{"kind":"RECORDED_NATIVE_OAUTH_CHECKS","checked_on":"2026-10-06","environment":"Installed native CLI clients against the real CiteDoor HTTP server and isolated PostgreSQL; no SDK proxy or injected bearer token.","access_ttl_seconds":60,"consent_method":"Each native client produced the real authorization URL and callback; an isolated owner approved via the consent API. Desktop sign-in UI was not exercised.","results":[{"client":"Claude Code","version":"2.1.284 (Claude Code)","login":true,"tools_discovered":true,"refresh_after_expiry":true,"restart_without_consent":true,"checked_on":"2026-10-06"},{"client":"Cursor CLI","version":"2026.10.01-e373342","login":true,"tools_discovered":true,"refresh_after_expiry":true,"restart_without_consent":true,"checked_on":"2026-10-06"},{"client":"Codex app-server","version":"codex-cli 0.150.1","registration":"dcr","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":true,"restart_after_refresh_without_consent":true,"restart_before_expiry_without_consent":true,"expiry_rounds":[{"round":1,"same_identity":true,"new_token_generation":true,"owner_projection_change":true},{"round":2,"same_identity":true,"new_token_generation":true,"owner_projection_change":true}],"ok":true,"checked_on":"2026-10-06","transport":"AUTHENTICATED_POST_NOTIFICATIONS"},{"client":"Codex app-server","version":"codex-cli 0.150.1","registration":"auto","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":true,"restart_after_refresh_without_consent":true,"restart_before_expiry_without_consent":true,"expiry_rounds":[{"round":1,"same_identity":true,"new_token_generation":true,"owner_projection_change":true},{"round":2,"same_identity":true,"new_token_generation":true,"owner_projection_change":true}],"ok":true,"checked_on":"2026-10-06","transport":"AUTHENTICATED_POST_NOTIFICATIONS"},{"client":"Codex app-server","version":"codex-cli 0.156.0","registration":"dcr","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":true,"restart_after_refresh_without_consent":true,"restart_before_expiry_without_consent":true,"expiry_rounds":[{"round":1,"same_identity":true,"new_token_generation":true,"owner_projection_change":true},{"round":2,"same_identity":true,"new_token_generation":true,"owner_projection_change":true}],"ok":true,"checked_on":"2026-10-06","transport":"AUTHENTICATED_POST_NOTIFICATIONS"},{"client":"Codex app-server","version":"codex-cli 0.156.0","registration":"auto","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":true,"restart_after_refresh_without_consent":true,"restart_before_expiry_without_consent":true,"expiry_rounds":[{"round":1,"same_identity":true,"new_token_generation":true,"owner_projection_change":true},{"round":2,"same_identity":true,"new_token_generation":true,"owner_projection_change":true}],"ok":true,"checked_on":"2026-10-06","transport":"AUTHENTICATED_POST_NOTIFICATIONS"}],"limits":["CLI/native app-server checks do not establish desktop UI or cloud-client compatibility.","Claude Code and Cursor checks establish native discovery, token renewal and fresh-process reconnection; they do not invoke an LLM.","Codex additionally makes an authenticated identity_whoami MCP tool call before expiry.","No production account credentials or private workspace data are part of this report.","Compatibility applies to the two recorded CLI versions. Newer versions, desktop UI and cloud clients require their own checks.","Actual LLM exec checks each completed three identity calls through two actual65-second pauses, without manual token injection. The owner consent step remains a harness action."],"reproduce":{"all":"cd backend && .venv/bin/python -m e2e.native_oauth","passing_clients":"cd backend && .venv/bin/python -m e2e.native_oauth --clients claude,cursor","codex":"cd backend && .venv/bin/python -m e2e.native_oauth --clients codex-dcr,codex-auto --expiry-rounds 2","codex_exec":"cd backend && .venv/bin/python -m e2e.codex_oauth_exec --wait-rounds 2 --output