95f64b6142
When an HTTP MCP server returns invalid_grant (or invalid_token / revoked / plain 401 from the token endpoint) during OAuth refresh, MCPManager previously logged "MCP OAuth refresh failed, using existing token" and re-attached the stale access token as Authorization: Bearer on every subsequent request. The next tool-load 401'd with invalid_token, future sessions repeated the loop, and the only recovery was to hand-clear the credential row in agent.db. Reported with Logfire as the trigger; any remote HTTP MCP that rotates / revokes refresh tokens is affected. #resolveAuthConfig now reuses pi-ai's isDefinitiveOAuthFailure classifier (same one auth-broker and AuthStorage use for first-party providers): on a definitive failure it calls AuthStorage.remove(credentialId), drops the Bearer entirely, and the next request surfaces a clean auth error so the user can /mcp reauth <server> (or /mcp unauth) to recover. Transient failures (network/fetch failed/ECONNREFUSED) still fall back to the existing token to ride out blips. Verified with new mcp-manager-oauth-refresh.test.ts (invalid_grant, 401, transient fallback, happy-path rotation). The full mcp-* test set (45 tests across 5 files) still passes. Fixes #1908