Hi Vercel team,
I'd like to request first-class OAuth compatibility between the official Vercel MCP server and Tailscale Aperture.
This is not just a request to allowlist my individual deployment. Tailscale Aperture users commonly host their Aperture gateway on Tailscale-managed .ts.net hostnames, and the current Vercel MCP redirect URI policy prevents those users from completing OAuth authorization.
Current behavior
Aperture successfully discovers the OAuth metadata and Dynamic Client Registration endpoint for:
https://mcp.vercel.com/
However, DCR fails when registering an Aperture callback URI.
For example, my Aperture instance uses:
https://ai.dala-castor.ts.net/aperture/auth/vercel/callback
Registering that callback directly against Vercel returns:
invalid_redirect_uri
The provided redirect URIs are not approved for use by this authorization server.
The flow is OAuth authorization code + PKCE (S256), with per-user authorization.
Request
Rather than allowlisting only my individual hostname, could Vercel support Tailscale Aperture callback URLs generally?
Aperture uses a well-defined callback structure:
https://<aperture-hostname>/aperture/auth/<connector-id>/callback
For Aperture installations using Tailscale DNS, this results in callback URLs under .ts.net.
One possible restricted pattern would therefore be:
https://*.ts.net/aperture/auth/*/callback
The intention is not to treat arbitrary .ts.net URLs as trusted OAuth redirects.
Ideally, Vercel could recognize Tailscale Aperture as an approved MCP client and permit only its documented callback structure on Tailscale-managed HTTPS hostnames.
That would allow any Tailscale Aperture user to connect to the official Vercel MCP server without requiring a separate manual allowlist request for every tailnet or Aperture deployment.
Current deployment for reproduction
-
MCP server:
https://mcp.vercel.com/ -
Client / gateway: Tailscale Aperture
-
Example callback:
https://ai.dala-castor.ts.net/aperture/auth/vercel/callback -
OAuth flow: authorization code + PKCE (S256)
-
Registration: Dynamic Client Registration
-
Authorization: per-user
Tailscale Aperture documentation:
https://tailscale.com/docs/aperture/connectors
OAuth connector documentation:
https://tailscale.com/docs/aperture/how-to/set-up-per-user-oauth2-connector
Connector reference:
https://tailscale.com/docs/aperture/connectors/reference
Vercel MCP documentation:
https://vercel.com/docs/agent-resources/vercel-mcp
There are already several Vercel Community threads where hosted MCP clients encountered the same invalid_redirect_uri restriction and were subsequently added to the Vercel MCP allowlist.
Supporting Aperture at the platform level would avoid repeating that process for every individual Tailscale user.
Thanks.