data/codex-oauth-exec-recheck.json"},"protocol_checks":{"claude_cursor":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":5},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":8},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":2},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":14},{"path":"/mcp","operation":"server/discover","status":200,"error":"","count":3},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":9},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":9},{"path":"/mcp","operation":"","status":200,"error":"","count":6},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":6},{"path":"/mcp","operation":"initialize","status":401,"error":"","count":2},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/mcp","operation":"resources/list","status":200,"error":"","count":3}],"codex_installed":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/mcp","operation":"","status":401,"error":"","count":12},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":12},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":12},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":2},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":2},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":4},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":4},{"path":"/mcp","operation":"","status":405,"error":"","count":4},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":4},{"path":"/mcp","operation":"tools/call","status":200,"error":"","count":8},{"path":"/v1/agents/agt_01M47ENFA0FJ7SCNTQ8S4V7X8Z/activate-read","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":4},{"path":"/v1/agents/agt_01M47ES78WBDEFK3P4AZPHQ3HE/activate-read","operation":"","status":200,"error":"","count":2}],"codex_0_156":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/mcp","operation":"","status":401,"error":"","count":12},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":12},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":12},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":2},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":2},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":4},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":4},{"path":"/mcp","operation":"","status":405,"error":"","count":4},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":4},{"path":"/mcp","operation":"tools/call","status":200,"error":"","count":8},{"path":"/v1/agents/agt_01M47EM9T11A3TCW8DF69VHPSW/activate-read","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":4},{"path":"/mcp","operation":"","status":204,"error":"","count":4},{"path":"/v1/agents/agt_01M47ER1V79J2PXN6BWMKMQT11/activate-read","operation":"","status":200,"error":"","count":2}]},"native_exec_checks":[{"at":"2026-10-06T01:53:07.198707+00:00","client":"codex-cli 0.150.1","kind":"ACTUAL_CODEX_EXEC_OAUTH_EXPIRY","access_ttl_seconds":60,"actual_model_turn":true,"server_token_injection":false,"boundaries":"Isolated CLI/native home and PostgreSQL schema. Not a desktop UI test.","expected_identity_calls":3,"process_exit_code":0,"exec_wall_seconds":160.23,"wait_command_observed":true,"mcp_calls":[{"tool":"identity.whoami","status":"COMPLETED"},{"tool":"identity.whoami","status":"COMPLETED"},{"tool":"identity.whoami","status":"COMPLETED"}],"refresh_timeline":[{"path":"/oauth/token","method":"POST","seconds":85.68,"grant_type":"refresh_token","resource_present":true,"client_ordinal":1,"refresh_ordinal":2,"status":200,"oauth_error":null,"replacement_ordinal":3},{"path":"/oauth/token","method":"POST","seconds":156.28,"grant_type":"refresh_token","resource_present":true,"client_ordinal":1,"refresh_ordinal":3,"status":200,"oauth_error":null,"replacement_ordinal":4}],"mcp_protocol_counts":[{"method":"","status":401,"count":5},{"method":"initialize","status":200,"count":1},{"method":"notifications/initialized","status":202,"count":1},{"method":"","status":405,"count":1},{"method":"tools/list","status":200,"count":1},{"method":"tools/call","status":200,"count":3},{"method":"","status":204,"count":1}],"successful_identity_calls":3,"all_expected_native_identity_calls":true,"two_successful_native_identity_calls":true,"same_identity":true,"refresh_success":true,"ok":true,"cleanup":"Own backend stopped and owned test schema dropped; temporary native home deleted."