Authentication failed: device_code_expired: Device code is expired. (teams-mcp)
Fixes the teams-mcp authenticate command failing with an expired device code. Use when npx @floriscornel/teams-mcp authenticate fails right after login. Not for AADSTS errors or missing licenses.
Authentication failed: devicecodeexpired: Device code is expired. (teams-mcp)
TL;DR: Re-run the authenticate command promptly and complete the browser login before the code expires. Old versions did not refresh tokens, so auth died after one hour and the device flow timed out. Upgrade to a current version with refresh-token support to stop this recurring.
The error
Authentication failed: device_code_expired: Device code is expired.Fix it
- Run npx @floriscornel/teams-mcp@latest authenticate again.
Expected: It shows a fresh device code and URL.
- Complete the browser login within a few minutes.
Expected: The CLI reports success and caches the token.
- Run the auth_status tool.
Expected: It shows authenticated.
- Upgrade the package to the latest to get refresh-token support.
Expected: Future sessions refresh silently.
When this applies
The teams-mcp device-code login fails with devicecodeexpired immediately after you log in.
When this does NOT apply
AADSTS700082 after weeks idle is the refresh-token expiry issue. 403s on chat tools are the license issue.
Tool compatibility
@floriscornel/teams-mcp, older versions without token refresh
Also seen as
- teams-mcp device code expired
- teams MCP authenticate fails
- devicecodeexpired floriscornel
Why it happens
The device code has a short lifetime, and older builds also failed to refresh the resulting token, so any delay or an hour-old session hit expiry. Newer builds cache a refresh token and renew silently.
Edge cases
- UTC-8 reporters suspected timezone drift; the real cause was the missing refresh.
- The client ID is the Microsoft Graph Command Line Tools first-party app; that is expected.
- Corporate conditional access can block device-code flow entirely; use AUTH_TOKEN instead.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.