Skip to content

Commit 298cb4e

Browse files
fix: use automatic OAuth issuer discovery
Align tutorial defaults and OAuth guidance with orca-cli PR #8. Keep issuer selection optional and update all three paths' error hints. Assisted-by: Codex
1 parent a61be0f commit 298cb4e

6 files changed

Lines changed: 26 additions & 14 deletions

File tree

‎.env.example‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -29,12 +29,14 @@ SN_MCP_URL=
2929

3030
# MCP authentication: oauth (default) or static_bearer for API-key MCP servers.
3131
# All three tutorial paths call ork for the first OAuth login, then reuse the
32-
# credential stored in the vault. Install ork with MCP OAuth proxy support.
32+
# credential stored in the vault. Install ork with the OAuth discovery support
33+
# from orca-cli PR #8 (or current main).
3334
SN_MCP_AUTH=oauth
3435

35-
# Expected issuer for the StreamNative OAuth proxy (from trusted provider setup).
36-
# For a different MCP provider, set its issuer or leave empty for discovery.
37-
SN_MCP_OAUTH_ISSUER=https://auth.streamnative.cloud/
36+
# Optional authorization server selection. Leave empty for automatic discovery.
37+
# If multiple servers are advertised, copy one exact authorization_servers value
38+
# from the MCP protected-resource metadata; do not substitute the metadata issuer.
39+
SN_MCP_OAUTH_ISSUER=
3840
SN_MCP_OAUTH_SCOPE="openid profile email offline_access"
3941

4042
# ------------------------------------------------------------- your choices --

‎README.md‎

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -61,8 +61,14 @@ stored OAuth credential. This check verifies MCP initialization; L3/L4 exercise
6161
the actual SQL tools. A failed check prints its fix. Still stuck after two tries?
6262
Raise your hand.
6363

64-
For StreamNative SQL Workspace MCP, keep `SN_MCP_AUTH=oauth` and the issuer/scope
65-
settings from `.env.example`. `SN_API_KEY` authenticates the hosted Agent Engine,
64+
For StreamNative SQL Workspace MCP, keep `SN_MCP_AUTH=oauth`, leave
65+
`SN_MCP_OAUTH_ISSUER` empty for automatic discovery, and use the scope from
66+
`.env.example`. Use an `ork` build containing [PR #8](https://github.com/orca-ae/orca-cli/pull/8)
67+
or current main. Its discovery accepts HTTPS issuer aliases within the same
68+
registrable domain and port. Only set `SN_MCP_OAUTH_ISSUER` when selecting one
69+
of multiple advertised `authorization_servers`; copy that advertised value
70+
exactly rather than the final issuer in authorization-server metadata.
71+
`SN_API_KEY` authenticates the hosted Agent Engine,
6672
Kafka and Schema Registry; it is not the OAuth MCP access token. All three paths
6773
use `ork` for the first MCP login, then reuse the live credential for the same URL
6874
and auth type from `.orca-state/<participant>.json`. Tokens stay in the server-side
@@ -332,7 +338,7 @@ ork agent update "$AGENT_ID" --version 1 --model "$ORCA_MODEL" \
332338
ork agent vaults create --display-name hello-vault-ana -o json
333339
ork agent vaults credentials create --vault "$VAULT_ID" --display-name streamnative-mcp \
334340
--mcp-server-url "$SN_MCP_URL" \
335-
--oauth-issuer "$SN_MCP_OAUTH_ISSUER" --oauth-scope "$SN_MCP_OAUTH_SCOPE" -o json
341+
--oauth-scope "$SN_MCP_OAUTH_SCOPE" -o json
336342

337343
ork agent sessions create --agent "$AGENT_ID" --agent-version 2 \
338344
--environment-id "$ENVIRONMENT_ID" --vault-id "$VAULT_ID" --title "L3: live context" -o json
@@ -408,7 +414,7 @@ action, and you have your hackathon project. Ideas and next steps:
408414
| `relation "avro.security.login_events" does not exist` | Select your team's database and update the quoted Avro source in both L2 SQL files to match `LOGIN_TOPIC` in `.env`. |
409415
| The agent can't find `login_failures` | Create the view in your team's database (L2, step 2); the agent looks it up there. |
410416
| `[error]` lines from MCP tools in L3 | Check `SN_MCP_URL` and `SN_MCP_AUTH`, finish the OAuth login, then rerun the doctor. |
411-
| OAuth issuer mismatch / unsupported client authentication | Install an `ork` build with OAuth proxy and `client_secret_basic` support; verify `SN_MCP_OAUTH_ISSUER` against trusted provider setup. |
417+
| OAuth issuer mismatch / unsupported client authentication | Use current `ork` main or PR #8 and leave `SN_MCP_OAUTH_ISSUER` empty for StreamNative discovery. An explicit issuer must match an advertised authorization server. `--oauth-allow-issuer-mismatch` is only for trusted servers whose metadata issuer crosses registrable domains; StreamNative does not need it. |
412418
| `Cannot reach the Agent Engine` | `ORCA_BASE_URL` must be the host root from your card, with no `/v1`. |
413419
| The agent answers from memory instead of querying | Ask again, "check the view first". The system prompt tells it to always query. |
414420