},{"at":"2026-10-06T01:53:06.057417+00:00","client":"codex-cli 0.156.0","kind":"ACTUAL_CODEX_EXEC_OAUTH_EXPIRY","access_ttl_seconds":60,"actual_model_turn":true,"server_token_injection":false,"boundaries":"Isolated CLI/native home and PostgreSQL schema. Not a desktop UI test.","expected_identity_calls":3,"process_exit_code":0,"exec_wall_seconds":160.11,"wait_command_observed":true,"mcp_calls":[{"tool":"identity.whoami","status":"COMPLETED"},{"tool":"identity.whoami","status":"COMPLETED"},{"tool":"identity.whoami","status":"COMPLETED"}],"refresh_timeline":[{"path":"/oauth/token","method":"POST","seconds":83.68,"grant_type":"refresh_token","resource_present":true,"client_ordinal":1,"refresh_ordinal":2,"status":200,"oauth_error":null,"replacement_ordinal":3},{"path":"/oauth/token","method":"POST","seconds":155.88,"grant_type":"refresh_token","resource_present":true,"client_ordinal":1,"refresh_ordinal":3,"status":200,"oauth_error":null,"replacement_ordinal":4}],"mcp_protocol_counts":[{"method":"","status":401,"count":5},{"method":"initialize","status":200,"count":1},{"method":"notifications/initialized","status":202,"count":1},{"method":"","status":405,"count":1},{"method":"tools/list","status":200,"count":1},{"method":"tools/call","status":200,"count":3},{"method":"","status":204,"count":1}],"successful_identity_calls":3,"all_expected_native_identity_calls":true,"two_successful_native_identity_calls":true,"same_identity":true,"refresh_success":true,"ok":true,"cleanup":"Own backend stopped and owned test schema dropped; temporary native home deleted."}],"historical_results_before_codex_compatibility":[{"client":"Claude Code","version":"2.1.284 (Claude Code)","login":true,"tools_discovered":true,"refresh_after_expiry":true,"restart_without_consent":true,"checked_on":"2026-10-02"},{"client":"Cursor CLI","version":"2026.09.28-64d2043","login":true,"tools_discovered":true,"refresh_after_expiry":true,"restart_without_consent":true,"checked_on":"2026-10-02"},{"client":"Codex app-server","version":"codex-cli 0.150.1","registration":"dcr","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":false,"restart_after_refresh_without_consent":false,"restart_before_expiry_without_consent":true,"ok":false,"failure_type":"RuntimeError","check":"Native client rejected mcpServer/tool/call","checked_on":"2026-10-06"},{"client":"Codex app-server","version":"codex-cli 0.150.1","registration":"auto","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":false,"restart_after_refresh_without_consent":false,"restart_before_expiry_without_consent":true,"ok":false,"failure_type":"RuntimeError","check":"Native client rejected mcpServer/tool/call","checked_on":"2026-10-06"},{"client":"Codex app-server","version":"codex-cli 0.156.0","registration":"dcr","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":false,"restart_after_refresh_without_consent":false,"restart_before_expiry_without_consent":true,"ok":false,"failure_type":"AssertionError","check":"Native tool failed","checked_on":"2026-10-06"},{"client":"Codex app-server","version":"codex-cli 0.156.0","registration":"auto","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":false,"restart_after_refresh_without_consent":false,"restart_before_expiry_without_consent":true,"ok":false,"failure_type":"AssertionError","check":"Native tool failed","checked_on":"2026-10-06"}],"historical_codex_failure":{"observed":"Codex 0.150.1 and 0.156.0: both DCR and automatic registration login and initial identity_whoami succeed. Native transport refreshes once, then submits the consumed refresh token again about nine seconds later and receives invalid_grant. Ordinary LLM codex exec tests of both versions also fail after a real sleep 65 pause.","restart_after_refresh":"Not reached: refresh failure revokes the token family.","cause":"The trace establishes stale-token reuse; the internal client cause has not been independently established.","workaround":"Use a revocable project key for the tested Codex 0.150.1 and 0.156.0 versions. OAuth remains unverified for sustained use; do not disable refresh replay protection to make it pass.","status":"HISTORICAL_BEFORE_COMPATIBILITY"},"historical_native_exec_checks":[{"client":"codex-cli 0.150.1","actual_model_turn":true,"process_exit_code":0,"mcp_calls":[{"tool":"identity.whoami","status":"COMPLETED"}],"two_successful_native_identity_calls":false,"refresh_success":true,"ok":false},{"client":"codex-cli 