“Dynamic Client Registration not supported”

The client found the authorization server but no way to register itself, so it asks for a client ID created by hand. The three common causes: (1) The authorization server publishes no `registration_endpoint` and does not advertise client ID metadata documents (GitHub, Slack and Entra apps are common cases). To tell: The doctor warns at client registration: "no registration_endpoint and no client_id_metadata_document_supported". (2) The authorization server's metadata could not be fetched at all (network, CORS or the wrong location), and VS Code reports that the same way. To tell: The doctor fails at authorization-server metadata. (3) The 401 has no WWW-Authenticate header, the client falls back to the root well-known document, and that document's `resource` does not match. To tell: The doctor warns at the challenge and at `resource`. One command shows which step breaks: npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client vscode.

Check your server now

npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client vscode

Discovery only: no credential, no client registration. It prints the first broken step, whose it is, and the fix with the spec section.

Who prints it

VS Code (a dialog), and the Codex CLI. 6 issues in microsoft/vscode and 5 in openai/codex, counted 8 October 2026.

The three causes, and how to tell them apart

  1. Cause 1. The authorization server publishes no `registration_endpoint` and does not advertise client ID metadata documents (GitHub, Slack and Entra apps are common cases).
    The check fails at step dcr. The doctor warns at client registration: "no registration_endpoint and no client_id_metadata_document_supported".
  2. Cause 2. The authorization server's metadata could not be fetched at all (network, CORS or the wrong location), and VS Code reports that the same way.
    The check fails at step as-metadata. The doctor fails at authorization-server metadata.
  3. Cause 3. The 401 has no WWW-Authenticate header, the client falls back to the root well-known document, and that document's `resource` does not match.
    The check fails at step prm-resource. The doctor warns at the challenge and at `resource`.

Public reports

Keep checking

Re-check it every hour and email me when a step breaks: agentcheck's free watch, no account — it follows the sign-in a new client follows, with these same rules.

Nightly, with history: mcpcheck Server Pro re-runs these sign-in checks against the server every night, with 90 days of history, and emails when one fails ($49 a server a month; the first run is free).

Other messages

Written 8 October 2026 from the public issues above. The sign-in check · MCP Liveness · Terms · Privacy