“Dynamic Client Registration not supported”
The client found the authorization server but no way to register itself, so it asks for a client ID created by hand. The three common causes: (1) The authorization server publishes no `registration_endpoint` and does not advertise client ID metadata documents (GitHub, Slack and Entra apps are common cases). To tell: The doctor warns at client registration: "no registration_endpoint and no client_id_metadata_document_supported". (2) The authorization server's metadata could not be fetched at all (network, CORS or the wrong location), and VS Code reports that the same way. To tell: The doctor fails at authorization-server metadata. (3) The 401 has no WWW-Authenticate header, the client falls back to the root well-known document, and that document's `resource` does not match. To tell: The doctor warns at the challenge and at `resource`. One command shows which step breaks: npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client vscode.
Check your server now
npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client vscode
Discovery only: no credential, no client registration. It prints the first broken step, whose it is, and the fix with the spec section.
Who prints it
VS Code (a dialog), and the Codex CLI. 6 issues in microsoft/vscode and 5 in openai/codex, counted 8 October 2026.
The three causes, and how to tell them apart
- Cause 1. The authorization server publishes no `registration_endpoint` and does not advertise client ID metadata documents (GitHub, Slack and Entra apps are common cases).
The check fails at stepdcr. The doctor warns at client registration: "no registration_endpoint and no client_id_metadata_document_supported". - Cause 2. The authorization server's metadata could not be fetched at all (network, CORS or the wrong location), and VS Code reports that the same way.
The check fails at stepas-metadata. The doctor fails at authorization-server metadata. - Cause 3. The 401 has no WWW-Authenticate header, the client falls back to the root well-known document, and that document's `resource` does not match.
The check fails at stepprm-resource. The doctor warns at the challenge and at `resource`.
Public reports
- microsoft/vscode#276513, opened 10 November 2025: a 1.105 to 1.106 regression; a maintainer traced it to how a failed metadata fetch was handled
- microsoft/vscode#279955, opened 28 November 2025: DCR issues in MCP servers: no WWW-Authenticate, root-fallback resource mismatch
- openai/codex#13200, opened 2 March 2026: codex mcp login against Slack's official server; 66 reactions, open
- github/github-mcp-server#1404, opened 13 November 2025: the same dialog with VS Code 1.106; closed
Keep checking
Other messages
- “Authorization with the MCP server failed”
- “Couldn't reach the MCP server”
- “Failed to discover OAuth metadata”
- “Incompatible auth server: does not support dynamic client registration”
- “Issuer mismatch”
- “invalid_redirect_uri”
- “Connection expired”
- “token exchange failed”
Written 8 October 2026 from the public issues above. The sign-in check · MCP Liveness · Terms · Privacy