Problem
A user who pre-registers an OAuth client (client ID + secret) with their authorization server has to register the Inspector's redirect URI there before connecting. The Server Settings → OAuth Settings panel never shows that value. Other MCP clients (Claude, ChatGPT) show it so it can be copied into the AS configuration. Right now users have to guess it or read the source.
With DCR the Inspector sends redirect_uris itself, so this only matters for pre-registered (static) clients.
Current behavior
- Web: the redirect URI is
${window.location.origin}/oauth/callback (core/auth/browser/providers.ts:54), which is http://localhost:6274/oauth/callback by default. It follows the address bar, so 127.0.0.1 vs localhost, a non-default CLIENT_PORT or a non-local host all change it. Many authorization servers match redirect URIs exactly.
- TUI/CLI:
http://127.0.0.1:6276/oauth/callback by default (core/auth/node/runner-oauth-callback.ts), overridable via --callback-url / MCP_OAUTH_CALLBACK_URL.
Proposed
Add a read-only Redirect URI field with a copy button to the OAuth Settings section of the web Server Settings form. Compute it the same way the provider does, so the field cannot drift from the value actually sent. Add a short description noting that it depends on the origin the Inspector is opened from.
Out of scope: TUI/CLI surfaces. Their default is already fixed and documented in their READMEs.
Reported by a user asking whether the redirect URI is fixed and whether they should register it on their AS.
Problem
A user who pre-registers an OAuth client (client ID + secret) with their authorization server has to register the Inspector's redirect URI there before connecting. The Server Settings → OAuth Settings panel never shows that value. Other MCP clients (Claude, ChatGPT) show it so it can be copied into the AS configuration. Right now users have to guess it or read the source.
With DCR the Inspector sends
redirect_urisitself, so this only matters for pre-registered (static) clients.Current behavior
${window.location.origin}/oauth/callback(core/auth/browser/providers.ts:54), which ishttp://localhost:6274/oauth/callbackby default. It follows the address bar, so127.0.0.1vslocalhost, a non-defaultCLIENT_PORTor a non-local host all change it. Many authorization servers match redirect URIs exactly.http://127.0.0.1:6276/oauth/callbackby default (core/auth/node/runner-oauth-callback.ts), overridable via--callback-url/MCP_OAUTH_CALLBACK_URL.Proposed
Add a read-only Redirect URI field with a copy button to the OAuth Settings section of the web Server Settings form. Compute it the same way the provider does, so the field cannot drift from the value actually sent. Add a short description noting that it depends on the origin the Inspector is opened from.
Out of scope: TUI/CLI surfaces. Their default is already fixed and documented in their READMEs.
Reported by a user asking whether the redirect URI is fixed and whether they should register it on their AS.