{"version":"2.1.284","anchor":"mcp-oauth-discovery-invalidation-keeps-the-auth-server-poin","canonical_anchor":"mcp-oauth-tokens-persist-more-discovery-metadata","heading":"MCP OAuth keeps fuller sign-in discovery details and no longer throws them away","tier":"internal","area":"MCP","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/mcp-oauth-discovery-invalidation-keeps-the-auth-server-poin","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### MCP OAuth keeps fuller sign-in discovery details and no longer throws them away\n\nStored MCP OAuth credentials now remember which auth server and metadata URL were used, and keep them across refreshes and invalidation\n\n**Unclear.** The exact sign-in problem you would have seen before is not settled.\n\n**What**\n\nWhen you sign in to an MCP server (an external tool server Claude Code connects to) with OAuth, Claude Code stores details of how it found the server's sign-in service, in `discoveryState`. Before, only `authorizationServerUrl` was kept. Now it keeps more and loses less.\n\n- `discoveryState` now also keeps `oauthMetadataFound` and `authServerMetadataUrl` alongside `authorizationServerUrl`, including when credentials are copied or saved.\n\n- `saveTokens` now writes a merged `discoveryState` with the authorization server used at sign-in (discovered or overridden), the metadata URL that was served, and whether the sign-in was interactive. Plain token saves used to leave it alone.\n\n- After an interactive sign-in, a helper builds the stored state, sets `oauthMetadataFound: true` and clears `authServerMetadataUrl` to null. A non-interactive refresh keeps the previous value.\n\n- A new internal flag, `_flowDiscoveryStateFromConfiguredUrl`, tracks whether the sign-in's discovery state came from a configured metadata URL; when it did, the overridden authorization server URL is taken from that state.\n\n- `invalidateCredentials('discovery')` now keeps a trimmed copy (authorization server, `oauthMetadataFound`, `authServerMetadataUrl`) instead of clearing it.\n\n- `saveDiscoveryState` merges with the previous state, records which configured `authServerMetadataUrl` served the metadata, and keeps an earlier `registrationNotOfferedAt` when no metadata came back.\n\n- The XAA silent refresh records which server issued the token by merging, instead of overwriting `discoveryState`.\n\n**Why**\n\nLater token refreshes and re-sign-ins can go back to the same authorization server that issued the token, rather than losing that pointer. This matters most for MCP servers with a configured or non-standard metadata URL.\n\n- Area: MCP\n- Names: `authServerMetadataUrl`\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5"}