[codex] Surface MCP reauthentication-required startup failures (#29877)

## Summary

- distinguish expired, non-refreshable stored MCP OAuth credentials from
first-time missing credentials
- carry a typed `failureReason: "reauthenticationRequired"` on the
existing `mcpServer/startupStatus/updated` notification only when user
action is required
- keep the public MCP auth-status API unchanged and regenerate the
app-server protocol schemas and documentation

## Why

An MCP server with an expired access token and no usable refresh token
currently fails startup without giving clients a reliable, typed
recovery signal.

The existing startup-status notification is the natural place to carry
this state. Its nullable `failureReason` keeps the recovery reason
attached to the failed startup transition without adding a one-off
notification. Internally, Codex distinguishes first-time login from
reauthentication and emits the reason only when the startup error itself
requires authentication.

## User impact

App clients can prompt an existing user to reconnect an MCP server when
automatic recovery is impossible by handling a failed
`mcpServer/startupStatus/updated` notification whose `failureReason` is
`reauthenticationRequired`. Starting, ready, cancelled, unrelated
failures, and first-time setup carry no reauthentication reason.

## Companion app PR

- openai/openai#1069582

## Validation

- `just test -p codex-app-server-protocol` — 248 passed; schema fixture
tests passed
- `cargo check -p codex-app-server -p codex-tui`
- `just test -p codex-rmcp-client -p codex-mcp` — 184 passed, 2 skipped
- `just test -p codex-protocol -p codex-app-server-protocol -p
codex-mcp` — 579 passed
- `just write-app-server-schema`
- `just fmt`
This commit is contained in:
felixxia-oai
2026-06-25 21:50:36 +00:00
committed by GitHub
parent b80fbb70cd
commit a6d20ed297
27 changed files with 350 additions and 55 deletions
+18 -1
View File
@@ -3621,10 +3621,22 @@ pub struct McpStartupUpdateEvent {
pub enum McpStartupStatus {
Starting,
Ready,
Failed { error: String },
Failed {
error: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
#[ts(optional = nullable)]
reason: Option<McpStartupFailureReason>,
},
Cancelled,
}
#[derive(Debug, Clone, Copy, PartialEq, Eq, Deserialize, Serialize, JsonSchema, TS)]
#[serde(rename_all = "snake_case")]
#[ts(rename_all = "snake_case")]
pub enum McpStartupFailureReason {
ReauthenticationRequired,
}
#[derive(Debug, Clone, Deserialize, Serialize, JsonSchema, TS, Default)]
pub struct McpStartupCompleteEvent {
pub ready: Vec<String>,
@@ -5749,6 +5761,7 @@ mod tests {
server: "srv".to_string(),
status: McpStartupStatus::Failed {
error: "boom".to_string(),
reason: Some(McpStartupFailureReason::ReauthenticationRequired),
},
}),
};
@@ -5758,6 +5771,10 @@ mod tests {
assert_eq!(value["msg"]["server"], "srv");
assert_eq!(value["msg"]["status"]["state"], "failed");
assert_eq!(value["msg"]["status"]["error"], "boom");
assert_eq!(
value["msg"]["status"]["reason"],
"reauthentication_required"
);
Ok(())
}