Support client secrets for pre-registered MCP OAuth clients - #47891
Merged
copyberry[bot] merged 1 commit intoSep 24, 2026
Conversation
## Why MCP OAuth configuration supported a pre-registered client ID but could not supply a client secret for token exchange or refresh. ## What changed - Add `oauth.client_secret` and `codex mcp add --oauth-client-secret`, requiring a nonempty secret and client ID. Persist the secret in server configuration and accept `clientSecret` in plugin configuration. - Pass configured credentials through CLI, app-server, and plugin login flows and token refresh. Require a new login when a configured confidential client's ID differs from stored credentials. - Redact secrets in debug output and keep them out of authorization URLs and persisted OAuth token records. - Invalidate cached OAuth connections when the configured client ID or secret changes. ## Testing Add coverage for configuration validation and round trips, CLI argument redaction and subsequent login, app-server login, connection invalidation, and refresh with `client_secret_basic` and `client_secret_post` in both refresh modes. Verify secret exclusion from token records and reject mismatched client IDs before contacting the provider. GitOrigin-RevId: 85bb0e410e9e68e6cd68eb6359badfc7eac78147
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/85bb0e410e9e68e6cd68eb6359badfc7eac78147
branch
from
September 24, 2026 17:26
96ca644 to
83b56bc
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/85bb0e410e9e68e6cd68eb6359badfc7eac78147
branch
September 24, 2026 17:26
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Support client secrets for pre-registered MCP OAuth clients
Why
MCP OAuth configuration supported a pre-registered client ID but could not supply a client secret for token exchange or refresh.
What changed
oauth.client_secretandcodex mcp add --oauth-client-secret, requiring a nonempty secret and client ID. Persist the secret in server configuration and acceptclientSecretin plugin configuration.Testing
Add coverage for configuration validation and round trips, CLI argument redaction and subsequent login, app-server login, connection invalidation, and refresh with
client_secret_basicandclient_secret_postin both refresh modes. Verify secret exclusion from token records and reject mismatched client IDs before contacting the provider.