[GH-ISSUE #20828] issue: OAuth2.1 MCP Tool Server Verification Error - Failed to connect to the tool server: 'coroutine' object is not iterable #73906

Closed
opened 2026-05-13 06:28:42 -05:00 by GiteaMirror · 1 comment
Owner

Originally created by @Lemmons on GitHub (Jan 20, 2026).
Original GitHub issue: https://github.com/open-webui/open-webui/issues/20828

Check Existing Issues

  • I have searched for any existing and/or related issues.
  • I have searched for any existing and/or related discussions.
  • I have also searched in the CLOSED issues AND CLOSED discussions and found no related items (your issue might already be addressed on the development branch!).
  • I am using the latest version of Open WebUI.

Installation Method

Other

Open WebUI Version

v0.7.2

Ollama Version (if applicable)

No response

Operating System

EKS (Amazon Linux)

Browser (if applicable)

No response

Confirmation

  • I have read and followed all instructions in README.md.
  • I am using the latest version of both Open WebUI and Ollama.
  • I have included the browser console logs.
  • I have included the Docker container logs.
  • I have provided every relevant configuration, setting, and environment variable used in my setup.
  • I have clearly listed every relevant configuration, custom setting, environment variable, and command-line option that influences my setup (such as Docker Compose overrides, .env values, browser settings, authentication configurations, etc).
  • I have documented step-by-step reproduction instructions that are precise, sequential, and leave nothing to interpretation. My steps:
  • Start with the initial platform/version/OS and dependencies used,
  • Specify exact install/launch/configure commands,
  • List URLs visited, user input (incl. example values/emails/passwords if needed),
  • Describe all options and toggles enabled or changed,
  • Include any files or environmental changes,
  • Identify the expected and actual result at each stage,
  • Ensure any reasonably skilled user can follow and hit the same issue.

Expected Behavior

Requests to /api/v1/configs/tool_servers/verify for a properly configured MCP tool server utilizing OAuth2.1 should succeed.

Actual Behavior

Regression in v0.7.2 vs v0.6.36 for the exact same MCP tool server with the exact same settings.

v0.6.36 - MCP client verification succeeds

v0.7.2 - MCP client verification fails immediately with open_webui.routers.configs:verify_tool_servers_config:347 - Failed to connect to the tool server: 'coroutine' object is not iterable

Steps to Reproduce

  1. Turn on debug logs for OpenWebUI (GLOBAL_LOG_LEVEL=DEBUG)
  2. Go to Admin Panel, Settings, External Tools, Manage Tool Servers
  3. Open the "Add Connection" dialog box
  4. Select MCP Type
  5. Select OAuth 2.1 Auth
  6. Put any url for the tool server url (valid or not does not matter)
  7. Click the "Verify Connection" button (refresh icon)
  8. UI shows a "Connection failed" dialog box
  9. Debug logs show open_webui.routers.configs:verify_tool_servers_config:347 - Failed to connect to the tool server: 'coroutine' object is not iterable

Logs & Screenshots

MCP client verification fails immediately

2026-01-20 18:12:16.071 | DEBUG    | open_webui.routers.configs:verify_tool_servers_config:347 - Failed to connect to the tool server: 'coroutine' object is not iterable
2026-01-20 18:12:16.074 | INFO     | uvicorn.protocols.http.httptools_impl:send:483 - REDACTED:0 - "POST /api/v1/configs/tool_servers/verify HTTP/1.1" 400

MCP client registration succeeds

2026-01-20 18:11:04.830 | DEBUG    | open_webui.utils.oauth:get_authorization_server_discovery_urls:270 - Found resource_metadata URL: REDACTED/mcp/.well-known/oauth-protected-resource
2026-01-20 18:11:04.852 | DEBUG    | open_webui.utils.oauth:get_authorization_server_discovery_urls:287 - Discovered authorization servers: ['REDACTED']
2026-01-20 18:11:05.269 | INFO     | open_webui.utils.oauth:get_oauth_client_info_with_dynamic_client_registration:433 - Dynamic client registration successful at REDACTED/oauth/register, client_id: REDACTED
2026-01-20 18:11:05.273 | INFO     | uvicorn.protocols.http.httptools_impl:send:483 - REDACTED:0 - "POST /api/v1/configs/oauth/clients/register?type=mcp HTTP/1.1" 200

Tool use works

2026-01-20 18:38:17.003 | INFO     | httpx._client:_send_single_request:1740 - HTTP Request: POST REDACTED/mcp "HTTP/1.1 200 OK"

Additional Information

This looks like its only an issue with verification of the url, as both client registration, and actual tool usage seems to work fine. I have not seen any suspect log messages during actual use.

