Skip to content

fix(client): map HTTP 401 on streamable HTTP to Unauthorized JSON-RPC error - #3406

Closed
mturac wants to merge 1 commit into
modelcontextprotocol:mainfrom
mturac:fix/issue-1295
Closed

fix(client): map HTTP 401 on streamable HTTP to Unauthorized JSON-RPC error#3406
mturac wants to merge 1 commit into
modelcontextprotocol:mainfrom
mturac:fix/issue-1295

Conversation

@mturac

@mturac mturac commented Aug 28, 2026

Copy link
Copy Markdown

Summary

Maps bare HTTP 401 responses on streamable HTTP POST requests to a distinguishable JSON-RPC error (INVALID_REQUEST / "Unauthorized" with data.http_status) instead of collapsing into the generic "Server returned an error response" fallback.

This lets agents and other callers handle operation-specific auth denials without tearing down the whole session.

Changes

  • src/mcp/client/streamable_http.py: added explicit 401 handling in _handle_post_request.
  • tests/client/test_notification_response.py: added end-to-end session-level regression test.
  • tests/client/test_streamable_http.py: added transport-level regression test.

Fixes #1295

AI assistance disclosure

AI was used for analysis and implementation support; I reviewed and verified the changes and tests.

… error

Operation-specific auth denials now surface as a distinguishable
INVALID_REQUEST / "Unauthorized" JSON-RPC error with data.http_status
instead of collapsing into the generic "Server returned an error response"
fallback.

Fixes modelcontextprotocol#1295
@github-actions github-actions Bot added the missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md) label Aug 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

This PR has been closed automatically. This repo only keeps pull requests open when they come from a maintainer, or from a contributor a maintainer has assigned to the linked issue, and you aren't currently assigned to #1295.

If a maintainer assigns you to #1295, this PR reopens on its own and there's nothing more you need to do here. Assignment is a maintainer call based on capacity; comments that only ask to be assigned don't factor in. What does help is engaging on the issue itself by confirming the repro, explaining why it matters for your use case, or describing the approach you'd take.

You're welcome to keep pushing commits here (just avoid force-pushing, since GitHub can't reopen a rewritten branch), but that on its own won't get the PR reviewed or the issue assigned, and realistically most auto-closed PRs stay closed. There's no need to open a new PR either way.

CONTRIBUTING.md has the full reasoning, but in short:

  • We're a small team with very little capacity to review community PRs right now.
  • Many recent PRs are AI-generated with little human review, and reviewing one carefully still costs a maintainer as much time as it ever did. A well-described issue is usually more useful to us than the code.

Maintainers: reopen, remove missing-issue-link, or add bypass-issue-check to override.

@github-actions github-actions Bot closed this Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

missing-issue-link Auto-closed: PR needs a linked issue assigned to its author (see CONTRIBUTING.md)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

401 in Streamable HTTP should be handled gracefully

1 participant