“Incompatible auth server: does not support dynamic client registration”

The client needed to register itself, and the authorization server offered no registration it could use and no client ID was configured. The three common causes: (1) No `registration_endpoint`, no client ID metadata documents, and no pre-registered client ID passed to the client. To tell: The doctor warns at client registration; Claude Code accepts `--client-id`, Cursor a static `auth` block. (2) Cursor: the registration request itself failed (for example a 500 on its three-redirect-URI payload) and was reported as unsupported. To tell: The doctor passes client registration; your registration endpoint's log shows a failed POST. (3) Claude Code before 2.1.248 ran OAuth discovery even when a headers helper already supplied the credential. To tell: You authenticate with a header, not OAuth; update Claude Code. One command shows which step breaks: npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp.

Check your server now

npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp

Discovery only: no credential, no client registration. It prints the first broken step, whose it is, and the fix with the spec section.

Who prints it

the MCP TypeScript SDK, so Claude Code, Cursor and other clients built on it. 261 issues across GitHub, 50 in anthropics/claude-code, counted 8 October 2026.

The three causes, and how to tell them apart

  1. Cause 1. No `registration_endpoint`, no client ID metadata documents, and no pre-registered client ID passed to the client.
    The check fails at step dcr. The doctor warns at client registration; Claude Code accepts `--client-id`, Cursor a static `auth` block.
  2. Cause 2. Cursor: the registration request itself failed (for example a 500 on its three-redirect-URI payload) and was reported as unsupported.
    The check cannot see this one from outside: it happens after consent, or inside the client. The doctor passes client registration; your registration endpoint's log shows a failed POST.
  3. Cause 3. Claude Code before 2.1.248 ran OAuth discovery even when a headers helper already supplied the credential.
    The check cannot see this one from outside: it happens after consent, or inside the client. You authenticate with a header, not OAuth; update Claude Code.

Public reports

Keep checking

Re-check it every hour and email me when a step breaks: agentcheck's free watch, no account — it follows the sign-in a new client follows, with these same rules.

Nightly, with history: mcpcheck Server Pro re-runs these sign-in checks against the server every night, with 90 days of history, and emails when one fails ($49 a server a month; the first run is free).

Other messages

Written 8 October 2026 from the public issues above. The sign-in check · MCP Liveness · Terms · Privacy