Repository navigation
plat 708
| Field | Value |
|---|---|
| State | fixed on main |
| Priority | P1 |
| Product | vault |
| Area | apps |
| Summary | Vercel rejects dynamic client registration for any hosted callback; we then linked people to vercel.com/oauth/authorize with no client. Now the registration error is logged and shown, and no authorize URL is given without a client. |
Confida, 2026-10-07 16:38 CEST: a person picked Vercel in Vault → Add app (PLAT-670).
The agent log showed Dynamic client registration failed for Vercel: ... status 400
then No client_id for Vercel, returning needs_client_id response, yet Vercel showed
"App configuration error: The app ID is invalid / The app redirect URL is invalid".
Two faults:
-
Vercel's DCR only accepts approved redirect hosts. Tested from a laptop with the exact body we send (
token_endpoint_auth_method: none,authorization_code+refresh_token,code,client_name: AgentWorks) againsthttps://api.vercel.com/login/oauth/register:-
http://localhost:8000/api/oauth/callback,http://127.0.0.1:...,https://claude.ai/api/mcp/auth_callback,cursor://...→ 201 -
https://<confida host>/api/oauth/callback,https://agentworkshq.com/...,https://example.com/...→ 400{"error":"invalid_redirect_uri","error_description":"The provided redirect URIs are not approved for use by this authorization server."}
So the request body is fine; Vercel allowlists known clients' callbacks and a hosted AgentWorks callback cannot self-register. Nothing in the request can change that.
-
-
We opened an authorize URL anyway. The
needs_client_idreply carried the provider'sauth_url(the bare authorization endpoint), and the Vault screen linked the first URL in the tool reply. Place MCP connect also opened anyauth_urlbefore checkingneeds_client_id.
- mcpagent
c13ab2a:RegisterClientreturns*oauth.RegistrationErrorwith the RFC 7591error/error_descriptionand a truncated one-line body (a rejection holds no secret). - agent_go
runOAuthFlow: logs the error with the redirect URI; theneeds_client_idreply no longer hasauth_url/token_urland, after a failed registration, says " sign-in couldn't be set up automatically: the provider rejected the app registration: . An admin can register an OAuth app for it, or store its API key as a Vault secret." - Vault person tool (
connect/sign_in): no sign-in JSON when there is no client;connectkeeps the connection and returns that text,sign_inreturns it as an error. - Vault screen links only the reply's
auth_urland otherwise shows the reply text; place MCP connect checksneeds_client_idbefore opening anything. - Test:
TestFailedRegistrationReturnsNoAuthorizeURL(agent_go), andTestRegisterClientRejectionKeepsTheProviderReason(mcpagent).
Apps whose sign-in cannot start on its own stay in Vault → Add app but carry a "Needs admin setup" badge (tooltip: "Sign-in can't be set up automatically here; an admin can register an OAuth app for it, or use an API key as a Vault secret") and sort last. They can still be picked; the error above explains.
- The
appsoperation returnsneeds_admin_setup: truefor an OAuth app with no configured client (none in the config, no deployment sign-in app) when it has noregistration_endpoint, needs a hand-registered confidential client, or already rejected this server's callback. - Rejections are remembered in
<tokens root>/_platform/registration_failures.json, keyed by registration endpoint + callback, written where the RegistrationError is logged inrunOAuthFlow(provider rejections only, not network errors); a later successful registration removes the entry, and a configured client overrides it. - Workflow/Crew connect messages name the catalog app ("Vercel"), not the internal server name.
- Test:
TestFailedRegistrationReturnsNoAuthorizeURLnow also checks the apps list marks and sorts Vercel, and that a configured client clears the mark.
- Vercel itself cannot be connected from a hosted server unless Vercel approves our callback or an admin enters a Vercel OAuth client by hand. Asking Vercel to approve the AgentWorks callback is the remaining option.
- A server only learns of a rejection after someone tries; until then Vercel shows as a normal sign-in app there.
- Not deployed.
Auto-synced from docs/ on main. Edit there, not here.