[GH-ISSUE #23344] issue: MCP-Server OAuth not working in v0.8.12 #35486

Closed
opened 2026-04-25 09:42:14 -05:00 by GiteaMirror · 1 comment
Owner

Originally created by @aleex1848 on GitHub (Apr 2, 2026).
Original GitHub issue: https://github.com/open-webui/open-webui/issues/23344

Check Existing Issues

  • I have searched for any existing and/or related issues.
  • I have searched for any existing and/or related discussions.
  • I have also searched in the CLOSED issues AND CLOSED discussions and found no related items (your issue might already be addressed on the development branch!).
  • I am using the latest version of Open WebUI.

Installation Method

Docker

Open WebUI Version

v0.8.12

Ollama Version (if applicable)

No response

Operating System

Windows 11

Browser (if applicable)

Chrome

Confirmation

  • I have read and followed all instructions in README.md.
  • I am using the latest version of both Open WebUI and Ollama.
  • I have included the browser console logs.
  • I have included the Docker container logs.
  • I have provided every relevant configuration, setting, and environment variable used in my setup.
  • I have clearly listed every relevant configuration, custom setting, environment variable, and command-line option that influences my setup (such as Docker Compose overrides, .env values, browser settings, authentication configurations, etc).
  • I have documented step-by-step reproduction instructions that are precise, sequential, and leave nothing to interpretation. My steps:
  • Start with the initial platform/version/OS and dependencies used,
  • Specify exact install/launch/configure commands,
  • List URLs visited, user input (incl. example values/emails/passwords if needed),
  • Describe all options and toggles enabled or changed,
  • Include any files or environmental changes,
  • Identify the expected and actual result at each stage,
  • Ensure any reasonably skilled user can follow and hit the same issue.

Expected Behavior

Login via OAuth/OIDC should set a cookie namend "oauth_session_id"

Actual Behavior

Login via OAuth/OIDC does not set a cookie namend "oauth_session_id".

Steps to Reproduce

Setup with OAUTH Login.
Add MCP-Server with Auth Method "OAuth".
Make a MCP-Request.
Inspect the request and see that no authorization header is sent.

Logs & Screenshots

Failed to store OAuth session server-side

Additional Information

In v0.8.10 it's working fine.

After updating to v0.8.12 it does not work anymore.

I would guess the problem sits here in line 1597
https://github.com/open-webui/open-webui/commit/bb3526f4e#diff-18f89641054f18680b1073ddaf7fb3e8d5b193533ee6dd79b89b60477d2dca61R1597

cookie_expires is not set so response.set_cookie is failing and never sets the cookie.

Originally created by @aleex1848 on GitHub (Apr 2, 2026). Original GitHub issue: https://github.com/open-webui/open-webui/issues/23344 ### Check Existing Issues - [x] I have searched for any existing and/or related issues. - [x] I have searched for any existing and/or related discussions. - [x] I have also searched in the CLOSED issues AND CLOSED discussions and found no related items (your issue might already be addressed on the development branch!). - [x] I am using the latest version of Open WebUI. ### Installation Method Docker ### Open WebUI Version v0.8.12 ### Ollama Version (if applicable) _No response_ ### Operating System Windows 11 ### Browser (if applicable) Chrome ### Confirmation - [x] I have read and followed all instructions in `README.md`. - [x] I am using the latest version of **both** Open WebUI and Ollama. - [x] I have included the browser console logs. - [x] I have included the Docker container logs. - [x] I have **provided every relevant configuration, setting, and environment variable used in my setup.** - [x] I have clearly **listed every relevant configuration, custom setting, environment variable, and command-line option that influences my setup** (such as Docker Compose overrides, .env values, browser settings, authentication configurations, etc). - [x] I have documented **step-by-step reproduction instructions that are precise, sequential, and leave nothing to interpretation**. My steps: - Start with the initial platform/version/OS and dependencies used, - Specify exact install/launch/configure commands, - List URLs visited, user input (incl. example values/emails/passwords if needed), - Describe all options and toggles enabled or changed, - Include any files or environmental changes, - Identify the expected and actual result at each stage, - Ensure any reasonably skilled user can follow and hit the same issue. ### Expected Behavior Login via OAuth/OIDC should set a cookie namend "oauth_session_id" ### Actual Behavior Login via OAuth/OIDC does not set a cookie namend "oauth_session_id". ### Steps to Reproduce Setup with OAUTH Login. Add MCP-Server with Auth Method "OAuth". Make a MCP-Request. Inspect the request and see that no authorization header is sent. ### Logs & Screenshots Failed to store OAuth session server-side ### Additional Information In v0.8.10 it's working fine. After updating to v0.8.12 it does not work anymore. I would guess the problem sits here in line 1597 https://github.com/open-webui/open-webui/commit/bb3526f4e#diff-18f89641054f18680b1073ddaf7fb3e8d5b193533ee6dd79b89b60477d2dca61R1597 cookie_expires is not set so response.set_cookie is failing and never sets the cookie.
GiteaMirror added the bug label 2026-04-25 09:42:14 -05:00
Author
Owner

@tjbck commented on GitHub (Apr 2, 2026):

Addresseed in dev.

<!-- gh-comment-id:4176840816 --> @tjbck commented on GitHub (Apr 2, 2026): Addresseed in dev.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#35486