MCP OAuth .localhost redirect URI: Sume allows localhost and 127.0.0.1

MCP TypeScript SDK 2.2.0 treats .localhost hosts as loopback for token endpoints. Sume's redirect check allows http only on localhost and 127.0.0.1.

4 min readSume
All posts

A callback such as http://app.localhost:3000/callback is not on Sume's redirect allow list. In Sume's OAuth check, plain http is accepted only when the host is localhost or 127.0.0.1, so use one of those for local development.

The .localhost change is from the MCP TypeScript SDK 2.2.0 notes and applies to token endpoints in that SDK, which is a different question from which redirect URIs a server accepts. Sume's rule is from its OAuth code, read 2026-10-01, alongside MCP OAuth and API keys.

What did the TypeScript SDK change?

The fixes list says: "Hostnames ending in .localhost count as loopback for OAuth token endpoints, so host-based multi-tenant local setups work." It is about how the client treats a token endpoint hostname. It does not change what an authorization server accepts as a redirect URI.

Which redirect URIs does Sume accept over http?

The redirect check compares the parsed hostname with two literal values. Anything else that is not allowed gets the error message "OAuth redirect_uri is not allowed."

Loopback hosts for plain-http redirects in Sume's MCP OAuth code, read 2026-10-01.
Redirect host over httpAccepted?
localhostYes
127.0.0.1Yes
app.localhostNo (not in the check)
Other hostnames over httpRejected with OAuth redirect_uri is not allowed.

What do I change in a local setup?

Register and use a redirect URI on http://localhost:<port>/... or http://127.0.0.1:<port>/.... Sume exposes a dynamic registration endpoint at /oauth/register on the MCP origin and requires PKCE with S256. If your tenant routing depends on a .localhost hostname, keep that for your app pages and send only the OAuth callback through a loopback address.

Client-specific callback notes: Cursor and Claude Code.

What about a hosted callback?

The same code accepts any https: redirect URI, plus a specific Cursor callback, as of 2026-10-01. So a hosted deployment should use https; the loopback rule above is only about plain http.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume