Repository navigation
MCP server returning 401 is retried forever (18+ failures, every 300 s) with no needs-auth state in the UI #6412
Description
Activity
- addedmcp-rpcMCP transport, tool registry, JSON-RPC, and core relay surfaces.MCP transport, tool registry, JSON-RPC, and core relay surfaces.priority: p2Soon. Real but survivable — a rough edge, a gap, a thing that will bite later.Soon. Real but survivable — a rough edge, a gap, a thing that will bite later.
on Sep 21, 2026 - addedpriority: p1Next. Wrong behaviour a user will hit, or a security weakness behind a condition.Next. Wrong behaviour a user will hit, or a security weakness behind a condition.and removedpriority: p2Soon. Real but survivable — a rough edge, a gap, a thing that will bite later.Soon. Real but survivable — a rough edge, a gap, a thing that will bite later.
on Sep 21, 2026 MCP server returning 401 is retried forever with exponential backoff capped at 300s, causing log noise and no user-visible auth-required state. Fix should halt retries on 401/403, mark the server as needing auth in the MCP Servers page, and provide a Set token action.
Labelled
priority: p1.Still reproduces on
0f1ecc9d28d85289ee3f87ade13156be02ffbd28— and the reason is a delivery gap, not a missing fix.The fix exists upstream. tinyhumansai/tinymcp#20 ("Park a server whose credential was rejected instead of retrying it forever") merged 2026-09-22T20:48Z as
10786a472e3c17b796c4c173a0e4647ed916b120.It has not been delivered here.
vendor/tinymcpon main is pinned atfe34f5b8c89a49e6f7ca05c2da791bb34550f85f:$ git ls-tree 0f1ecc9d2 vendor/tinymcp 160000 commit fe34f5b8c89a49e6f7ca05c2da791bb34550f85f vendor/tinymcp $ gh api repos/tinyhumansai/tinymcp/compare/10786a472...fe34f5b8c --jq '{status,behind_by}' {"status":"behind","behind_by":2}The pinned commit is dated 2026-09-19; the fix merged three days later. The pin is behind the fix, so it cannot contain it. Every build cut from main still runs the old retry loop.
What's needed: a
vendor/tinymcpgitlink bump to a tinymcp commit at or after10786a472. Nothing in this repo needs changing — the retry/backoff and theneeds_authstate are both submodule-side.Test that would prove delivery: assert the pin contains the fix rather than eyeballing it, e.g. a CI step running
git -C vendor/tinymcp merge-base --is-ancestor 10786a472 HEAD. More generally, the recurring failure mode here is that a merged submodule PR reads as "fixed" while users still run the old code — #6411 and #6415 are in the same position against the same pin.- added a commit that references this issue
on Sep 23, 2026 - added a commit that references this issue
on Sep 23, 2026
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsDone
Description
An MCP server whose credential was never saved (
https://api.inference.sh, HTTP 401) is retried forever. Backoff grows to 300 s and then stays there; 18+ failures logged in one session with no circuit breaker, no UI indicator that the server needs auth, and no way to see it from the MCP Servers page.Reported by: Alan (QA)
Build: v0.63.29
Reproducible: Yes
Steps to reproduce
Expected behaviour
Actual behaviour
Impact
Acceptance criteria
needs_authstate visible on the MCP Servers page