‎cli/lib.sh‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -216,7 +216,7 @@ ensure_vault() { # ensure_vault <name>
216216
[ -z "${SN_MCP_OAUTH_SCOPE:-}" ] || oauth_args+=(--oauth-scope "$SN_MCP_OAUTH_SCOPE")
217217
# Keep the browser URL and callback progress visible; tokens go directly to the vault.
218218
ork agent vaults credentials create "${oauth_args[@]}" -o json ||
219-
hello_die "MCP OAuth authorization failed. Check the ork error above and SN_MCP_OAUTH_ISSUER, then rerun L3/L4."
219+
hello_die "MCP OAuth authorization failed. Check the ork error above; normally leave SN_MCP_OAUTH_ISSUER empty for discovery, then rerun L3/L4."
220220
else
221221
auth=$(jq -cn --arg url "$SN_MCP_URL" --arg token "$SN_API_KEY" '{type: "static_bearer", mcp_server_url: $url, token: $token}')
222222
ork_json agent vaults credentials create --vault "$VAULT_ID" --display-name streamnative-mcp --auth-json "$auth" \

‎docs/before-you-arrive.md‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -11,9 +11,13 @@ can pick a different one.
1111

1212
Everyone also needs `git`, a terminal, and [`ork`](https://github.com/orca-ae/orca-cli)
1313
for the first OAuth MCP login in L3/L4, including the Python and TypeScript paths.
14-
Use a build with MCP OAuth proxy issuer pinning and `client_secret_basic` support;
15-
check `ork agent vaults credentials create --help` for `--oauth-issuer` and
16-
`--oauth-client-secret-file`. The browser flow stores tokens directly in the vault.
14+
Use current `orca-cli` main or a build containing [PR #8](https://github.com/orca-ae/orca-cli/pull/8).
15+
Check `ork agent vaults credentials create --help` for `--oauth-issuer` and
16+
`--oauth-allow-issuer-mismatch`. Automatic discovery handles StreamNative's
17+
same-domain proxy issuer aliases and dynamic client authentication. Leave
18+
`SN_MCP_OAUTH_ISSUER` empty for this flow; `--oauth-issuer` only selects an
19+
authorization server advertised by the MCP server when a choice is needed.
20+
The browser flow stores tokens directly in the vault.
1721
On Windows, use WSL or Git Bash for the CLI path.
1822

1923
## 1. Get the code

‎python/common.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -192,7 +192,7 @@ def authorize_mcp(vault_id: str, config: Config) -> None:
192192
except OSError:
193193
raise ConfigError("Install ork with MCP OAuth proxy support and put it on PATH (see docs/before-you-arrive.md).") from None
194194
if result.returncode:
195-
raise ConfigError("MCP OAuth authorization failed. Check the ork error above and SN_MCP_OAUTH_ISSUER, then rerun L3/L4.")
195+
raise ConfigError("MCP OAuth authorization failed. Check the ork error above; normally leave SN_MCP_OAUTH_ISSUER empty for discovery, then rerun L3/L4.")
196196

197197

198198
def ensure_vault(client: Any, state: State, name: str, config: Config) -> str:

‎typescript/src/common.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -330,7 +330,7 @@ export function authorizeMcp(vaultId: string, config: Config): void {
330330
// No shell and no credentials in argv; OAuth tokens are never read by this script.
331331
const result = spawnSync('ork', args, { env, stdio: 'inherit' });
332332
if (result.error) throw new ConfigError('Install ork with MCP OAuth proxy support and put it on PATH (see docs/before-you-arrive.md).');
333-
if (result.status !== 0) throw new ConfigError('MCP OAuth authorization failed. Check the ork error above and SN_MCP_OAUTH_ISSUER, then rerun L3/L4.');
333+
if (result.status !== 0) throw new ConfigError('MCP OAuth authorization failed. Check the ork error above; normally leave SN_MCP_OAUTH_ISSUER empty for discovery, then rerun L3/L4.');
334334
}
335335

336336
/** The remembered resource, or null if it was never created, deleted, or archived. */

0 commit comments

Comments
 (0)