fix(mcp-oauth): one-click connect — friendly success page + private-use URI schemes - #16
Merged
Merged
Conversation
MCP clients (Claude, Cursor, Codex, Lovable, OpenClaw, Hermes, …) were dropping users on the browser's "site can't be reached" screen when the loopback listener had closed or the client used a deep-link scheme that DCR rejected. - New /oauth/success page confirms the connection visually, fires a no-cors fetch to the loopback listener (so the CLI still receives the code), triggers private-use URI schemes for desktop clients, and shows a copy-pasteable auth code as a manual fallback. - Auth code is handed off via sessionStorage so it never lands in the URL bar or browser history. - Client registration (HTTP + SQL) now accepts private-use URI scheme redirects per RFC 8252 §7, not just https / loopback http. - Docs updated to describe the new flow. https://claude.ai/code/session_019gMoupKKTVydpNwiiACQRd
criptogus
marked this pull request as ready for review
May 21, 2026 16:12
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Users connecting MCP clients (Claude, Cursor, Codex, Lovable, OpenClaw, Hermes, …) were dropped on the browser's
"site can't be reached"page after consent. Two root causes:Authorize, we navigated the tab straight tohttp://localhost:XXXXX/callback?code=…. If the client's loopback listener had already closed (or wasn't up), the browser showed a broken URL with no recovery path — common-user dead end.cursor://,vscode://,claude://,codex://,lovable://,hermes://,openclaw://) were rejected at DCR because both the HTTP handler and the SQL validator only acceptedhttps://or loopbackhttp://.Fix
/oauth/successpage confirms the connection visually ("Connected ✅ to {client}"), then:fetch(no-cors)to deliver the code to the CLI/desktop listener without navigating the tab (so a closed listener no longer breaks the page).https://callbacks: just redirects.sessionStorageso it never lands in URL bar / history of the consent tab./api/public/oauth/registerand themcp_oauth_register_clientRPC) now accepts private-use URI scheme redirects per RFC 8252 §7, while still rejecting non-loopback plainhttp://./docs/mcpupdated to describe the new flow.Files
src/routes/oauth.success.tsx(new)src/routes/oauth.authorize.tsx— hands off via sessionStorage, navigates to/oauth/successsrc/lib/oauth/mcp-oauth.functions.ts— also returns rawcodefor the fallback displaysrc/routes/api/public/oauth/register.ts— accept private-use URI schemessupabase/migrations/20260521000000_mcp_oauth_allow_private_uri_schemes.sql— matching server-side changesrc/routes/docs.mcp.tsx— describe the new success behaviorTest plan
npx -y super-agent connect --client claude-codeand confirm the success page appears and the CLI completes.Authorize— verify the success page appears with the auth code visible to paste./account/connections.redirect_uris: ["http://evil.example/cb"]→ still rejected.redirect_uris: ["cursor://callback"]→ accepted.https://claude.ai/code/session_019gMoupKKTVydpNwiiACQRd
Generated by Claude Code