Describe the bug
Where: github/copilot-cli (public issues). The GitHub Copilot desktop
app's MCP sessions identify as copilot-cli in the MCP clientInfo.
1. ping after negotiating the new protocol
Against a server built on modelcontextprotocol/go-sdk (via Obot), the
session negotiates the 2026-07-28 protocol (it uses
subscriptions/listen) but still sends ping about every 20 seconds.
go-sdk rejects initialize, ping, notifications/initialized,
logging/setLevel and resources/(un)subscribe on that protocol with
-32601 "ping" is not supported in the new protocol. Our audit log shows
27 failed pings in 10 minutes from one desktop session. Expected: no
ping on protocol versions that removed it (use the new protocol's
keep-alive), or negotiate an older version.
2. Reuses rotated refresh tokens
The desktop app (OAuth client_id
https://github.com/copilot/desktop/client-metadata.json) sends the same
refresh token several times within a second, and sometimes abandons the
request midway. Against a server that rotates refresh tokens (recommended
by OAuth 2.1 for public clients), every reuse fails and the user is
repeatedly asked to sign in. VS Code, against the same server, never reuses
a token. Expected: serialize refreshes per server, and save the rotated
token before the next use.
Affected version
Version 1.1.27
Steps to reproduce the behavior
No response
Expected behavior
No response
Additional context
No response
Describe the bug
Where: github/copilot-cli (public issues). The GitHub Copilot desktop
app's MCP sessions identify as
copilot-cliin the MCPclientInfo.1.
pingafter negotiating the new protocolAgainst a server built on modelcontextprotocol/go-sdk (via Obot), the
session negotiates the 2026-07-28 protocol (it uses
subscriptions/listen) but still sendspingabout every 20 seconds.go-sdk rejects
initialize,ping,notifications/initialized,logging/setLevelandresources/(un)subscribeon that protocol with-32601 "ping" is not supported in the new protocol. Our audit log shows27 failed
pings in 10 minutes from one desktop session. Expected: nopingon protocol versions that removed it (use the new protocol'skeep-alive), or negotiate an older version.
2. Reuses rotated refresh tokens
The desktop app (OAuth
client_idhttps://github.com/copilot/desktop/client-metadata.json) sends the samerefresh token several times within a second, and sometimes abandons the
request midway. Against a server that rotates refresh tokens (recommended
by OAuth 2.1 for public clients), every reuse fails and the user is
repeatedly asked to sign in. VS Code, against the same server, never reuses
a token. Expected: serialize refreshes per server, and save the rotated
token before the next use.
Affected version
Version 1.1.27
Steps to reproduce the behavior
No response
Expected behavior
No response
Additional context
No response