Skip to content

fix(mcp): request offline access for Google endpoints and preserve clientSecret on refresh - #29578

Open
arsenyspb wants to merge 3 commits into
google-gemini:mainfrom
arsenyspb:fix/mcp-oauth-offline-client-secret-29577
Open

arsenyspb wants to merge 3 commits into
google-gemini:mainfrom
arsenyspb:fix/mcp-oauth-offline-client-secret-29577

Conversation

@arsenyspb

Copy link
Copy Markdown

Summary

Fixes an issue where remote MCP servers configured with OAuth 2.0 against Google endpoints (e.g. Google Workspace APIs such as Docs, Sheets, Slides, Drive) or other confidential OAuth providers fail to receive refresh tokens on initial login and fail during background token refresh, trapping users in an hourly re-authentication loop.

Details

  1. Offline Access & Consent Prompt for Google Endpoints:
    In packages/core/src/utils/oauth-flow.ts (buildAuthorizationUrl), when the authorization URL targets Google endpoints (accounts.google.com or *.google.com), automatically append access_type=offline and prompt=consent (if not already explicitly provided in the URL). This mirrors the CLI's internal OAuth login in packages/core/src/code_assist/oauth2.ts and ensures Google issues a refresh_token upon authorization code exchange instead of only a transient 1-hour access_token.

  2. clientSecret Storage & Propagation on Refresh:
    When an MCP server's OAuth client is registered with a client_secret (as is required by Google for Web/Desktop client applications during token refresh), Google's token endpoint (https://oauth2.googleapis.com/token) strictly rejects refresh requests with client_secret is missing if the secret is omitted:

    • Added optional clientSecret?: string to OAuthCredentials (packages/core/src/mcp/token-storage/types.ts).
    • Updated MCPOAuthTokenStorage.saveToken to accept and preserve clientSecret across updates.
    • Updated MCPOAuthProvider.getValidToken and MCPOAuthProvider.getValidTokenWithMetadata to resolve and forward clientSecret to refreshAccessToken and persist it on subsequent saves.
    • Updated getStoredOAuthToken (packages/core/src/tools/mcp-client.ts) to forward clientSecret from stored credentials.

Related Issues

Fixes #29577
Related to #29048

How to Validate

  1. Run unit tests for oauth-flow:
    npm test -w @google/gemini-cli-core -- src/utils/oauth-flow.test.ts
  2. Run unit tests for token storage and provider:
    npm test -w @google/gemini-cli-core -- src/mcp/oauth-token-storage.test.ts src/mcp/oauth-provider.test.ts
  3. Run lint and typecheck:
    npm run typecheck --workspace @google/gemini-cli-core
    npx eslint packages/core/src/utils/oauth-flow.ts packages/core/src/mcp/oauth-token-storage.ts packages/core/src/mcp/oauth-provider.ts packages/core/src/tools/mcp-client.ts

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

…ientSecret on refresh

Resolves google-gemini#29577

- Add access_type=offline and prompt=consent to Google authorization URLs in buildAuthorizationUrl to ensure refresh tokens are issued.
- Store clientSecret in OAuthCredentials and MCPOAuthTokenStorage.
- Forward clientSecret in getStoredOAuthToken and MCPOAuthProvider during refreshAccessToken to support confidential client refresh.
- Add unit tests in oauth-flow, oauth-token-storage, and oauth-provider test suites.
@arsenyspb
arsenyspb requested review from a team as code owners September 30, 2026 09:06
@google-cla

google-cla Bot commented Sep 30, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@github-actions github-actions Bot added the size/m A medium sized PR label Sep 30, 2026
@github-actions

Copy link
Copy Markdown

📊 PR Size: size/M

  • Lines changed: 142
  • Additions: +139
  • Deletions: -3
  • Files changed: 8

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🛑 Action Required: Evaluation Approval

Steering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged.

Maintainers:

  1. Go to the Workflow Run Summary.
  2. Click the yellow 'Review deployments' button.
  3. Select the 'eval-gate' environment and click 'Approve'.

Once approved, the evaluation results will be posted here automatically.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses authentication issues with remote MCP servers using Google OAuth 2.0. It ensures that the necessary parameters are provided during the initial authorization flow to receive refresh tokens and fixes a bug where missing client secrets caused background token refresh failures.

Highlights

  • Google OAuth Improvements: Automatically appends access_type=offline and prompt=consent to Google authorization URLs to ensure refresh tokens are issued.
  • Client Secret Persistence: Added clientSecret support to OAuthCredentials and updated storage/provider logic to preserve and propagate the secret during token refresh cycles.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds support for storing, preserving, and refreshing OAuth tokens using a clientSecret in the MCP OAuth provider and token storage. Additionally, it updates Google OAuth authorization URLs to automatically append access_type=offline and prompt=consent parameters if they are not already present. Feedback on these changes suggests using the nullish coalescing operator (??) instead of the logical OR operator (||) when resolving the clientSecret in oauth-token-storage.ts to ensure empty strings are not incorrectly overridden.

Comment thread packages/core/src/mcp/oauth-token-storage.ts
@gemini-cli

gemini-cli Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'.

This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

@arsenyspb

Copy link
Copy Markdown
Author

Hi team, I've submitted a complete fix for this in PR #29578 to fix the MCP issue #29577 .

The automated PR bot mentioned that community PRs are only reviewed if the associated issue has the help wanted label, and that my PR will be closed in 7 days otherwise. Which is fair enough from prioritization perspective.

Trying luck here, - could a maintainer please triage this issue and add the help wanted label so the PR can proceed to review?..

Thanks!

This branch is waiting to be deployed

1 waiting deployment
eval-gate — 730ad346 Waiting Oct 8, 2026 by arsenyspb via Evaluate Steering & Regressions #2154
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(mcp): MCP OAuth fails to obtain refresh_token and drops client_secret during background token refresh

1 participant