[Gemini app: Spark custom apps] MCP OAuth never exchanges the code, "Cannot Complete Request" on oauth-redirect.googleusercontent.com

Summary

Adding a custom app (MCP server) in the Gemini app fails at the last step of OAuth. Gemini registers, the user signs in, and the authorization server returns a code to Google’s relay. Gemini never calls the token endpoint. The relay page shows “Cannot Complete Request” and the connection is not added.

Setup

  • MCP server: https://camberstack.io/mcp (Streamable HTTP)
  • Auth: OAuth 2.1, dynamic client registration (RFC 7591), PKCE S256, protected resource metadata (RFC 9728)
  • Account: personal Google account, Google AI Pro, US, English, Keep Activity on
  • Clients tried: Gemini app (Android), Chrome, Firefox. All fail the same way.

What our server logs show (every attempt, e.g. 2026-10-02 12:22 UTC)

step user agent request result
1 Google POST /mcp 401 with WWW-Authenticate: Bearer resource_metadata="…"
2 Google GET /.well-known/oauth-protected-resource/mcp 200
3 Google GET /.well-known/oauth-authorization-server 200
4 OpenAuth POST /register (6 redirect_uris on oauth-redirect*.googleusercontent.com) 201
5 browser GET /authorize → user signs in 302 to https://oauth-redirect.googleusercontent.com/r/user_bound_custom-mcp-…-camberstack_io?state=…&code=…
6 — POST /token never arrives code is never redeemed

The state (~1,400 characters) is returned byte for byte.

What we ruled out

  • Client authentication: tried a confidential client (client_secret_post) and a public client (none, no secret). Same result.
  • Issuer: tried https://camberstack.io/ and https://camberstack.io (no trailing slash). Same result.
  • Network: Google-owned IPs unblocked at the firewall during testing. The relay never reaches the server.
  • Browser / account: Gemini app, Chrome and Firefox; a single signed-in Google account, the same one used for Gemini.
  • Upstream sign-in: with our Google sign-in step bypassed, the relay returns to gemini.google.com without the error page, but still never calls /token.

The same server connects and works from Claude and ChatGPT.

Expected

After the 302 to the relay with code and state, Gemini’s backend should POST /token with the code and PKCE verifier, and the custom app should be added.

Question

Is there a requirement for the authorization response or server metadata that the relay checks before exchanging the code? “Cannot Complete Request — Additional information about this problem or error is currently unavailable” gives server developers nothing to go on.