MCP OAuth breaks in Codex after token expiry, as devs slam inconsistent host implementations
max__drake · x · 2026-09-11
A dev who has built both MCP servers and apps slams MCP hosts (Claude Code, Codex, Cursor) for buggy, inconsistent spec implementations. Key evidence: openai/codex issue #33403, where remote Streamable HTTP MCP servers break after the 15-minute access token expires because the OAuth refresh omits the RFC 8707 resource parameter. A Clerk writeup details OAuth's fragmented spec landscape and misaligned security incentives.
More from coding & agent
- Economist replicates an academic paper with a research agent, 'almost zero' manual work — soumitrashukla9 · 2026-09-11
- Warp exec runs six non-engineering teams like engineering, all on Claude Code — round · 2026-09-11
- Automating content creation: build the research pipeline first, writing comes last — EXM7777 · 2026-09-11
- Anthropic engineer on self-improving agents, and why multi-agent workflows should be graphs, not lines — Aiden_Tech_Ai · 2026-09-11
- Muse can generate a podcast on any topic; dev builds full series via MCP — RichardsonDx · 2026-09-11
- My agent spent $3.64 answering one question I thought was free — GoldBroccoli7073 · 2026-09-11