mirror of
https://github.com/openai/codex.git
synced 2026-09-03 14:59:03 +00:00
## Why OAuth discovery failures do not establish that an MCP server lacks OAuth support. Reporting those failures as `unsupported` conflates an inconclusive check with a confirmed result. ## What changed - Add an `unknown` MCP authentication status across the protocol, app server, CLI, and TUI. - Preserve OAuth discovery errors so callers can report `unknown`, while retaining `unsupported` for servers known not to support OAuth. - Document the distinction in the app server API. ## Testing - Verify transient HTTP discovery errors are preserved. - Verify `codex mcp list --json` reports `unknown` when discovery is rate limited. GitOrigin-RevId: e4562985971606740538e542ec7eeee502111964