Requesting redirect URI allowlist for MCP DCR - Airia | Community
Skip to main content
Question

Requesting redirect URI allowlist for MCP DCR - Airia

  • September 2, 2026
  • 0 replies
  • 1 view

Product or tool name: Airia (https://airia.ai)

Exact redirect URI to review:

  • https://auth.airia.ai/OAuth/callback

MCP endpoints targeted: both https://mcp.intercom.com/mcp (US) and https://mcp.eu.intercom.com/mcp (EU). We have EU-hosted customers whose Intercom workspaces are on app.eu.intercom.com, so the EU endpoint is a requirement rather than a nice-to-have. Both authorization servers reject the URI today, so we'd need the allowlist entry on each. 

Use case and distribution model: Airia is a multi-tenant SaaS platform. Each end user authorizes their own Intercom workspace through OAuth 2.1 authorization code with PKCE (S256); tokens are held in our credential store, encrypted at rest, scoped to the authorizing user, and never shared between users or tenants. Registration is one client per tenant, with per-user authorization on top. Distribution is direct to our own enterprise customers, where Intercom appears as one connector in our integration library, not resold or white-labeled.

We have at least one customer (AccurX) actively looking to use Intercom through Airia. While we are looking to use the bearer token auth method as a stopgap to allow our customer to be unblocked, for security reasons we would much prefer to push our users to use DCR OAuth. 

We register a single redirect URI and proxy the callback internally, so allowlisting this URIs covers every customer we onboard rather than generating a new request per tenant.

Happy to provide anything else that helps with the review.

Thanks,
Cole McCord
Airia
colemccord@airia.com