MCP OAuth breaks in Codex after token expiry, as devs slam inconsistent host implementations

max__drake · x · 2026-09-11

A dev who has built both MCP servers and apps slams MCP hosts (Claude Code, Codex, Cursor) for buggy, inconsistent spec implementations. Key evidence: openai/codex issue #33403, where remote Streamable HTTP MCP servers break after the 15-minute access token expires because the OAuth refresh omits the RFC 8707 resource parameter. A Clerk writeup details OAuth's fragmented spec landscape and misaligned security incentives.

Original post →

More from coding & agent

coding & agent channel →