Skip to content

Conversation

@sam-tombury
Copy link
Contributor

Relaxes the restriction on redirect_uri during OAuth client registration (and token flows) from AnyHttpUrl to AnyUrl.

Motivation and Context

Cursor uses deeplinks with a custom scheme for redirect_uri when registering OAuth clients for MCP, which currently fails validation (as it is not a valid AnyHttpUrl).

How Has This Been Tested?

Tested an MCP server using this branch and successfully registered Cursor as an OAuth client.

Breaking Changes

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

@asparsh29kumar
Copy link

This will actually be really helpful! I just opened an issue for this #897.

@Kludex Kludex merged commit 2bce10b into modelcontextprotocol:main Jun 7, 2025
10 checks passed
@sp94 sp94 mentioned this pull request Jun 19, 2025
9 tasks
saqadri pushed a commit to saqadri/stdio-fixes that referenced this pull request Aug 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants