I do security review for my company. I suspect this is a means of containing OAuth redirect vulnerabilities. We basically needed to do the same thing with our MCP server.
The security problem is two fold: (1) companies want control over where their data goes. Figma allowing any MCP creates problems (2) open redirects can create phishing issues. If your using Pi, you’re probably thinking of this. Most users aren’t.
For us, we decided to do an allowlist pattern because it was a reasonable tradeoff. The solution is allowing per-tenant client configuration, but that comes with its own set of issues (dev time, support, maintenance, etc). When nearly all of the money is flowing through a handful of well-known MCPs there’s little reason to out effort into supporting every MCP.
It’s not a very good way of doing that though. Rather than constraining the callback url to pre-registered partners, you just need to enter “Claude Code” as your product name and it lets you in.
We need OIDC tokens generated at the SSO placed on the dev environment upon user authentication and then have those OIDCs reusable among multiple mcps. People don't wanna login to 10 different mcps every morning.
> companies want control over where their data goes
That's the age-old problem that's the root of this debacle, too. Both the companies and the users want control over a shared resource, and each side has a different opinion on where the border lies :).
(In practice, as a user, that's why my mind reads the phrase "OAuth redirect vulnerabilities" as a feature of a product, not a bug.)