Skip to content

Copilot sends ping on the 2026-07-28 protocol, and reuses rotated refresh tokens #5079

Description

@chinmaymjog

Describe the bug

Where: github/copilot-cli (public issues). The GitHub Copilot desktop
app's MCP sessions identify as copilot-cli in the MCP clientInfo.

1. ping after negotiating the new protocol

Against a server built on modelcontextprotocol/go-sdk (via Obot), the
session negotiates the 2026-07-28 protocol (it uses
subscriptions/listen) but still sends ping about every 20 seconds.
go-sdk rejects initialize, ping, notifications/initialized,
logging/setLevel and resources/(un)subscribe on that protocol with
-32601 "ping" is not supported in the new protocol. Our audit log shows
27 failed pings in 10 minutes from one desktop session. Expected: no
ping on protocol versions that removed it (use the new protocol's
keep-alive), or negotiate an older version.

2. Reuses rotated refresh tokens

The desktop app (OAuth client_id
https://github.com/copilot/desktop/client-metadata.json) sends the same
refresh token several times within a second, and sometimes abandons the
request midway. Against a server that rotates refresh tokens (recommended
by OAuth 2.1 for public clients), every reuse fails and the user is
repeatedly asked to sign in. VS Code, against the same server, never reuses
a token. Expected: serialize refreshes per server, and save the rotated
token before the next use.

Affected version

Version 1.1.27

Steps to reproduce the behavior

No response

Expected behavior

No response

Additional context

No response

Activity

  1. added theissue type on Oct 8, 2026
  2. Xieyan commented on Oct 9, 2026

    @Xieyan

    We're seeing this on the Microsoft Learn MCP Server too: a large number of ping requests from copilot-cli that fail with HTTP 404 (JSON-RPC -32601, method not found), since ping was removed in the 2026-07-28 revision. These failed pings are roughly 10–100x the volume of normal MCP requests (server/discover, tools/list, tools/call).

    What copilot-cli sends

    The whole session runs on 2026-07-28: server/discover, then tools/list, then ping about every 21 seconds while idle. The pings come from the session's own MCP client, since their JSON-RPC ids continue from tools/list. They don't come from the OAuth probe, which pings on 2025-11-25. No Mcp-Session-Id is sent.

    • Headers: MCP-Protocol-Version: 2026-07-28, Mcp-Method: ping, User-Agent: copilot-cli, Accept: text/event-stream, application/json
    • params._meta:
      • io.modelcontextprotocol/protocolVersion: "2026-07-28"
      • io.modelcontextprotocol/clientInfo: {"name":"copilot-cli","version":"1.0.93-1"}
      • io.modelcontextprotocol/clientCapabilities: {"sampling":{}}
      • progressToken: 3

    Captured request (copilot-cli 1.0.93-1):

    POST /mcp
    Accept: text/event-stream, application/json
    Content-Type: application/json
    MCP-Protocol-Version: 2026-07-28
    Mcp-Method: ping
    User-Agent: copilot-cli
    
    {"jsonrpc":"2.0","id":4,"method":"ping","params":{"_meta":{"io.modelcontextprotocol/protocolVersion":"2026-07-28","io.modelcontextprotocol/clientInfo":{"name":"copilot-cli","version":"1.0.93-1"},"io.modelcontextprotocol/clientCapabilities":{"sampling":{}},"progressToken":3}}}

    Local repro

    Setup: one session with one tool call, then idle, against a local MCP server behind a logging proxy, with auto-update off. The server's answer doesn't change the ping rate, and there were no reconnects in either case.

    Client Server answer to ping Idle time ping requests
    1.0.93-1 HTTP 404, -32601 150 s 6, ~21 s apart
    1.0.93-1 HTTP 200, {} 150 s 6, ~21 s apart
    1.0.93 n/a 180 s 0

    The stable 1.0.93 build didn't send ping in the same setup, so this may already be fixed there. We haven't tested 1.0.94.

    Expected: don't send ping on sessions that negotiated 2026-07-28 or later (removed in SEP-2575), or at least stop after a -32601 response. Against servers that reject ping, every idle session currently produces about 170 failed requests an hour.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions