Describe the bug
Native HTTP MCP authentication fails for Google's official Workspace MCP
endpoints before the browser authorization flow begins.
The protected-resource metadata advertises this authorization server:
https://accounts.google.com/
Google's authorization-server/OpenID metadata advertises this issuer:
https://accounts.google.com
These URLs differ only by the trailing slash on the origin root, but Copilot CLI
compares them literally and rejects the server:
OAuth authentication failed for google-calendar: MCPOAuthError:
Incompatible authorization server: authorization server advertised an issuer
that does not match the URL its metadata was discovered from (RFC 8414 §3.3);
refusing to connect
This affects all seven currently documented Google Workspace MCP endpoints:
- Calendar:
https://calendarmcp.googleapis.com/mcp/v1
- Gmail:
https://gmailmcp.googleapis.com/mcp/v1
- Drive:
https://drivemcp.googleapis.com/mcp/v1
- People:
https://people.googleapis.com/mcp/v1
- Docs:
https://docsmcp.googleapis.com/mcp/v1
- Slides:
https://slidesmcp.googleapis.com/mcp/v1
- Sheets:
https://sheetsmcp.googleapis.com/mcp/v1
Each endpoint's protected-resource metadata currently returns:
{
"resource": "<the MCP endpoint>",
"authorization_servers": ["https://accounts.google.com/"]
}
Google's public metadata returns:
GET https://accounts.google.com/.well-known/openid-configuration
{
"issuer": "https://accounts.google.com"
}
Affected version
GitHub Copilot CLI 1.0.81-10
Steps to reproduce the behavior
-
Register the localhost OAuth redirect URI required by Google and configure
Calendar as a native HTTP MCP server (credentials redacted):
{
"mcpServers": {
"google-calendar": {
"type": "http",
"url": "https://calendarmcp.googleapis.com/mcp/v1",
"oauthClientId": "<redacted>",
"auth": {
"clientSecret": "<redacted>",
"redirectPort": 8080
}
}
}
}
-
Start Copilot CLI.
-
Run /mcp auth google-calendar.
-
Authentication fails with the RFC 8414 issuer-mismatch error above. The
browser consent flow never starts.
The same behavior occurs with the other Google Workspace MCP endpoints.
Expected behavior
Copilot CLI should be able to authenticate with Google's official Workspace MCP
endpoints.
Ideally, the implementation would preserve strict issuer validation while
canonicalizing only semantically equivalent origin-root URLs before selecting
the discovery issuer (or otherwise handling the empty-path/trailing-slash
equivalence safely). If that is not acceptable under the CLI's RFC 8414
validation policy, the error should identify the two compared values and
provide an actionable, narrowly scoped compatibility option.
Additional context
- OS: macOS 26.6
- Architecture: Apple Silicon (
arm64)
- Terminal: iTerm2
- Shell: zsh
A pinned mcp-remote@0.2.4 stdio proxy using the same endpoint, OAuth client,
redirect URI, and Google account completes the OAuth flow successfully and can
call the Google tools. This confirms the client registration, consent, token
exchange, scopes, and MCP endpoints are functional; the failure is specific to
Copilot CLI's native HTTP MCP OAuth discovery/issuer validation.
Related reports:
This Google case is distinct: the protected-resource metadata uses the
RFC 9728 resource string and authorization_servers array correctly, and the
issuer differs only by a trailing slash at the authorization server's root.
Describe the bug
Native HTTP MCP authentication fails for Google's official Workspace MCP
endpoints before the browser authorization flow begins.
The protected-resource metadata advertises this authorization server:
Google's authorization-server/OpenID metadata advertises this issuer:
These URLs differ only by the trailing slash on the origin root, but Copilot CLI
compares them literally and rejects the server:
This affects all seven currently documented Google Workspace MCP endpoints:
https://calendarmcp.googleapis.com/mcp/v1https://gmailmcp.googleapis.com/mcp/v1https://drivemcp.googleapis.com/mcp/v1https://people.googleapis.com/mcp/v1https://docsmcp.googleapis.com/mcp/v1https://slidesmcp.googleapis.com/mcp/v1https://sheetsmcp.googleapis.com/mcp/v1Each endpoint's protected-resource metadata currently returns:
{ "resource": "<the MCP endpoint>", "authorization_servers": ["https://accounts.google.com/"] }Google's public metadata returns:
{ "issuer": "https://accounts.google.com" }Affected version
Steps to reproduce the behavior
Register the localhost OAuth redirect URI required by Google and configure
Calendar as a native HTTP MCP server (credentials redacted):
{ "mcpServers": { "google-calendar": { "type": "http", "url": "https://calendarmcp.googleapis.com/mcp/v1", "oauthClientId": "<redacted>", "auth": { "clientSecret": "<redacted>", "redirectPort": 8080 } } } }Start Copilot CLI.
Run
/mcp auth google-calendar.Authentication fails with the RFC 8414 issuer-mismatch error above. The
browser consent flow never starts.
The same behavior occurs with the other Google Workspace MCP endpoints.
Expected behavior
Copilot CLI should be able to authenticate with Google's official Workspace MCP
endpoints.
Ideally, the implementation would preserve strict issuer validation while
canonicalizing only semantically equivalent origin-root URLs before selecting
the discovery issuer (or otherwise handling the empty-path/trailing-slash
equivalence safely). If that is not acceptable under the CLI's RFC 8414
validation policy, the error should identify the two compared values and
provide an actionable, narrowly scoped compatibility option.
Additional context
arm64)A pinned
mcp-remote@0.2.4stdio proxy using the same endpoint, OAuth client,redirect URI, and Google account completes the OAuth flow successfully and can
call the Google tools. This confirms the client registration, consent, token
exchange, scopes, and MCP endpoints are functional; the failure is specific to
Copilot CLI's native HTTP MCP OAuth discovery/issuer validation.
Related reports:
discovery.
This Google case is distinct: the protected-resource metadata uses the
RFC 9728
resourcestring andauthorization_serversarray correctly, and theissuer differs only by a trailing slash at the authorization server's root.