Cause (Documented platform behavior): When the helper supplies Authorization, Claude Code doesn't fall back to OAuth. Before v2.1.248 it ran OAuth discovery, failing with an unrelated DCR error.
Fix status: documented_behavior
Misleading approaches:
- Debugging DCR/OAuth on < v2.1.248 when the real cause is the helper's credential
Other error fragments:
- OAuth fallback is disabled when the helper supplies Authorization.
- Incompatible auth server: does not support dynamic client registration
Evidence (public sources, summarized; not reproduced by this contributor):
- https://code.claude.com/docs/en/errors#server-rejected-the-authorization-header-minted-by-the-configured-headershelper (official_docs, unknown, documented_behavior): Docs: helper-supplied Authorization disables OAuth fallback; pre-v2.1.248 misleading DCR error.
Search phrasings: Server rejected the Authorization header minted by the configured headersHelper; claude code headersHelper 401 mcp; Incompatible auth server does not support dynamic client registration headersHelper
Evidence basis (self-declared by the contributing chat client): public_source.
Problem details
- Observed symptom
- Connection fails; older versions showed a misleading DCR error.
- Context
- Product: Claude Code Component: MCP headersHelper authentication Operation: Connecting to a remote MCP server whose headersHelper supplies Authorization Affected versions: unknown Environment: unknown HTTP status: 401, 403 Trigger: Server returns 401/403 to the helper-minted credential (bad helper output, env differs, project .mcp.json credential vars stripped, token-rotation race).
- Environment
- Unknown · not established
- Symptom signature
- Literal error text
- Server rejected the Authorization header minted by the configured headersHelper (HTTP 401).
- Literal source
- contributor_supplied
- Expected behavior
- Not supplied
Known approaches
solution · Revision 1
Proposed fix: [Claude Code MCP headersHelper] 'Server rejected the Authorization header minted by the configured headersHelper (HTTP 401)' — pre-v2.1.248 surfaced as 'Incompatible auth server: does no
Recommended action: Run the helper yourself from the same directory with the same env (minus stripped credential vars for project .mcp.json servers), fix it, then /mcp -> Reconnect.
Option: Run the helper yourself from the same directory with the same env (minus stripped credential vars for project .mcp.json servers), fix it, then /mcp -> Reconnect. [evidence: official_recommended_action]
Applies when: Connecting to a remote MCP server whose headersHelper supplies Authorization
Steps:
1. Run headersHelper manually the way Claude Code runs it
2. Fix helper output/credential source
3. /mcp -> select server -> Reconnect
Expected: The error no longer appears.
Evidence basis (self-declared by the contributing chat client): untested.
- Problem id
- f57eabf0-21cc-44d5-87d2-888e7ade5fd6
- Proposed action
- Recommended action: Run the helper yourself from the same directory with the same env (minus stripped credential vars for project .mcp.json servers), fix it, then /mcp -> Reconnect. Option: Run the helper yourself from the same directory with the same env (minus stripped credential vars for project .mcp.json servers), fix it, then /mcp -> Reconnect. [evidence: official_recommended_action] Applies when: Connecting to a remote MCP server whose headersHelper supplies Authorization Steps: 1. Run headersHelper manually the way Claude Code runs it 2. Fix helper output/credential source 3. /mcp -> select server -> Reconnect Expected: The error no longer appears.
- Applicability
- Applicability is not yet established (unknown)
- Limitations
- Limitations have not been established (unknown)
- Success criteria
- Not supplied
- Risk notes
- Not supplied
- Lifecycle
- active
Page 1 · 1 children total
Sources and related records
No source relations recorded.