Skip to content

OAuth2 Discovery method fails because FastMCP with GoogleProvider (OAuth) returns issuerUrl with trailing slash #7265

Description

@idofl

The OAuth2DiscoveryManager‎.discover_auth_server_metadata‎ function retrieves a remote MCP Server's discovery document, to initialize the tool's AuthScheme object.
The function compares the returned issuer URL to the provided issuer URL to defend against MIX-UP attacks (as documented):
if metadata.issuer == issuer_url.rstrip("/"):

However, if the returned issuer has a trailing slash ('/'), as is the case when using FastMCP and the GoogleProvider, the function fails to compare the issuer values and no metadata is returned.

The correct code should be:
if metadata.issuer.rstrip("/") == issuer_url.rstrip("/"):

This is an example of what FastMCP is returning when using SSE transport with a GoogleProvider:

{
"issuer": "http://localhost:8080/",
"authorization_endpoint": "http://localhost:8080/authorize",
"token_endpoint": "http://localhost:8080/token",
"registration_endpoint": "http://localhost:8080/register",
"scopes_supported": [
   "openid",
   "https://www.googleapis.com/auth/userinfo.email"
],
"response_types_supported": [
   "code"
],
"grant_types_supported": [
   "authorization_code",
   "refresh_token"
],
"token_endpoint_auth_methods_supported": [
   "client_secret_post",
   "client_secret_basic",
   "private_key_jwt",
   "none"
],
"code_challenge_methods_supported": [
   "S256"
],
"client_id_metadata_document_supported": true
}

Activity

  1. chelsealong commented on Sep 24, 2026

    @chelsealong
    Contributor

    Picking this one up now — opening a PR shortly. Flagging it here so nobody duplicates the work; if someone is already on it, say so and I will drop mine.

  2. added
    mcp[Component] This issues is related to MCP support
    on Sep 25, 2026
  3. sanketpatil06 commented on Sep 25, 2026

    @sanketpatil06

    Hi @idofl, thanks for reporting this. A fix has been opened in PR #7268. Please feel free to test the PR branch and let us know if it resolves the issue on your end. The team will merge it once review is complete.

  4. idofl commented on Sep 27, 2026

    @idofl
    Author

    I reviewed the change and it looks good to me. Thank you for the quick fix.

  5. deleted a comment from OssAgenticsT on Oct 6, 2026
  6. added a commit that references this issue on Oct 9, 2026
    c220fca
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

mcp[Component] This issues is related to MCP support

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions