“token exchange failed”
The consent screen finished and ChatGPT could not turn the authorization code into a token. The three common causes: (1) The token endpoint does not accept how ChatGPT authenticates: it sends the client credentials as an HTTP Basic Authorization header. To tell: Your token endpoint logs an invalid_client for a request carrying Authorization: Basic; the MCP Inspector, which authenticates differently, works. (2) The client ChatGPT registered was deleted or expired on the authorization server, which answers invalid_client (OpenAI's troubleshooting page). To tell: Removing and re-adding the connector fixes it until the registration is cleaned up again. (3) ChatGPT checks RFC 9207 `iss` before the exchange: a server that advertises it and returns no `iss`, or a different one, never gets the token request. To tell: The doctor shows authorization_response_iss_parameter_supported; your authorization responses lack `iss` or carry another value. One command shows which step breaks: npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client chatgpt.
Check your server now
npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client chatgpt
Discovery only: no credential, no client registration. It prints the first broken step, whose it is, and the fix with the spec section.
Who prints it
what people search after ChatGPT's connector sign-in fails at the last step (we found no ChatGPT message with exactly these words).
The three causes, and how to tell them apart
- Cause 1. The token endpoint does not accept how ChatGPT authenticates: it sends the client credentials as an HTTP Basic Authorization header.
The check fails at steptoken-auth. Your token endpoint logs an invalid_client for a request carrying Authorization: Basic; the MCP Inspector, which authenticates differently, works. - Cause 2. The client ChatGPT registered was deleted or expired on the authorization server, which answers invalid_client (OpenAI's troubleshooting page).
The check cannot see this one from outside: it happens after consent, or inside the client. Removing and re-adding the connector fixes it until the registration is cleaned up again. - Cause 3. ChatGPT checks RFC 9207 `iss` before the exchange: a server that advertises it and returns no `iss`, or a different one, never gets the token request.
The check fails at stepiss-param. The doctor shows authorization_response_iss_parameter_supported; your authorization responses lack `iss` or carry another value.
Public reports
- community.openai.com: "MCP OAuth token exchange fails in ChatGPT App, works in MCP Inspector", opened 22 December 2025: resolved by accepting ChatGPT's Basic Authorization header on /token
- Apps SDK troubleshooting, opened 8 October 2026: documents invalid_client after a deleted or expired registration (read 8 Oct 2026)
- Apps SDK authentication, opened 8 October 2026: documents the iss check before the exchange (read 8 Oct 2026)
Keep checking
Other messages
- “Authorization with the MCP server failed”
- “Couldn't reach the MCP server”
- “Failed to discover OAuth metadata”
- “Dynamic Client Registration not supported”
- “Incompatible auth server: does not support dynamic client registration”
- “Issuer mismatch”
- “invalid_redirect_uri”
- “Connection expired”
Written 8 October 2026 from the public issues above. The sign-in check · MCP Liveness · Terms · Privacy