I'm having an OAuth Dynamic Registration issue using the Sprites MCP from a power that I am developing for Sprites. The "Sprites power" mentioned is currently a WIP. I ran into this issue while testing its implementation.
Before opening, please confirm
Operating System
macOS 26.7
Kiro Version
- IDE: 1.1.70 (build dated September 23, 2026)
- CLI: 2.24.1, using
kiro-cli --v3 chat
- Observed September 28, 2026 in both IDE and CLI.
Bug Description
The Sprites power installs and its skills load, but its Streamable HTTP MCP server fails during OAuth Dynamic Client Registration, before browser authorization. No Sprites MCP tools become available.
The authorization server advertises none and client_secret_post. Inspection of the installed CLI runtime indicates that Kiro's OAuth provider omits token_endpoint_auth_method from its client registration metadata. The registration helper serializes that metadata into the POST body. Omission defaults to client_secret_basic under RFC 7591, which this server does not support.
This is a registration-request issue, not a missing field in the server's discovery response. The omission was identified through local runtime inspection, not a captured network request. Both IDE and CLI logs independently confirm the registration rejection below.
Steps to Reproduce
- Install a local Agent Plugins power with a remote MCP entry pointing to Sprites. The relevant
mcp.json is:
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/mcp.schema.json",
"mcpServers": {
"sprites": {
"type": "streamable-http",
"url": "https://sprites.dev/mcp"
}
}
}
For a minimal package, pair this with a plugin.json such as:
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "sprites",
"version": "1.0.0",
"description": "Connect to the Sprites MCP server.",
"author": { "name": "Fly.io" },
"keywords": ["sprites"]
}
- In the IDE, use Powers → Add Custom Power → Import power from a folder. Activate it by asking: “Use the Sprites power to check my connection and list my Sprites. Don't create or modify anything.”
- With the power installed, also start
kiro-cli --v3 chat and inspect /mcp or make the same request.
- Inspect the MCP connection logs. Registration fails before the browser sign-in flow.
The observed package also contains Sprites skills; the files above isolate its manifest and MCP configuration without requiring those instructions.
Actual Behavior
Both surfaces report:
Dynamic Client Registration rejected (HTTP 400): {"error":"invalid_client_metadata","error_description":"token_endpoint_auth_method must be 'none' or 'client_secret_post'"}
In the CLI, the callback listener starts successfully, registration fails, and the listener is stopped. Skills remain available, but the MCP tools do not load.
Expected Behavior
Kiro should explicitly select a supported client authentication method during dynamic registration. For a public-client flow against this server, submit:
"token_endpoint_auth_method": "none"
Then proceed with browser authorization and PKCE. This is a proposed fix for the observed registration blocker; the remainder of the flow has not been verified with a patched client.
Additional Context
The public discovery endpoint, https://sprites.dev/.well-known/oauth-authorization-server, advertises:
{
"registration_endpoint": "https://sprites.dev/oauth/register",
"token_endpoint_auth_methods_supported": ["none", "client_secret_post"],
"code_challenge_methods_supported": ["S256"]
}
Related: #3908, especially the report of requesting client_secret_basic despite advertised none/client_secret_post, and the subsequent confirmation that version 0.8.140 resolved it. Here, the inspected runtime omits the field rather than explicitly setting client_secret_basic. This may be a recurrence or a different implementation path; no known-good version comparison has been performed for Sprites.
References:
This report was generated in part by OpenAI Codex from local configuration, application logs, and inspection of the installed CLI runtime.
I'm having an OAuth Dynamic Registration issue using the Sprites MCP from a power that I am developing for Sprites. The "Sprites power" mentioned is currently a WIP. I ran into this issue while testing its implementation.
Before opening, please confirm
Operating System
macOS 26.7
Kiro Version
kiro-cli --v3 chatBug Description
The Sprites power installs and its skills load, but its Streamable HTTP MCP server fails during OAuth Dynamic Client Registration, before browser authorization. No Sprites MCP tools become available.
The authorization server advertises
noneandclient_secret_post. Inspection of the installed CLI runtime indicates that Kiro's OAuth provider omitstoken_endpoint_auth_methodfrom its client registration metadata. The registration helper serializes that metadata into the POST body. Omission defaults toclient_secret_basicunder RFC 7591, which this server does not support.This is a registration-request issue, not a missing field in the server's discovery response. The omission was identified through local runtime inspection, not a captured network request. Both IDE and CLI logs independently confirm the registration rejection below.
Steps to Reproduce
mcp.jsonis:{ "$schema": "https://agent-plugins.org/schemas/1.0.0/mcp.schema.json", "mcpServers": { "sprites": { "type": "streamable-http", "url": "https://sprites.dev/mcp" } } }For a minimal package, pair this with a
plugin.jsonsuch as:{ "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json", "name": "sprites", "version": "1.0.0", "description": "Connect to the Sprites MCP server.", "author": { "name": "Fly.io" }, "keywords": ["sprites"] }kiro-cli --v3 chatand inspect/mcpor make the same request.The observed package also contains Sprites skills; the files above isolate its manifest and MCP configuration without requiring those instructions.
Actual Behavior
Both surfaces report:
In the CLI, the callback listener starts successfully, registration fails, and the listener is stopped. Skills remain available, but the MCP tools do not load.
Expected Behavior
Kiro should explicitly select a supported client authentication method during dynamic registration. For a public-client flow against this server, submit:
Then proceed with browser authorization and PKCE. This is a proposed fix for the observed registration blocker; the remainder of the flow has not been verified with a patched client.
Additional Context
The public discovery endpoint,
https://sprites.dev/.well-known/oauth-authorization-server, advertises:{ "registration_endpoint": "https://sprites.dev/oauth/register", "token_endpoint_auth_methods_supported": ["none", "client_secret_post"], "code_challenge_methods_supported": ["S256"] }Related: #3908, especially the report of requesting
client_secret_basicdespite advertisednone/client_secret_post, and the subsequent confirmation that version 0.8.140 resolved it. Here, the inspected runtime omits the field rather than explicitly settingclient_secret_basic. This may be a recurrence or a different implementation path; no known-good version comparison has been performed for Sprites.References:
This report was generated in part by OpenAI Codex from local configuration, application logs, and inspection of the installed CLI runtime.