What did you do?
Ran the client OAuth flow (auth.AuthorizationCodeHandler) against an authorization server whose metadata advertises PKCE with only the plain method:
"code_challenge_methods_supported": ["plain"]
What did you see?
oauthex.GetAuthServerMeta accepted the metadata: it only checks that code_challenge_methods_supported is non-empty. The handler then always sends an S256 challenge (oauth2.S256ChallengeOption in auth/authorization_code.go, and likewise in auth/extauth/oidc_login.go), so the server rejects the authorization request. The failure surfaces late, at the authorization endpoint in the user's browser, instead of during discovery with a clear message.
What did you expect to see?
Discovery to reject a server that cannot do S256, since that is the only method the SDK's clients use. The MCP authorization spec requires clients to use S256 (via OAuth 2.1 section 7.5.2), and the TypeScript SDK refuses such a server during discovery: packages/client/src/client/auth.ts throws Incompatible auth server: does not support code challenge method S256 when the list is present and lacks S256.
Real servers that also support plain are unaffected; Google's metadata in oauthex/testdata/google-auth-meta.json lists ["plain", "S256"].
What version of the Go MCP SDK are you using?
v1.8.0, and main at the time of writing.
What version of Go are you using (go version)?
go1.25.3 windows/amd64 (also reproduced with the go1.26 toolchain).
I have a fix with tests ready and will link the PR here. It tightens the check in GetAuthServerMeta, whose doc already says it "verifies that the authorization server supports PKCE"; if you'd rather keep oauthex permissive and put the check in the auth handlers instead, I'm happy to move it.
What did you do?
Ran the client OAuth flow (
auth.AuthorizationCodeHandler) against an authorization server whose metadata advertises PKCE with only theplainmethod:What did you see?
oauthex.GetAuthServerMetaaccepted the metadata: it only checks thatcode_challenge_methods_supportedis non-empty. The handler then always sends anS256challenge (oauth2.S256ChallengeOptioninauth/authorization_code.go, and likewise inauth/extauth/oidc_login.go), so the server rejects the authorization request. The failure surfaces late, at the authorization endpoint in the user's browser, instead of during discovery with a clear message.What did you expect to see?
Discovery to reject a server that cannot do
S256, since that is the only method the SDK's clients use. The MCP authorization spec requires clients to useS256(via OAuth 2.1 section 7.5.2), and the TypeScript SDK refuses such a server during discovery:packages/client/src/client/auth.tsthrowsIncompatible auth server: does not support code challenge method S256when the list is present and lacksS256.Real servers that also support
plainare unaffected; Google's metadata inoauthex/testdata/google-auth-meta.jsonlists["plain", "S256"].What version of the Go MCP SDK are you using?
v1.8.0, and
mainat the time of writing.What version of Go are you using (
go version)?go1.25.3 windows/amd64 (also reproduced with the go1.26 toolchain).
I have a fix with tests ready and will link the PR here. It tightens the check in
GetAuthServerMeta, whose doc already says it "verifies that the authorization server supports PKCE"; if you'd rather keepoauthexpermissive and put the check in theauthhandlers instead, I'm happy to move it.