You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When a token exchange or refresh fails, `MCP::Client::OAuth::Flow::AuthorizationError` includes the HTTP status and
165
+
the authorization server's `error` and `error_description` from [RFC 6749 Section 5.2](https://www.rfc-editor.org/rfc/rfc6749#section-5.2).
166
+
For example:
167
+
168
+
```text
169
+
Token endpoint returned status 400. invalid_request: Client must not use multiple authentication methods
170
+
```
171
+
172
+
The exception exposes `http_status`, `error`, and `error_description` readers for structured diagnostics. Missing or non-string
173
+
diagnostic fields are `nil`; non-JSON responses retain the status-only message. Other authorization failures have `nil` readers.
174
+
An `invalid_grant` response still raises `Flow::InvalidGrantError`, a subclass of `Flow::AuthorizationError`, so refresh-token
175
+
recovery behavior is unchanged.
176
+
177
+
Diagnostic fields are limited to 128 characters for `error` and 512 for `error_description`, including a trailing `...` when
178
+
truncated. Characters outside the RFC's printable ASCII set are replaced with spaces, and surrounding whitespace is removed.
179
+
The SDK excludes all other response fields, including `error_uri`, and does not include the raw response body in these errors.
180
+
Descriptions are provider-controlled text, not guaranteed to be free of sensitive information; apply your application's logging
181
+
and redaction policy before persisting them or displaying them to users.
182
+
162
183
### Client Credentials Grant
163
184
164
185
For a confidential machine-to-machine client (no user, no browser redirect), use `MCP::Client::OAuth::ClientCredentialsProvider` instead of `Provider`.
0 commit comments