MCP OAuth .localhost redirect URI: Sume allows localhost and 127.0.0.1
MCP TypeScript SDK 2.2.0 treats .localhost hosts as loopback for token endpoints. Sume's redirect check allows http only on localhost and 127.0.0.1.

A callback such as http://app.localhost:3000/callback is not on Sume's redirect allow list. In Sume's OAuth check, plain http is accepted only when the host is localhost or 127.0.0.1, so use one of those for local development.
The .localhost change is from the MCP TypeScript SDK 2.2.0 notes and applies to token endpoints in that SDK, which is a different question from which redirect URIs a server accepts. Sume's rule is from its OAuth code, read 2026-10-01, alongside MCP OAuth and API keys.
What did the TypeScript SDK change?
The fixes list says: "Hostnames ending in .localhost count as loopback for OAuth token endpoints, so host-based multi-tenant local setups work." It is about how the client treats a token endpoint hostname. It does not change what an authorization server accepts as a redirect URI.
Which redirect URIs does Sume accept over http?
The redirect check compares the parsed hostname with two literal values. Anything else that is not allowed gets the error message "OAuth redirect_uri is not allowed."
| Redirect host over http | Accepted? |
|---|---|
localhost | Yes |
127.0.0.1 | Yes |
app.localhost | No (not in the check) |
| Other hostnames over http | Rejected with OAuth redirect_uri is not allowed. |
What do I change in a local setup?
Register and use a redirect URI on http://localhost:<port>/... or http://127.0.0.1:<port>/.... Sume exposes a dynamic registration endpoint at /oauth/register on the MCP origin and requires PKCE with S256. If your tenant routing depends on a .localhost hostname, keep that for your app pages and send only the OAuth callback through a loopback address.
Client-specific callback notes: Cursor and Claude Code.
What about a hosted callback?
The same code accepts any https: redirect URI, plus a specific Cursor callback, as of 2026-10-01. So a hosted deployment should use https; the loopback rule above is only about plain http.
Sources
Related posts
More in Developers
- MCP progressive discovery: Sume tools_list, then tools_schema
For a large MCP tool set, list first and fetch one contract second. Sume has tools_list for visible tools and tools_schema for a single tool by name.
- MCP standardized error handling: Sume's named outcomes
MCP has no single error standard across surfaces yet. Here is how Sume's named outcomes map to retry, re-auth, or stop in a hosted MCP client.
- MCP sub-agent with narrower authority: a read-only Sume token
Give a sub-agent a Sume token granted only mcp:read and it sees read-only tools, so it can inspect jobs and assets but never submit a paid generation.
- MCP workload identity federation: Sume takes code grant only
MCP's roadmap names Workload Identity Federation. Sume's hosted MCP advertises only the authorization_code grant, so headless workloads use an API key.
Written by Sume