Skip to content

Remote MCP OAuth tokens never refreshed; restart loses auth state (IBKR connector) #49773

Description

@lucaderosa2-jpg

Remote MCP OAuth tokens never refreshed; restart loses auth state

What happens

  • A remote MCP server (IBKR mcp-public, OAuth via browser flow) works right after activation, then starts failing minutes later with 401 after successful authentication on every endpoint — snapshots, search, everything.
  • Restarting opencode flips the server back to needs_auth on its own.
  • Re-authenticating does not reliably revive the running session.

Evidence from my machine (Windows, global opencode.jsonc, type: remote, no custom headers)

  • ~/.local/share/opencode/mcp-auth.json holds the entry with dynamically registered clientInfo, serverUrl, and a tokens object containing accessToken, refreshToken, expiresAt, scope. So both tokens persist — the refresh just never fires.
  • Stored access-token lifetimes are on the order of tens of minutes, so any session longer than that hits this wall.
  • Same IBKR sessions stay alive fine when driven from other MCP clients, so this is the client's refresh handling, not the authorization server.

Expected

  • Silent refresh_token grant before expiry; running session picks up the rotated token without re-auth or restart.

Related (same symptom family)

Happy to pull redacted mcp debug output if useful — token values stay with me.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions