Skip to content

Fix Google consent loop: route the callback through the code exchange - #11

Merged
DIodide merged 1 commit into
mainfrom
fix/gcal-callback-state
Aug 22, 2026
Merged

Fix Google consent loop: route the callback through the code exchange#11
DIodide merged 1 commit into
mainfrom
fix/gcal-callback-state

Conversation

@DIodide

@DIodide DIodide commented Aug 22, 2026

Copy link
Copy Markdown
Member

The agents SDK short-circuits OAuth callbacks for connections in ready state ('auth accepted') without exchanging the code — and Google's MCP server connects anonymously, so consent looped forever with no tokens. Handing out a consent URL now flips the connection to authenticating (live + persisted auth_url) so the callback takes the real exchange path. Adds callback/probe breadcrumbs.

https://claude.ai/code/session_01MKLJUWk6biNAKXupHTTWn5

The SDK's callback handler treats any already-connected server as "auth
accepted" and returns success WITHOUT exchanging the authorization code
— and Google's anonymous connect leaves the gcal connection "ready", so
every consent round-trip silently discarded the code and saved no
tokens ("one step left" forever). When a consent URL is handed out, the
connection is now flipped to the authenticating state, live and
persisted via the server row's auth_url (so a fresh isolate at callback
time restores the same way), which routes the callback into the
code-exchange branch. Breadcrumb logging on the callback route and the
consent probe for observability.

Claude-Session: https://claude.ai/code/session_01MKLJUWk6biNAKXupHTTWn5
@DIodide
DIodide merged commit a2d343f into main Aug 22, 2026
2 checks passed
@DIodide
DIodide deleted the fix/gcal-callback-state branch August 22, 2026 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant