Product or tool name: Airia (https://airia.ai)
Exact redirect URI to review:
- https://auth.airia.ai/OAuth/callback
MCP endpoints targeted: both https://mcp.intercom.com/mcp (US) and https://mcp.eu.intercom.com/mcp (EU). We have EU-hosted customers whose Intercom workspaces are on app.eu.intercom.com, so the EU endpoint is a requirement rather than a nice-to-have. Both authorization servers reject the URI today, so we'd need the allowlist entry on each.
Use case and distribution model: Airia is a multi-tenant SaaS platform. Each end user authorizes their own Intercom workspace through OAuth 2.1 authorization code with PKCE (S256); tokens are held in our credential store, encrypted at rest, scoped to the authorizing user, and never shared between users or tenants. Registration is one client per tenant, with per-user authorization on top. Distribution is direct to our own enterprise customers, where Intercom appears as one connector in our integration library, not resold or white-labeled.
We have at least one customer (AccurX) actively looking to use Intercom through Airia. While we are looking to use the bearer token auth method as a stopgap to allow our customer to be unblocked, for security reasons we would much prefer to push our users to use DCR OAuth.
We register a single redirect URI and proxy the callback internally, so allowlisting this URIs covers every customer we onboard rather than generating a new request per tenant.
Happy to provide anything else that helps with the review.
Thanks,
Cole McCord
Airia
colemccord@airia.com