Skip to content

[Bug]: t3-code MCP credential expires when a turn waits on the user for more than 24 hours #14076

Description

@robertnisipeanu

Before submitting

  • I searched existing issues and did not find a duplicate.
  • I included enough detail to reproduce or investigate the problem.

Area

apps/server

Steps to reproduce

  1. Start a thread with a provider that gets the t3-code MCP server (seen with Claude).
  2. Have the agent start a turn that asks the user a question (for example with AskUserQuestion) and leave it unanswered for more than 24 hours. Keep the T3 server running the whole time.
  3. Answer the question. The same turn continues.
  4. Have the agent call any t3-code tool, for example link_pull_request.

Observed timeline: the question was asked at 2026-09-26 10:12 UTC, answered at 2026-09-28 06:19 UTC (44 hours later), and the link_pull_request call at 06:39 UTC failed. The server had been running without a restart since 2026-09-25.

Expected behavior

A provider session keeps a valid t3-code MCP credential for as long as the session is alive, however long a turn runs or waits on the user.

Actual behavior

Every t3-code tool call from that session is rejected:

MCP server "t3-code" rejected the Authorization header in its config (update it, then run /mcp to reconnect)

The session cannot recover. The provider process keeps the old bearer in its MCP config, so reconnecting with /mcp presents the same rejected token.

Cause, in apps/server/src/mcp/McpSessionRegistry.ts:

  • Credentials live in memory, and any record whose lastAliveAt is older than DEFAULT_LIVENESS_WINDOW_MS (24 hours) is pruned.
  • lastAliveAt is refreshed only by MCP traffic (resolve) and by touchActiveMcpThread, which ProviderService calls from sendTurn and compactThread. Answering a pending user-input request or an approval does not refresh it, and nothing refreshes it while a turn is in progress.
  • resolve, issue and touch all prune before they refresh, so once 24 hours have passed a later touch cannot bring the record back.

Related, but separate:

Impact

Major degradation or frequent failure

Version or commit

0.0.42; the same code is on main @ d15210c

Environment

Linux, Claude provider

Workaround

Let the turn finish, then restart the T3 server. The next message resumes the session with a fresh credential.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething is broken or behaving incorrectly.via-triageFiled through npx t3 triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions