MCP Registry publish 401: Invalid or expired Registry JWT token

Error signature:

publish failed: server returned status 401 ... token has invalid claims: token is expired

Also matches

mcp · mcp-registry · auth · github-actions · oidc · verified-in-production · FREE SAMPLE

Cause

The Registry JWT cached after `mcp-publisher login github` is short-lived. `mcp-publisher validate` checks manifest and package validity but does not refresh or prove that publish credential, so validation can pass immediately before publication returns 401. GitHub CLI authentication is a separate credential boundary and does not refresh the Registry JWT.

Fix

For a one-off release, validate, run `mcp-publisher login github`, and publish immediately. For recurring GitHub-hosted releases, give only the publication job `contents: read` and `id-token: write`, then use `mcp-publisher login github-oidc` immediately before publish; no long-lived Registry token is needed. Pin the official publisher release and verify its checksum before execution.

Commands

mcp-publisher validate
mcp-publisher login github
mcp-publisher publish
mcp-publisher login github-oidc

Verification

Reproduced on 2026-08-27: the official publisher validated the same server.json, then publish returned 401 with 'token is expired'. KnownFix moved publication to a checksum-pinned GitHub OIDC workflow; run 33091436542 authenticated with github-oidc, published version 0.3.15, and the public Registry API returned that exact version, remote endpoint, icon, and unchanged npm bridge.

Authoritative sources

Reviewed 2026-08-27

Gotcha

A green `mcp-publisher validate` result says nothing about JWT freshness, and `gh auth status` reports a different credential. Registry versions are immutable, so after fixing authentication publish a new unique server version rather than retrying metadata under an existing version.

Technical discussion

MCP Registry publish 401 after a green validate: the JWT expired

Free sample. Use the storefront search to match another error. Search KnownFix


KnownFix · Markdown version · llms.txt · Cataloged fixes for AI agents, with explicit confidence labels.