0.156.0","actual_model_turn":true,"process_exit_code":0,"mcp_calls":[{"tool":"identity.whoami","status":"COMPLETED"}],"two_successful_native_identity_calls":false,"refresh_success":true,"ok":false}],"historical_protocol_checks":{"claude_cursor":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":5},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":8},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":2},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":14},{"path":"/mcp","operation":"server/discover","status":200,"error":"","count":3},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":9},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":9},{"path":"/mcp","operation":"","status":200,"error":"","count":6},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":6},{"path":"/mcp","operation":"initialize","status":401,"error":"","count":2},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/mcp","operation":"resources/list","status":200,"error":"","count":3}],"codex":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/mcp","operation":"","status":401,"error":"","count":8},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":8},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":8},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":2},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":2},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":2},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":2},{"path":"/mcp","operation":"","status":200,"error":"","count":6},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":2},{"path":"/mcp","operation":"tools/call","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":2},{"path":"/oauth/token","operation":"refresh_token","status":400,"error":"invalid_grant","count":2}],"codex_latest_checked":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/mcp","operation":"","status":401,"error":"","count":8},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":8},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":8},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":2},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":2},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":2},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":2},{"path":"/mcp","operation":"","status":200,"error":"","count":6},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":2},{"path":"/mcp","operation":"tools/call","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":2},{"path":"/oauth/token","operation":"refresh_token","status":400,"error":"invalid_grant","count":2}],"codex_0_156_0":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/mcp","operation":"","status":401,"error":"","count":8},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":8},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":8},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":2},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":2},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":2},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":2},{"path":"/mcp","operation":"","status":200,"error":"","count":6},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":2},{"path":"/mcp","operation":"tools/call","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":2},{"path":"/oauth/token","operation":"refresh_token","status":400,"error":"invalid_grant","count":4}]},"codex_compatibility":{"status":"PASS_FOR_RECORDED_CLI_VERSIONS","versions":["0.150.1","0.156.0"],"mechanism":"Decline the optional standalone GET stream only for authenticated OAuth sessions initialized by these codex-mcp-client versions; deliver queued notifications through authenticated POST SSE responses. The regular tool-result inbox remains available.","observed_cause":"A successful background refresh was followed by foreground reuse of the old refresh. Disabling the competing GET transport removed the failure in actual clients. This does not establish the internal Codex source-code cause.","security":"Access expiry, rotating refresh, client/resource binding, consent expiry, revocation and the existing two-second duplicate retry window remain unchanged.","existing_revoked_grants":"A fresh login and owner consent are required; revoked token families are never restored.","idle_notifications":"Queued notifications wait until the client makes its next request. Other clients and project-key connections keep the standalone GET stream."