You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
After the -32601/server/discover fatal-failure bug (#4870) was fixed in 1.0.87-0, the Figma remote MCP server (https://mcp.figma.com/mcp) now progresses much further through the OAuth flow — client registration succeeds, the browser consent screen works, and the CLI logs Completing authentication... — but the token exchange itself fails with:
OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
This happens on every attempt, with fresh, unused authorization codes, correct PKCE verifiers, and a client that was successfully registered days earlier (so this is not the client_name DCR 403 described in #4906 — registration is not the failure point here).
Environment
GitHub Copilot CLI: 1.0.87-0
OS: Linux (devcontainer, aarch64)
Figma MCP server: https://mcp.figma.com/mcp
Registered OAuth client: dynamically registered days earlier via DCR, token_endpoint_auth_method unknown (both client_secret_post and client_secret_basic are advertised as supported per Figma's .well-known/oauth-authorization-server metadata)
Trigger authentication (/mcp → figma → Authenticate, or reconnect after a 401).
Complete the browser consent screen; the CLI receives the redirect and logs Completing authentication....
Immediately after, authentication fails:
ERROR OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
Log excerpt
2026-09-21T09:08:22.351Z [ERROR] Completing authentication...
2026-09-21T09:08:22.565Z [ERROR] OAuth authentication failed for figma: MCPOAuthError: Token exchange failed: Failed to parse server response
2026-09-21T09:08:22.566Z [WARNING] HTTP 401 challenge (WWW-Authenticate: ...authorization_uri="https://api.figma.com/.well-known/oauth-authorization-server") {"server":"figma"}
Investigation so far
Manually replaying the same authorization code directly against POST https://api.figma.com/v1/oauth/token (per RFC 8414 discovery, the real token endpoint is https://api.figma.com/v1/oauth/token, not/oauth/token) after the CLI's attempt returns a clean, well-formed JSON invalid_grant error — consistent with the code already being single-use-consumed by the CLI's own (failed) exchange attempt. This suggests the CLI's request did reach the token endpoint and did receive a response (invalid_grant errors from Figma are clean, parseable JSON), but something about a successful response body apparently trips up the CLI's parser — the error text is specifically "Failed to parse server response", not a network/timeout/auth error.
Not fixed by re-authenticating, restarting the CLI, or using a completely fresh browser-based (non-relayed) OAuth attempt.
Suggested next step
Capture/log the raw HTTP response body (status + headers + body) when a token-exchange parse failure occurs, so the actual shape of Figma's response can be compared against what the CLI's OAuth client expects (e.g. extra/missing fields, unexpected token_type casing, non-standard field names, etc.).
Summary
After the
-32601/server/discoverfatal-failure bug (#4870) was fixed in 1.0.87-0, the Figma remote MCP server (https://mcp.figma.com/mcp) now progresses much further through the OAuth flow — client registration succeeds, the browser consent screen works, and the CLI logsCompleting authentication...— but the token exchange itself fails with:This happens on every attempt, with fresh, unused authorization codes, correct PKCE verifiers, and a client that was successfully registered days earlier (so this is not the client_name DCR 403 described in #4906 — registration is not the failure point here).
Environment
https://mcp.figma.com/mcptoken_endpoint_auth_methodunknown (bothclient_secret_postandclient_secret_basicare advertised as supported per Figma's.well-known/oauth-authorization-servermetadata)Steps to reproduce
{ "mcpServers": { "figma": { "type": "http", "url": "https://mcp.figma.com/mcp", "tools": ["*"] } } }/mcp→ figma → Authenticate, or reconnect after a 401).Completing authentication....Log excerpt
Investigation so far
POST https://api.figma.com/v1/oauth/token(per RFC 8414 discovery, the real token endpoint ishttps://api.figma.com/v1/oauth/token, not/oauth/token) after the CLI's attempt returns a clean, well-formed JSONinvalid_granterror — consistent with the code already being single-use-consumed by the CLI's own (failed) exchange attempt. This suggests the CLI's request did reach the token endpoint and did receive a response (invalid_grant errors from Figma are clean, parseable JSON), but something about a successful response body apparently trips up the CLI's parser — the error text is specifically "Failed to parse server response", not a network/timeout/auth error.client_name403 issue — our client was registered successfully well before this session (no 403 at registration time), and the failure occurs at the token exchange step, after a successful consent screen.Suggested next step
Capture/log the raw HTTP response body (status + headers + body) when a token-exchange parse failure occurs, so the actual shape of Figma's response can be compared against what the CLI's OAuth client expects (e.g. extra/missing fields, unexpected
token_typecasing, non-standard field names, etc.).