AWS signin: Restrict DCR to public redirect URIs; add OAuth clients
Summary
Adds a note that Dynamic Client Registration (DCR) only supports public redirect URIs (private/internal/non-production URIs are not supported), and adds several new approved OAuth client redirect URIs (Unosecur, Cequence, Microsoft Copilot Studio, Arcade, Langdock, NeuralTrust, Devin, Executor) to the table.
Security assessment
The note constrains OAuth redirect URIs to public endpoints and explicitly disallows private/internal URIs, which reduces risk of redirect-based token leakage or abuse of non-production endpoints; the table additions enumerate allow-listed callback URIs. This is OAuth hardening guidance rather than a fix for a specific disclosed vulnerability.
Evidence
+Currently, only public redirect URIs are supported for Dynamic Client Registration (DCR). Private redirect URIs are not supported, including internal development and non-production URIs—even for the public OAuth clients listed in the following table.
Diff
diff --git a/signin/latest/userguide/aws-mcp-server.md b/signin/latest/userguide/aws-mcp-server.md index 27e605e6b..d205d4470 100644 --- a//signin/latest/userguide/aws-mcp-server.md +++ b//signin/latest/userguide/aws-mcp-server.md @@ -53,0 +54,4 @@ Agents can register with AWS Sign-In and use one or more approved redirect URIs +###### Note + +Currently, only public redirect URIs are supported for Dynamic Client Registration (DCR). Private redirect URIs are not supported, including internal development and non-production URIs—even for the public OAuth clients listed in the following table. + @@ -67,0 +72,8 @@ Vercel v0 | `https://api.v0.dev/v1/mcp-servers/oauth/callback` +Unosecur | `https://mcp-app.unosecur.com/connector-oauth/callback` +Cequence | `https://connect.aigateway.cequence.ai/oauth/callback` +Microsoft Copilot Studio | `https://global.consent.azure-apim.net/redirect/*` +Arcade | `https://cloud.arcade.dev/api/v1/oauth/*` +Langdock | `https://app.langdock.com/api/integrations/*` +NeuralTrust | `https://gateway-mcp.neuraltrust.ai/oauth/callback/com.amazon.aws/mcp` +Devin | `https://api.devin.ai/mcp/oauth/callback` +Executor | `https://executor.sh/api/oauth/callback`