Skip to content

Support client secrets for pre-registered MCP OAuth clients - #47891

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/85bb0e410e9e68e6cd68eb6359badfc7eac78147
Sep 24, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/85bb0e410e9e68e6cd68eb6359badfc7eac78147

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Support client secrets for pre-registered MCP OAuth clients

Why

MCP OAuth configuration supported a pre-registered client ID but could not supply a client secret for token exchange or refresh.

What changed

  • Add oauth.client_secret and codex mcp add --oauth-client-secret, requiring a nonempty secret and client ID. Persist the secret in server configuration and accept clientSecret in plugin configuration.
  • Pass configured credentials through CLI, app-server, and plugin login flows and token refresh. Require a new login when a configured confidential client's ID differs from stored credentials.
  • Redact secrets in debug output and keep them out of authorization URLs and persisted OAuth token records.
  • Invalidate cached OAuth connections when the configured client ID or secret changes.

Testing

Add coverage for configuration validation and round trips, CLI argument redaction and subsequent login, app-server login, connection invalidation, and refresh with client_secret_basic and client_secret_post in both refresh modes. Verify secret exclusion from token records and reject mismatched client IDs before contacting the provider.

## Why

MCP OAuth configuration supported a pre-registered client ID but could not supply a client secret for token exchange or refresh.

## What changed

- Add `oauth.client_secret` and `codex mcp add --oauth-client-secret`, requiring a nonempty secret and client ID. Persist the secret in server configuration and accept `clientSecret` in plugin configuration.
- Pass configured credentials through CLI, app-server, and plugin login flows and token refresh. Require a new login when a configured confidential client's ID differs from stored credentials.
- Redact secrets in debug output and keep them out of authorization URLs and persisted OAuth token records.
- Invalidate cached OAuth connections when the configured client ID or secret changes.

## Testing

Add coverage for configuration validation and round trips, CLI argument redaction and subsequent login, app-server login, connection invalidation, and refresh with `client_secret_basic` and `client_secret_post` in both refresh modes. Verify secret exclusion from token records and reject mismatched client IDs before contacting the provider.

GitOrigin-RevId: 85bb0e410e9e68e6cd68eb6359badfc7eac78147
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/85bb0e410e9e68e6cd68eb6359badfc7eac78147 branch from 96ca644 to 83b56bc Compare September 24, 2026 17:26
@copyberry
copyberry Bot merged commit 83b56bc into main Sep 24, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/85bb0e410e9e68e6cd68eb6359badfc7eac78147 branch September 24, 2026 17:26
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 24, 2026
@joelmitz
joelmitz deployed to issue-triage September 24, 2026 17:28 — with GitHub Actions Active
@joelmitz
joelmitz deployed to issue-triage September 24, 2026 17:28 — with GitHub Actions Active
@joelmitz
joelmitz deployed to issue-triage September 24, 2026 17:28 — with GitHub Actions Active
@joelmitz
joelmitz deployed to issue-triage September 24, 2026 17:29 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — 83b56bc5 Deployed Sep 24, 2026 by apdrafting via Translate non-English issue #14955
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants