Open Q&A
If there's no good subforum for your question - ask it here!
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Dynatrace MCP OAuth refresh fails after logout—supported approach for persistent per-user access?

vedant05422
Visitor

We’re connecting Rhythms to Dynatrace’s hosted remote MCP server using a confidential OAuth client with Authorization Code + PKCE. We need reliable per-user access without requiring users to remain signed into Dynatrace in their browser.

Normal refresh works. However, after explicitly signing out of Dynatrace, refresh fails. We independently reproduced this in VS Code on October 6:

  • Before logout: refresh succeeded.
  • After logout: HTTP 400, invalid_grant, UNSUCCESSFUL_OAUTH_REFRESH_TOKEN_VALIDATION_FAILED.
  • VS Code required a new login.

Separately, Rhythms has encountered UNSUCCESSFUL_OAUTH_REFRESH_TOKEN_MISSING_SESSION with “User session is no longer active.” We haven’t established whether all these failures have the same cause.

Could the OAuth/MCP team clarify:

  1. Is refresh-token invalidation after logout expected?
  2. What are the refresh-token and underlying session lifetimes, including idle limits?
  3. Is offline_access, or an equivalent persistent-access option, available for Authorization Code MCP clients? How is it enabled, and does trial versus paid account status matter?
  4. What is the supported approach for reliable background, per-user MCP access without frequent reconnection or switching to client credentials?
2 REPLIES 2

Julius_Loman
DynaMight Legend
DynaMight Legend

@vedant05422 can your users use platform tokens instead? https://docs.dynatrace.com/docs/shortlink/platform-tokens#my-platform-tokens

Dynatrace Ambassador | Alanata a.s., Slovakia, Dynatrace Master Partner

Thanks Julius! Platform tokens could be a fallback, but we prefer OAuth so customers don’t have to manually create and manage tokens. Is there a supported way to obtain persistent per-user access to the hosted remote MCP server through Authorization Code OAuth—such as offline_access or an equivalent? We reproduced refresh failure after Dynatrace logout in VS Code too, and would appreciate clarification on the expected session lifetime and refresh behavior.

Featured Posts