the URL.
--use-stored-auth refreshes (or injects) the active issuer's token and succeeds.
--wait-for-auth returns as soon as the token lands.
- The refresh write-back persists the rotated tokens under the active issuer.
The existing stored-auth tests should cover the byIssuer shape, so this can't regress silently again.
Problem
The CLI's stored-auth flags can't see a token the shared OAuth store actually holds:
--use-stored-authexits3withno_stored_token, and its message lists the very URL it failed to match under "Stored keys".--list-stored-authreturns"storedServerUrls": [].--wait-for-authgoes through the same lookup (findStoredToken), so going by the code it waits until it times out even after the token lands. I haven't run this one.The lookups in
clients/cli/src/cli.tsread the token at the server level:state.tokens?.access_token/state.tokens?.refresh_token(onv2/main: L325findStoredToken, L388, L1010--list-stored-auth, L1120–1121--use-stored-auth). Since the OAuth store was re-keyed per issuer (#1625), acquired tokens are stored atservers[url].byIssuer[activeIssuer].tokens, so none of these lookups ever matches.--stored-auth-onlyis unaffected because it goes through the normal auth provider path, which does readbyIssuer.Found while smoke testing #2482, where it reproduced identically on
v2/main(30a9a897) and on the PR head (fc55e11a). So it is not caused by that PR. The PR does change where the tokens live, since they move to the secret store and are joined back on read, so a fix should read the joined view.Reproduce
node test-servers/build/server-composable.js --config test-servers/configs/oauth-revocation-http.json(:8083).MCP_STORAGE_DIR, complete an interactive CLI login:mcp-inspector --cli --server-url http://localhost:8083/mcp --method tools/list.--stored-auth-only --method tools/listsucceeds, andoauth.jsonshowsservers["http://localhost:8083/mcp"].byIssuer["http://localhost:8083"].tokens.mcp-inspector --cli --list-stored-authprintsstoredServerUrls: [].mcp-inspector --cli --server-url http://localhost:8083/mcp --use-stored-auth --method tools/listexits 3 with{"error":{"code":"no_stored_token",…"Stored keys: http://localhost:8083/mcp."}}.Expected
--list-stored-authlists the URL.--use-stored-authrefreshes (or injects) the active issuer's token and succeeds.--wait-for-authreturns as soon as the token lands.The existing stored-auth tests should cover the
byIssuershape, so this can't regress silently again.