},"final_source_rechecks":[{"environment":"Isolated PostgreSQL, installed native client, real HTTP","results":[{"client":"Codex app-server","version":"codex-cli 0.150.1","registration":"dcr","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":true,"restart_after_refresh_without_consent":true,"restart_before_expiry_without_consent":true,"expiry_rounds":[{"round":1,"same_identity":true,"new_token_generation":true,"owner_projection_change":true},{"round":2,"same_identity":true,"new_token_generation":true,"owner_projection_change":true}],"ok":true}],"post_only_experiment":false,"initialize_clients":[{"client_name":"codex-mcp-client","client_version":"0.150.1","status":200},{"client_name":"codex-mcp-client","client_version":"0.150.1","status":200}],"foreground_notification_responses":[{"seconds":62.76,"rpc_method":"tools/call","status":200},{"seconds":123.94,"rpc_method":"tools/call","status":200}],"protocol_checks":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/mcp","operation":"","status":401,"error":"","count":6},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":6},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":6},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":1},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":1},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":1},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":2},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":2},{"path":"/mcp","operation":"","status":405,"error":"","count":2},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":2},{"path":"/mcp","operation":"tools/call","status":200,"error":"","count":4},{"path":"/v1/agents/agt_01M47ET3VD9PD1D6JYT4E3P127/activate-read","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":2}],"refresh_timeline":[{"path":"/oauth/token","method":"POST","seconds":62.71,"grant_type":"refresh_token","resource_present":true,"client_ordinal":1,"refresh_ordinal":2,"status":200,"oauth_error":null,"replacement_ordinal":3},{"path":"/oauth/token","method":"POST","seconds":123.87,"grant_type":"refresh_token","resource_present":true,"client_ordinal":1,"refresh_ordinal":3,"status":200,"oauth_error":null,"replacement_ordinal":4}]},{"environment":"Isolated PostgreSQL, installed native client, real HTTP","results":[{"client":"Codex app-server","version":"codex-cli 0.156.0","registration":"dcr","login":true,"tools_discovered":true,"native_tool_call":true,"refresh_after_expiry":true,"restart_after_refresh_without_consent":true,"restart_before_expiry_without_consent":true,"expiry_rounds":[{"round":1,"same_identity":true,"new_token_generation":true,"owner_projection_change":true},{"round":2,"same_identity":true,"new_token_generation":true,"owner_projection_change":true}],"ok":true}],"post_only_experiment":false,"initialize_clients":[{"client_name":"codex-mcp-client","client_version":"0.156.0","status":200},{"client_name":"codex-mcp-client","client_version":"0.156.0","status":200}],"foreground_notification_responses":[{"seconds":62.13,"rpc_method":"tools/call","status":200},{"seconds":123.31,"rpc_method":"tools/call","status":200}],"protocol_checks":[{"path":"/health","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/demo","operation":"","status":200,"error":"","count":1},{"path":"/v1/auth/login","operation":"","status":200,"error":"","count":1},{"path":"/mcp","operation":"","status":401,"error":"","count":6},{"path":"/.well-known/oauth-protected-resource/mcp","operation":"","status":200,"error":"","count":6},{"path":"/.well-known/oauth-authorization-server","operation":"","status":200,"error":"","count":6},{"path":"/oauth/register","operation":"","status":201,"error":"","count":1},{"path":"/oauth/authorize","operation":"","status":303,"error":"","count":1},{"path":"/v1/oauth/requests/{id}/decision","operation":"","status":200,"error":"","count":1},{"path":"/oauth/token","operation":"authorization_code","status":200,"error":"None","count":1},{"path":"/mcp","operation":"initialize","status":200,"error":"","count":2},{"path":"/mcp","operation":"notifications/initialized","status":202,"error":"","count":2},{"path":"/mcp","operation":"","status":405,"error":"","count":2},{"path":"/mcp","operation":"tools/list","status":200,"error":"","count":2},{"path":"/mcp","operation":"tools/call","status":200,"error":"","count":4},{"path":"/v1/agents/agt_01M47ET3TE1P4NYZZ7M3MCHCHD/activate-read","operation":"","status":200,"error":"","count":2},{"path":"/oauth/token","operation":"refresh_token","status":200,"error":"None","count":2},{"path":"/mcp","operation":"","status":204,"error":"","count":2}],"refresh_timeline":[{"path":"/oauth/token","method":"POST","seconds":62.07,"grant_type":"refresh_token","resource_present":true,"client_ordinal":1,"refresh_ordinal":2,"status":200,"oauth_error":null,"replacement_ordinal":3},{"path":"/oauth/token","method":"POST","seconds":123.24,"grant_type":"refresh_token","resource_present":true,"client_ordinal":1,"refresh_ordinal":3,"status":200,"oauth_error":null,"replacement_ordinal":4}]}]}