Fixed — connector login, properly this time
v1.12.1's pin was not enough. Deeper finding: fastmcp 3.4.3 already contains the new authorize flow (CIMD, /consent interstitial, RFC 8707 resource forwarding). v1.11.0 only looked fine because existing connector sessions renew via refresh tokens — the last fresh login predated the 3.4.x flow, so the regression stayed invisible until a reconnect was needed.
The real, version-independent fix is in AICortex's own proxy construction:
forward_resource=False— the upstream IdP never sees theresourceparameter it rejects (invalid_request — "The 'resource' or 'scope' parameter is invalid", e.g. Pocket ID)require_authorization_consent="external"— no/consentinterstitial; the IdP's own (passkey) login is the consent, restoring the familiar flow
Both are signature-checked, so a fastmcp version without these kwargs can never break boot. New guard tests (tests/test_oauth_upstream.py) pin the contract against the installed fastmcp — the full suite passes against 3.4.4 (which Dependabot bumped to in #32, now safe thanks to the config fix).
Deploy: git pull && docker compose pull && docker compose up -d, then reconnect the connector in the Claude app.