What feature would you like to see?
Add an explicit, per-MCP trusted OAuth issuer override for remote MCP servers whose protected-resource metadata points to an authorization-server URL that publishes a different issuer.
Suggested configuration shape:
[mcp_servers.meta-ads]
url = "https://mcp.facebook.com/ads"
oauth_expected_issuer = "https://www.facebook.com"
The override should be opt-in, scoped to one exact MCP server URL, require an absolute HTTPS issuer URL, and preserve strict issuer validation for every server without the setting. Codex should still validate the authorization response and token exchange against the configured issuer. A warning during login would make the exception visible.
What problem would this solve?
Meta's official hosted MCP endpoints currently publish internally inconsistent OAuth discovery metadata. Codex CLI 0.147.0 rejects both before opening the browser.
For Meta Ads:
GET https://mcp.facebook.com/.well-known/oauth-protected-resource/ads
resource: https://mcp.facebook.com/ads
authorization_servers[0]: https://mcp.facebook.com/ads
GET https://mcp.facebook.com/.well-known/oauth-authorization-server/ads
issuer: https://www.facebook.com
authorization_endpoint: https://www.facebook.com/v26.0/dialog/oauth
token_endpoint: https://graph.facebook.com/v26.0/oauth/access_token
For Meta Developer Tools:
GET https://mcp.facebook.com/.well-known/oauth-protected-resource/devtools
resource: https://mcp.facebook.com/devtools
authorization_servers[0]: https://mcp.facebook.com/devtools
GET https://mcp.facebook.com/.well-known/oauth-authorization-server/devtools
issuer: https://www.facebook.com
authorization_endpoint: https://www.facebook.com/v26.0/dialog/oauth
token_endpoint: https://graph.facebook.com/v26.0/oauth/access_token
Reproduction:
codex mcp add meta-ads --url https://mcp.facebook.com/ads
codex mcp login meta-ads
Actual result:
Error: Authorization server issuer mismatch: expected https://mcp.facebook.com/ads, received https://www.facebook.com
The same failure occurs for https://mcp.facebook.com/devtools.
Meta should ideally correct its discovery metadata. Until then, a per-server explicit override would provide a bounded compatibility path without weakening issuer checks globally. A same-registrable-domain heuristic would be too broad; the requested setting should compare exact configured URLs only.
Environment:
Codex CLI: 0.147.0
macOS: Apple Silicon
Transport: streamable_http
Authentication: OAuth
This is distinct from #35459, which reports a Meta Ads streamable-HTTP handshake failure after OAuth has already completed. This request concerns the earlier discovery/issuer-validation stage.
What feature would you like to see?
Add an explicit, per-MCP trusted OAuth issuer override for remote MCP servers whose protected-resource metadata points to an authorization-server URL that publishes a different issuer.
Suggested configuration shape:
The override should be opt-in, scoped to one exact MCP server URL, require an absolute HTTPS issuer URL, and preserve strict issuer validation for every server without the setting. Codex should still validate the authorization response and token exchange against the configured issuer. A warning during login would make the exception visible.
What problem would this solve?
Meta's official hosted MCP endpoints currently publish internally inconsistent OAuth discovery metadata. Codex CLI 0.147.0 rejects both before opening the browser.
For Meta Ads:
For Meta Developer Tools:
Reproduction:
Actual result:
The same failure occurs for
https://mcp.facebook.com/devtools.Meta should ideally correct its discovery metadata. Until then, a per-server explicit override would provide a bounded compatibility path without weakening issuer checks globally. A same-registrable-domain heuristic would be too broad; the requested setting should compare exact configured URLs only.
Environment:
This is distinct from #35459, which reports a Meta Ads streamable-HTTP handshake failure after OAuth has already completed. This request concerns the earlier discovery/issuer-validation stage.