Originally created by @Lemmons on GitHub (Jan 20, 2026). Original GitHub issue: https://github.com/open-webui/open-webui/issues/20828 ### Check Existing Issues - [x] I have searched for any existing and/or related issues. - [x] I have searched for any existing and/or related discussions. - [x] I have also searched in the CLOSED issues AND CLOSED discussions and found no related items (your issue might already be addressed on the development branch!). - [x] I am using the latest version of Open WebUI. ### Installation Method Other ### Open WebUI Version v0.7.2 ### Ollama Version (if applicable) _No response_ ### Operating System EKS (Amazon Linux) ### Browser (if applicable) _No response_ ### Confirmation - [x] I have read and followed all instructions in `README.md`. - [x] I am using the latest version of **both** Open WebUI and Ollama. - [x] I have included the browser console logs. - [x] I have included the Docker container logs. - [x] I have **provided every relevant configuration, setting, and environment variable used in my setup.** - [x] I have clearly **listed every relevant configuration, custom setting, environment variable, and command-line option that influences my setup** (such as Docker Compose overrides, .env values, browser settings, authentication configurations, etc). - [x] I have documented **step-by-step reproduction instructions that are precise, sequential, and leave nothing to interpretation**. My steps: - Start with the initial platform/version/OS and dependencies used, - Specify exact install/launch/configure commands, - List URLs visited, user input (incl. example values/emails/passwords if needed), - Describe all options and toggles enabled or changed, - Include any files or environmental changes, - Identify the expected and actual result at each stage, - Ensure any reasonably skilled user can follow and hit the same issue. ### Expected Behavior Requests to `/api/v1/configs/tool_servers/verify` for a properly configured MCP tool server utilizing OAuth2.1 should succeed. ### Actual Behavior Regression in v0.7.2 vs v0.6.36 for the exact same MCP tool server with the exact same settings. v0.6.36 - MCP client verification succeeds v0.7.2 - MCP client verification fails immediately with `open_webui.routers.configs:verify_tool_servers_config:347 - Failed to connect to the tool server: 'coroutine' object is not iterable` ### Steps to Reproduce 1. Turn on debug logs for OpenWebUI (GLOBAL_LOG_LEVEL=DEBUG) 2. Go to Admin Panel, Settings, External Tools, Manage Tool Servers 3. Open the "Add Connection" dialog box 4. Select MCP Type 5. Select OAuth 2.1 Auth 6. Put any url for the tool server url (valid or not does not matter) 7. Click the "Verify Connection" button (refresh icon) 8. UI shows a "Connection failed" dialog box 9. Debug logs show `open_webui.routers.configs:verify_tool_servers_config:347 - Failed to connect to the tool server: 'coroutine' object is not iterable` ### Logs & Screenshots MCP client verification fails immediately ``` 2026-01-20 18:12:16.071 | DEBUG | open_webui.routers.configs:verify_tool_servers_config:347 - Failed to connect to the tool server: 'coroutine' object is not iterable 2026-01-20 18:12:16.074 | INFO | uvicorn.protocols.http.httptools_impl:send:483 - REDACTED:0 - "POST /api/v1/configs/tool_servers/verify HTTP/1.1" 400 ``` MCP client registration succeeds ``` 2026-01-20 18:11:04.830 | DEBUG | open_webui.utils.oauth:get_authorization_server_discovery_urls:270 - Found resource_metadata URL: REDACTED/mcp/.well-known/oauth-protected-resource 2026-01-20 18:11:04.852 | DEBUG | open_webui.utils.oauth:get_authorization_server_discovery_urls:287 - Discovered authorization servers: ['REDACTED'] 2026-01-20 18:11:05.269 | INFO | open_webui.utils.oauth:get_oauth_client_info_with_dynamic_client_registration:433 - Dynamic client registration successful at REDACTED/oauth/register, client_id: REDACTED 2026-01-20 18:11:05.273 | INFO | uvicorn.protocols.http.httptools_impl:send:483 - REDACTED:0 - "POST /api/v1/configs/oauth/clients/register?type=mcp HTTP/1.1" 200 ``` Tool use works ``` 2026-01-20 18:38:17.003 | INFO | httpx._client:_send_single_request:1740 - HTTP Request: POST REDACTED/mcp "HTTP/1.1 200 OK" ``` ### Additional Information This looks like its only an issue with verification of the url, as both client registration, and actual tool usage seems to work fine. I have not seen any suspect log messages during actual use.
GiteaMirror added the bug label 2026-05-13 06:28:42 -05:00
Author
Owner

