Skip to content

Add manual callback input to MCP OAuth login - #44629

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/16ea9c3221f72d93e6e3e5acdc6b9465293a0a65
Sep 10, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/16ea9c3221f72d93e6e3e5acdc6b9465293a0a65

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Add manual callback input to MCP OAuth login

Why

Allow MCP authentication to complete when the browser cannot reach the callback page by accepting the full redirect URL copied from its address bar.

What changed

  • Add codex mcp login --no-browser to print the authorization URL and accept a pasted callback without launching a browser. HTTP callbacks remain supported while waiting for input.
  • Validate pasted redirect URLs and OAuth responses before exchanging tokens, hide terminal input, bound input size, and avoid echoing callback values in diagnostics.
  • Preserve manual input across discovered-scope retries and support cancellation during callback input and token exchange.

Testing

Add unit and CLI integration tests for callback validation, bounded input, credential storage, HTTP callback completion with stdin open, scope retries, and cancellation during token exchange.

## Why

Allow MCP authentication to complete when the browser cannot reach the callback page by accepting the full redirect URL copied from its address bar.

## What changed

- Add `codex mcp login  --no-browser` to print the authorization URL and accept a pasted callback without launching a browser. HTTP callbacks remain supported while waiting for input.
- Validate pasted redirect URLs and OAuth responses before exchanging tokens, hide terminal input, bound input size, and avoid echoing callback values in diagnostics.
- Preserve manual input across discovered-scope retries and support cancellation during callback input and token exchange.

## Testing

Add unit and CLI integration tests for callback validation, bounded input, credential storage, HTTP callback completion with stdin open, scope retries, and cancellation during token exchange.

GitOrigin-RevId: 16ea9c3221f72d93e6e3e5acdc6b9465293a0a65
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/16ea9c3221f72d93e6e3e5acdc6b9465293a0a65 branch from 00cc867 to f8ab573 Compare September 10, 2026 19:52
@copyberry
copyberry Bot merged commit f8ab573 into main Sep 10, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/16ea9c3221f72d93e6e3e5acdc6b9465293a0a65 branch September 10, 2026 19:52
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 10, 2026

This branch was previously deployed

1 inactive deployment
issue-triage — f8ab5735 Deployed Sep 10, 2026 by muqiao215 via Translate non-English issue #12525
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants