Skip to content

v1.0.8 — Fix Bearer token auth on /brain URL

Choose a tag to compare

@nickhamze nickhamze released this 21 Mar 03:23
· 39 commits to main since this release

Root cause of "Authorization with the MCP server failed"

This release fixes the actual root cause of the authorization failure when connecting Claude or other MCP clients.

What was broken

When an MCP client sends requests to the /brain pretty-URL (e.g. https://yoursite.com/brain), WordPress's rewrite rule routes the request internally to /pressocampus/v1/mcp — but REQUEST_URI stays as /brain.

The Bearer-token authentication filter checked only REQUEST_URI to decide whether to handle the request. Since /brain doesn't contain /pressocampus/v1/, the filter returned early and never validated the token. Every authenticated request returned 401, even after the user had successfully completed the OAuth flow.

From Claude's perspective: it completed authorization, got a valid token, sent it on every subsequent request, and received 401 every time. This is what triggered "Authorization with the MCP server failed."

The fix

The filter now also checks $GLOBALS['wp']->query_vars['rest_route'], which is populated by the rewrite rule and always contains the real REST path (/pressocampus/v1/mcp). The same fix was applied to the WWW-Authenticate header filter.


This is the upgrade to install if you've been seeing the authorization failure error.