@owui-terminator[bot] commented on GitHub (Jan 20, 2026):

🔍 Similar Issues Found

I found some existing issues that might be related to this one. Please check if any of these are duplicates or contain helpful solutions:

  1. #20808 issue: mcp oauth 2.1 callback always ends in 401 not authenticated
    by bk-lg • Jan 20, 2026 • bug

  2. #19823 Issue: MCP with OAuth 2.1 Authorization/Token retrival is broken in v0.6.41
    by mllab-nl • Dec 08, 2025 • bug

  3. #19116 issue: MCP OAuth 2.1 client registration fails when policy_uri, client_uri, logo_uri or tos_uri are not set
    by xqqp • Nov 11, 2025 • bug

  4. #20802 issue: oauth_token passed to tools is None
    by m1g32 • Jan 19, 2026 • bug

  5. #19148 issue: Verify OAuth mcp server sends incorrect authorization header
    by Oleg52 • Nov 12, 2025 • bug

Show 2 more related issues
  1. #20629 issue: MCP server response fails
    by thrasher • Jan 12, 2026 • bug

  2. #19813 issue: Failed to connect to MCP server, while the connection test works fine
    by spi-dlp • Dec 08, 2025 • bug


💡 Tips:

  • If this is a duplicate, please consider closing this issue and adding any additional details to the existing one
  • If you found a solution in any of these issues, please share it here to help others

This comment was generated automatically by a bot. Please react with a 👍 if this comment was helpful, or a 👎 if it was not.

<!-- gh-comment-id:3774649468 --> @owui-terminator[bot] commented on GitHub (Jan 20, 2026): 🔍 **Similar Issues Found** I found some existing issues that might be related to this one. Please check if any of these are duplicates or contain helpful solutions: 1. [#20808](https://github.com/open-webui/open-webui/issues/20808) **issue: mcp oauth 2.1 callback always ends in 401 not authenticated** *by bk-lg • Jan 20, 2026 • `bug`* 2. [#19823](https://github.com/open-webui/open-webui/issues/19823) **Issue: MCP with OAuth 2.1 Authorization/Token retrival is broken in v0.6.41** *by mllab-nl • Dec 08, 2025 • `bug`* 3. [#19116](https://github.com/open-webui/open-webui/issues/19116) **issue: MCP OAuth 2.1 client registration fails when policy_uri, client_uri, logo_uri or tos_uri are not set** *by xqqp • Nov 11, 2025 • `bug`* 4. [#20802](https://github.com/open-webui/open-webui/issues/20802) **issue: __oauth_token__ passed to tools is None** *by m1g32 • Jan 19, 2026 • `bug`* 5. [#19148](https://github.com/open-webui/open-webui/issues/19148) **issue: Verify OAuth mcp server sends incorrect authorization header** *by Oleg52 • Nov 12, 2025 • `bug`* <details> <summary>Show 2 more related issues</summary> 6. [#20629](https://github.com/open-webui/open-webui/issues/20629) **issue: MCP server response fails** *by thrasher • Jan 12, 2026 • `bug`* 7. [#19813](https://github.com/open-webui/open-webui/issues/19813) **issue: Failed to connect to MCP server, while the connection test works fine** *by spi-dlp • Dec 08, 2025 • `bug`* </details> --- 💡 **Tips:** - If this is a duplicate, please consider closing this issue and adding any additional details to the existing one - If you found a solution in any of these issues, please share it here to help others *This comment was generated automatically by a bot.* Please react with a 👍 if this comment was helpful, or a 👎 if it was not.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#73906