Could you confirm whether this is a known issue with Cursor Cloud / background agents?
Specifically:
Should Cursor Cloud be using /agents/mcp/oauth/callback instead of /bot/mcp/oauth/callback? Is there a configuration or workaround I can use to change the callback URI? If not, does Cursor need to coordinate with AWS to have the /bot/ callback added to AWS MCP’s OAuth redirect allowlist?
This is specifically affecting the cloud version of aws-mcp. My local AWS CLI authentication/profile works correctly
I have exactly the same problem since yesterday. Before that, I have been running these AWS MCP calls successfully for over three weeks using the cloud agent.
For AI issues: which model did you use?
Model name (e.g., Sonnet 4, Tab…)
For AI issues: add Request ID with privacy disabled
Request ID: f9a7046a-279b-47e5-ab48-6e8dc12daba1
For Background Agent issues, also post the ID: bc-…
Additional Information
Add any other context about the problem here.
Does this stop you from using Cursor?
Yes - Cursor is unusable
Sometimes - I can sometimes use Cursor
No - Cursor works, but with this issue
The more details you provide, the easier it is for us to reproduce and fix the issue. Thanks!
You’ve read this correctly. Cursor Cloud does use https://www.cursor.com/agents/mcp/oauth/callback as its redirect URI, but a recent change on our side started including an additional callback URL (the /bot/ one in your screenshot) in the client registration we send to MCP servers.
AWS validates every URL in that list against its allowlist, so it rejects the entire registration before the sign-in page ever loads. That’s also why this worked for weeks and then suddenly stopped.
There’s no setting on your end that affects this, and you don’t need to ask AWS to allowlist anything. The fix is on our side, and we’ll keep this thread updated.