Repository navigation
Connection with OAuth doesn't include scopes #454
Description
Activity
- addedauthIssues and PRs related to authorizationIssues and PRs related to authorization
on Jul 8, 2025 After tracing back through the history of linked PRs, it appears that this Typescript SDK PR should address the root issue so I'll link it here: modelcontextprotocol/typescript-sdk#672
Reacted by Chris Coutinho- addedclosed-v1-deprecatedClosed: v1 is deprecated and accepting security fixes onlyClosed: v1 is deprecated and accepting security fixes only
on Aug 1, 2026 Closing: v1 is deprecated.
Thank you for reporting this, and apologies for the long wait for a response.
v1 will receive security fixes only — this issue describes a functionality, compatibility, or usability problem rather than a vulnerability, so it is being closed against v1. This is not a judgment on whether the problem is real — it's a consequence of the v1 line being frozen. This is happening as part of #1872.
If this still happens in v2, we'd genuinely like to know. v2 is a complete rewrite — three clients over a shared core — so many v1 behaviours no longer exist in the same form. Please open a fresh issue against v2 with steps to reproduce, and we'll look at it. Note that we accept external contributions as issues rather than pull requests; maintainers handle design and implementation through a prompt-driven workflow. See
CONTRIBUTING.md.Thanks for taking the time to report it.
Describe the bug
The OAuth debugger includes all the
scopes_supportedvalues in the Authorization URL step as a query param, but even if scope is marked asrequiredin the authorization server metadata, thescopequery param isn't included in the URL when clicking the "Connect" button.Expected behavior
The authorization URL for the two OAuth connection methods (debugger or simple "connect" button) should match exactly.
Related PR: #355