MCP OAuth .localhost redirect URI: Sume allows localhost and 127.0.0.1
MCP TypeScript SDK 2.2.0 treats .localhost hosts as loopback for token endpoints. Sume's redirect check allows http only on localhost and 127.0.0.1.

A callback such as http://app.localhost:3000/callback is not on Sume's redirect allow list. In Sume's OAuth check, plain http is accepted only when the host is localhost or 127.0.0.1, so use one of those for local development.
The .localhost change is from the MCP TypeScript SDK 2.2.0 notes and applies to token endpoints in that SDK, which is a different question from which redirect URIs a server accepts. Sume's rule is from its OAuth code, read 2026-10-01, alongside MCP OAuth and API keys.
What did the TypeScript SDK change?
The fixes list says: "Hostnames ending in .localhost count as loopback for OAuth token endpoints, so host-based multi-tenant local setups work." It is about how the client treats a token endpoint hostname. It does not change what an authorization server accepts as a redirect URI.
Which redirect URIs does Sume accept over http?
The redirect check compares the parsed hostname with two literal values. Anything else that is not allowed gets the error message "OAuth redirect_uri is not allowed."
| Redirect host over http | Accepted? |
|---|---|
localhost | Yes |
127.0.0.1 | Yes |
app.localhost | No (not in the check) |
| Other hostnames over http | Rejected with OAuth redirect_uri is not allowed. |
What do I change in a local setup?
Register and use a redirect URI on http://localhost:<port>/... or http://127.0.0.1:<port>/.... Sume exposes a dynamic registration endpoint at /oauth/register on the MCP origin and requires PKCE with S256. If your tenant routing depends on a .localhost hostname, keep that for your app pages and send only the OAuth callback through a loopback address.
Client-specific callback notes: Cursor and Claude Code.
What about a hosted callback?
The same code accepts any https: redirect URI, plus a specific Cursor callback, as of 2026-10-01. So a hosted deployment should use https; the loopback rule above is only about plain http.
Sources
Related posts
More in Developers
- MCP 403 forbidden_origin: why a browser client is refused
Sume remote MCP answers a disallowed Origin header with 403 forbidden_origin. A request with no Origin, like curl or a server SDK, is not checked this way.
- MCP progressive discovery: Sume tools_list, then tools_schema
For a large MCP tool set, list first and fetch one contract second. Sume has tools_list for visible tools and tools_schema for a single tool by name.
- MCP resource not found -32602: Sume is tools-only, so -32601
MCP 2026-07-28 moves resource-not-found from -32002 to -32602. Sume's hosted MCP advertises tools only, so resources/read gets method-not-found -32601.
- MCP standardized error handling: Sume's named outcomes
MCP has no single error standard across surfaces yet. Here is how Sume's named outcomes map to retry, re-auth, or stop in a hosted MCP client.
Written by Sume