Skip to content

Connection with OAuth doesn't include scopes #454

Description

@leblancfg

Describe the bug
The OAuth debugger includes all the scopes_supported values in the Authorization URL step as a query param, but even if scope is marked as required in the authorization server metadata, the scope query param isn't included in the URL when clicking the "Connect" button.

Expected behavior
The authorization URL for the two OAuth connection methods (debugger or simple "connect" button) should match exactly.

Related PR: #355

Activity

  1. added
    authIssues and PRs related to authorization
    on Jul 8, 2025
  2. olaservo commented on Oct 13, 2025

    @olaservo
    Member

    After tracing back through the history of linked PRs, it appears that this Typescript SDK PR should address the root issue so I'll link it here: modelcontextprotocol/typescript-sdk#672

  3. cliffhall commented on Aug 1, 2026

    @cliffhall
    Member

    Closing: v1 is deprecated.

    Thank you for reporting this, and apologies for the long wait for a response.

    v1 will receive security fixes only — this issue describes a functionality, compatibility, or usability problem rather than a vulnerability, so it is being closed against v1. This is not a judgment on whether the problem is real — it's a consequence of the v1 line being frozen. This is happening as part of #1872.

    If this still happens in v2, we'd genuinely like to know. v2 is a complete rewrite — three clients over a shared core — so many v1 behaviours no longer exist in the same form. Please open a fresh issue against v2 with steps to reproduce, and we'll look at it. Note that we accept external contributions as issues rather than pull requests; maintainers handle design and implementation through a prompt-driven workflow. See CONTRIBUTING.md.

    Thanks for taking the time to report it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    authIssues and PRs related to authorizationbugSomething isn't workingclosed-v1-deprecatedClosed: v1 is deprecated and accepting security fixes onlyv1waiting on sdkWaiting for an SDK feature

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions