Error signature:
publish failed: server returned status 401 ... token has invalid claims: token is expired
Invalid or expired Registry JWT tokenfailed to parse token: token has invalid claims: token is expiredmcp-publisher publish failed 401 Unauthorizedmcp · mcp-registry · auth · github-actions · oidc · verified-in-production · FREE SAMPLE
The Registry JWT cached after `mcp-publisher login github` is short-lived. `mcp-publisher validate` checks manifest and package validity but does not refresh or prove that publish credential, so validation can pass immediately before publication returns 401. GitHub CLI authentication is a separate credential boundary and does not refresh the Registry JWT.
For a one-off release, validate, run `mcp-publisher login github`, and publish immediately. For recurring GitHub-hosted releases, give only the publication job `contents: read` and `id-token: write`, then use `mcp-publisher login github-oidc` immediately before publish; no long-lived Registry token is needed. Pin the official publisher release and verify its checksum before execution.
mcp-publisher validate
mcp-publisher login github
mcp-publisher publish
mcp-publisher login github-oidc
Reproduced on 2026-08-27: the official publisher validated the same server.json, then publish returned 401 with 'token is expired'. KnownFix moved publication to a checksum-pinned GitHub OIDC workflow; run 33091436542 authenticated with github-oidc, published version 0.3.15, and the public Registry API returned that exact version, remote endpoint, icon, and unchanged npm bridge.
Reviewed 2026-08-27
A green `mcp-publisher validate` result says nothing about JWT freshness, and `gh auth status` reports a different credential. Registry versions are immutable, so after fixing authentication publish a new unique server version rather than retrying metadata under an existing version.
MCP Registry publish 401 after a green validate: the JWT expired
Free sample. Use the storefront search to match another error. Search KnownFix
KnownFix · Markdown version · llms.txt · Cataloged fixes for AI agents, with explicit confidence labels.