Summary
Adding a custom app (MCP server) in the Gemini app fails at the last step of OAuth. Gemini registers, the user signs in, and the authorization server returns a code to Google’s relay. Gemini never calls the token endpoint. The relay page shows “Cannot Complete Request” and the connection is not added.
Setup
- MCP server:
https://camberstack.io/mcp(Streamable HTTP) - Auth: OAuth 2.1, dynamic client registration (RFC 7591), PKCE
S256, protected resource metadata (RFC 9728) - Account: personal Google account, Google AI Pro, US, English, Keep Activity on
- Clients tried: Gemini app (Android), Chrome, Firefox. All fail the same way.
What our server logs show (every attempt, e.g. 2026-10-02 12:22 UTC)
| step | user agent | request | result |
|---|---|---|---|
| 1 | Google |
POST /mcp |
401 with WWW-Authenticate: Bearer resource_metadata="…" |
| 2 | Google |
GET /.well-known/oauth-protected-resource/mcp |
200 |
| 3 | Google |
GET /.well-known/oauth-authorization-server |
200 |
| 4 | OpenAuth |
POST /register (6 redirect_uris on oauth-redirect*.googleusercontent.com) |
201 |
| 5 | browser | GET /authorize → user signs in |
302 to https://oauth-redirect.googleusercontent.com/r/user_bound_custom-mcp-…-camberstack_io?state=…&code=… |
| 6 | — | POST /token never arrives |
code is never redeemed |
The state (~1,400 characters) is returned byte for byte.
What we ruled out
- Client authentication: tried a confidential client (
client_secret_post) and a public client (none, no secret). Same result. - Issuer: tried
https://camberstack.io/andhttps://camberstack.io(no trailing slash). Same result. - Network: Google-owned IPs unblocked at the firewall during testing. The relay never reaches the server.
- Browser / account: Gemini app, Chrome and Firefox; a single signed-in Google account, the same one used for Gemini.
- Upstream sign-in: with our Google sign-in step bypassed, the relay returns to
gemini.google.comwithout the error page, but still never calls/token.
The same server connects and works from Claude and ChatGPT.
Expected
After the 302 to the relay with code and state, Gemini’s backend should POST /token with the code and PKCE verifier, and the custom app should be added.
Question
Is there a requirement for the authorization response or server metadata that the relay checks before exchanging the code? “Cannot Complete Request — Additional information about this problem or error is currently unavailable” gives server developers nothing to go on.