Allowlist hosted OAuth redirects for Vercel Connect, Devin, and other cloud agent platforms
J
Josh Sacks
CircleCI supports OAuth 2.0 Dynamic Client Registration (DCR) with PKCE for API / MCP auth. The limitation is redirect URIs: DCR only accepts RFC 8252 loopback (localhost / 127.0.0.1 / ::1) plus a small allowlist of hosted callbacks (e.g. VS Code, Claude, Cursor Cloud Agents).
We need either:
- Expanded allowlisting of trusted hosted OAuth callbacks for cloud / remote agent platforms, or
- A way for customers to register known callbacks for their own hosted agents
Priority platforms that fail today with “no supported redirect_uri”:
- Vercel Connect — https://connect.vercel.com/callback
- Devin — https://api.devin.ai/mcp/oauth/callback
- Other hosted MCP / agent hosts that cannot use localhost (same class as Cursor Cloud Agents, which is already allowlisted)
Without this, those hosts cannot complete OAuth and must fall back to a Personal API Token / API-key connector.