You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
MCP Registry publish 401 after a green validate: the JWT expired
The official publisher can validate server.json successfully and still fail the next command with:
Publishing to https://registry.modelcontextprotocol.io...
Error: publish failed: server returned status 401
Invalid or expired Registry JWT token
failed to parse token: token has invalid claims: token is expired
That combination is not contradictory. mcp-publisher validate proves that the manifest satisfies the Registry schema and package checks. It does not prove that the locally cached Registry JWT is fresh, and it does not refresh it. gh auth status is a different credential boundary and cannot repair this token.
One-off recovery
Keep the authentication step adjacent to publication:
Pin the publisher release and verify its official checksum before execution. Publish a unique server version; Registry versions are immutable, so rerunning the same version is not an update.
Production proof
KnownFix reproduced the expired-token 401 on 2026-08-27 immediately after the same server.json passed validation. We then moved Registry publication to a least-privilege GitHub OIDC job, checksum-pinned mcp-publisher v1.8.1, and published io.github.b-hash88/knownfix version 0.3.15 successfully.
This report verifies interactive GitHub login and GitHub Actions OIDC publication. It does not test DNS or HTTP namespace authentication. The checksum cited by the implementation is release- and platform-specific; re-resolve it from the official release when changing publisher version or runner architecture.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
MCP Registry publish 401 after a green validate: the JWT expired
The official publisher can validate
server.jsonsuccessfully and still fail the next command with:That combination is not contradictory.
mcp-publisher validateproves that the manifest satisfies the Registry schema and package checks. It does not prove that the locally cached Registry JWT is fresh, and it does not refresh it.gh auth statusis a different credential boundary and cannot repair this token.One-off recovery
Keep the authentication step adjacent to publication:
Treat the issued JWT as a secret. Do not print it, commit it, copy it into an agent prompt, or persist it as a repository variable.
Recurring GitHub publication
For a GitHub-hosted release workflow, avoid a long-lived Registry credential. Give only the publication job the permissions required for GitHub OIDC:
Pin the publisher release and verify its official checksum before execution. Publish a unique server version; Registry versions are immutable, so rerunning the same version is not an update.
Production proof
KnownFix reproduced the expired-token 401 on 2026-08-27 immediately after the same
server.jsonpassed validation. We then moved Registry publication to a least-privilege GitHub OIDC job, checksum-pinnedmcp-publisherv1.8.1, and publishedio.github.b-hash88/knownfixversion0.3.15successfully.Limits
This report verifies interactive GitHub login and GitHub Actions OIDC publication. It does not test DNS or HTTP namespace authentication. The checksum cited by the implementation is release- and platform-specific; re-resolve it from the official release when changing publisher version or runner architecture.
All reactions