Skip to content

feat(models): forward MCP OAuth scopes in claude_code and codex_cli generators - #647

Open
ikenwan-dev wants to merge 3 commits into
GoogleCloudPlatform:mainfrom
ikenwan-dev:forward-mcp-oauth-scopes
Open

ikenwan-dev wants to merge 3 commits into
GoogleCloudPlatform:mainfrom
ikenwan-dev:forward-mcp-oauth-scopes

Conversation

@ikenwan-dev

Copy link
Copy Markdown
Contributor

Summary

  • Claude Code: Extracts oauth.scopes and forwards them to gcloud auth application-default print-access-token --scopes=... in both static header and dynamic headersHelper token refresh.
  • Codex CLI: Tracks oauth.scopes across configured MCP servers, forwards them when fetching the GCloud bearer token, and refreshes the token with scopes per turn.
  • Added unit tests for both generators and updated documentation.

@prernakakkar-google

Copy link
Copy Markdown
Collaborator

/gcbrun

@prernakakkar-google

Copy link
Copy Markdown
Collaborator

fix pycodestyle

@prernakakkar-google

Copy link
Copy Markdown
Collaborator

Claude (claude_code.py#L294-L310) accepts oauth: {scopes: [...]}, oauth: [...], oauth: "...", a top-level scopes, and comma-separated strings.

Codex (codex_cli.py#L611-L614) calls oauth.get(...), which raises AttributeError for oauth: [...] or oauth: "...". Strings aren't split or stripped either ("a, b" becomes ["a, b"]).
The existing mcp_client.auth_headers
(used by fetch_mcp_tools, which the dataset_quality scorer calls) accepts only oauth.scopes and requires it. It raises the same AttributeError on a non-dict oauth and rejects a top-level scopes.

Three code paths read the same mcp_servers block, and Claude's extra shapes work in only one of them. The documented contract (Gemini CLI schema) is oauth.scopes: string[]. I suggest one shared helper (in agent_cli.py or mcp_client.py) that accepts only the canonical shape and is used by both generators, ideally by auth_headers too

@ikenwan-dev

Copy link
Copy Markdown
Contributor Author

Done! I've put scope extraction into a shared extract_mcp_oauth_scopes helper in mcp_client.py that follows the canonical oauth.scopes contract, and updated Claude Code, Codex CLI, and auth_headers to use it.

Claude (claude_code.py#L294-L310) accepts oauth: {scopes: [...]}, oauth: [...], oauth: "...", a top-level scopes, and comma-separated strings.

Codex (codex_cli.py#L611-L614) calls oauth.get(...), which raises AttributeError for oauth: [...] or oauth: "...". Strings aren't split or stripped either ("a, b" becomes ["a, b"]). The existing mcp_client.auth_headers (used by fetch_mcp_tools, which the dataset_quality scorer calls) accepts only oauth.scopes and requires it. It raises the same AttributeError on a non-dict oauth and rejects a top-level scopes.

Three code paths read the same mcp_servers block, and Claude's extra shapes work in only one of them. The documented contract (Gemini CLI schema) is oauth.scopes: string[]. I suggest one shared helper (in agent_cli.py or mcp_client.py) that accepts only the canonical shape and is used by both generators, ideally by auth_headers too

@prernakakkar-google

Copy link
Copy Markdown
Collaborator

/gcbrun

@prernakakkar-google

Copy link
Copy Markdown
Collaborator

linting error is till there

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants