Remote OAuth MCP servers dropped out of /mcp under `omp auth-broker
serve` once their access token expired: neither the client nor the
broker could complete the refresh.
- Client: the MCP manager threw on the broker-redacted refresh sentinel
(REMOTE_REFRESH_SENTINEL) instead of asking the broker to refresh. It
now routes redacted MCP refreshes through
AuthStorage.forceRefreshCredentialById, which calls back to the broker
(the real refresh token never leaves the broker host).
- Broker: the serve process had no mcp_oauth:* refresh path, so
POST /v1/credential/:id/refresh answered "Unknown OAuth provider". Its
AuthStorage is now built with a refreshOAuthCredential override that
refreshes MCP credentials with a generic refresh_token grant from the
credential's embedded token endpoint and client id. The background
refresher keeps MCP tokens live through the same path.
Extract shared refreshManagedMcpOAuthCredential and
mcpOAuthServerUrlFromCredentialId helpers so both paths use identical
refresh material selection and RFC 8707 fallback-resource logic.
Fixes#8933