“token exchange failed”

The consent screen finished and ChatGPT could not turn the authorization code into a token. The three common causes: (1) The token endpoint does not accept how ChatGPT authenticates: it sends the client credentials as an HTTP Basic Authorization header. To tell: Your token endpoint logs an invalid_client for a request carrying Authorization: Basic; the MCP Inspector, which authenticates differently, works. (2) The client ChatGPT registered was deleted or expired on the authorization server, which answers invalid_client (OpenAI's troubleshooting page). To tell: Removing and re-adding the connector fixes it until the registration is cleaned up again. (3) ChatGPT checks RFC 9207 `iss` before the exchange: a server that advertises it and returns no `iss`, or a different one, never gets the token request. To tell: The doctor shows authorization_response_iss_parameter_supported; your authorization responses lack `iss` or carry another value. One command shows which step breaks: npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client chatgpt.

Check your server now

npx --allow-git=root github:agentwares/mcp-oauth-doctor https://your-server.example/mcp --client chatgpt

Discovery only: no credential, no client registration. It prints the first broken step, whose it is, and the fix with the spec section.

Who prints it

what people search after ChatGPT's connector sign-in fails at the last step (we found no ChatGPT message with exactly these words).

The three causes, and how to tell them apart

  1. Cause 1. The token endpoint does not accept how ChatGPT authenticates: it sends the client credentials as an HTTP Basic Authorization header.
    The check fails at step token-auth. Your token endpoint logs an invalid_client for a request carrying Authorization: Basic; the MCP Inspector, which authenticates differently, works.
  2. Cause 2. The client ChatGPT registered was deleted or expired on the authorization server, which answers invalid_client (OpenAI's troubleshooting page).
    The check cannot see this one from outside: it happens after consent, or inside the client. Removing and re-adding the connector fixes it until the registration is cleaned up again.
  3. Cause 3. ChatGPT checks RFC 9207 `iss` before the exchange: a server that advertises it and returns no `iss`, or a different one, never gets the token request.
    The check fails at step iss-param. The doctor shows authorization_response_iss_parameter_supported; your authorization responses lack `iss` or carry another value.

Public reports

Keep checking

Re-check it every hour and email me when a step breaks: agentcheck's free watch, no account — it follows the sign-in a new client follows, with these same rules.

Nightly, with history: mcpcheck Server Pro re-runs these sign-in checks against the server every night, with 90 days of history, and emails when one fails ($49 a server a month; the first run is free).

Other messages

Written 8 October 2026 from the public issues above. The sign-in check · MCP Liveness · Terms · Privacy