[BUG] Cannot connect Remote GitHub MCP Server
Environment
- Platform (select one):
- [x] Anthropic API
- [ ] AWS Bedrock
- [ ] Google Vertex AI
- [ ] Other: <!-- specify -->
- Claude CLI version: <!-- output of
claude --version--> 1.0.27 (Claude Code) - Operating System: <!-- e.g. macOS 14.3, Windows 11, Ubuntu 22.04 --> macOS 15.5
- Terminal: <!-- e.g. iTerm2, Terminal App --> iTerm2
Bug Description
<!-- A clear and concise description of the bug -->
The OAuth authentication fails for the GitHub MCP Server (https://github.com/github/github-mcp-server) added with the following command:
claude mcp add -t http github-server https://api.githubcopilot.com/mcp/
and https://docs.anthropic.com/en/docs/claude-code/mcp#authenticate-with-remote-mcp-servers
Based on the observed behavior, it seems that Claude immediately tries to connect to /.well-known/oauth-authorization-server and ignores the resource_metadata in the www-authenticate header, preventing it from properly following the GitHub MCP Server flow.
I believe GitHub MCP Server could be supported by implementing the following flow:
- Retrieve resource_metadata from the www-authenticate header returned by GET https://api.githubcopilot.com/mcp/
- Send a request to the URL obtained in step 1, and use authorization_servers to perform OAuth
- Continue with the normal flow
Steps to Reproduce
- do
claude mcp add -t http github-server https://api.githubcopilot.com/mcp/ - run
claudeand try/mcpcommand
Expected Behavior
<!-- What you expected to happen -->
Complete OAuth 2.0 authentication flow
Actual Behavior
<!-- What actually happened -->
Failed OAuth 2.0 authentication flow
Additional Context
<!-- Add any other context about the problem here, such as screenshots, logs, etc. -->
11 Comments
The github mcp server doesn't support dynamic oauth client registration, meaning it doesn't support our normal oauth flow out of the box. Their docs touch on this a bit: https://github.com/github/github-mcp-server?tab=readme-ov-file#installation.
Instead you need to configure a PAT and set up the server config like:
I am still having this issue. Example of config:
I get the error:
I'm seeing the same behaviour with a different OAuth implementation that does support dynamic registration. It is working when I use Inspector as the client rather than Claude Code.
Our /mcp endpoint replies with the resource_metadata option:
Claude Code never attempts to fetch the protected resource metadata. Instead we see it makes a request for /.well-known/oauth-authorization-server at the MCP server, rather than our authorization server, which fails. I think the issue might still be unresolved.
I'm still having the same issue when I try to initialise mcp serve with
/mcpcommand after adding the mcp server withclaude mcp add --transport http github https://api.githubcopilot.com/mcp/
Same error on WSL
@Archulan @malisancube are you adding a bearer token with a PAT as mentioned above?
@ashwin-ant I was able to configure the MCP via the json including the PAT as that was the final resort. But the original issue raised was related to dynamic OAuth not working.
I'm starting to really hate MCP all together. What a shit show maintaining mcp servers..
@Archulan that's an issue with the github server not offering dynamic OAuth, not actually a bug in Claude Code
@ashwin-ant 💯 . That's why I didn't reopen this issue.
This issue has been automatically locked since it was closed and has not had any activity for 7 days. If you're experiencing a similar issue, please file a new issue and reference this one if it's relevant.