Hey there! This is expected behavior, not a regression, and it’s fixable on your side. We recently switched MCP OAuth in the desktop IDE to http://localhost:8787/callback, though some installs still fall back to the old cursor:// one, which is why it looks inconsistent.
Fix: in your OAuth client, allowlist both of these and keep both registered:
http://localhost:8787/callback
cursor://anysphere.cursor-mcp/oauth/callback
That way whichever callback a given install sends will match. There’s no mcp.json field or setting to pick the callback, so registering both is the way to go. See Static OAuth for remote servers.
If the warning persists after adding both, send the exact redirect_uri from Output → MCP: <your server> logs plus your provider name and I’ll dig in.