You see this error when you sign in to Recorded Future MCP from a browser with an integration user Client ID.
When you sign in, Recorded Future sends you back to your MCP client at a specified address. This address is the redirect URI. For example, Claude uses this redirect URI:
https://claude.ai/api/mcp/auth_callback
Recorded Future sends you back only to a redirect URI that is registered to your Client ID. A new Client ID has no registered redirect URIs. If the redirect URI is not registered, Recorded Future stops the sign-in and shows this error.
To correct the error, add the redirect URI to your Client ID in the Integration Center.
Before you start
- You must be an enterprise administrator to add or remove redirect URIs.
- You can add redirect URIs only to Client ID/Secret credentials.
- Each Client ID has a different list of redirect URIs. If you make a new Client ID, add the redirect URI to the new Client ID.
Find the redirect URI of your MCP client
If you use Claude, use this redirect URI: https://claude.ai/api/mcp/auth_callback. Then go to the next procedure.
If you use a different MCP client, find the redirect URI in the browser page that shows the error:
- Find the address bar of the browser page that shows the error.
- In the address, find the text that starts with redirect_uri=.
- Copy the text between redirect_uri= and the next & character.
- In the text that you copied, replace each %3A with :.
- Replace each %2F with /.
Example: https%3A%2F%2Fclaude.ai%2Fapi%2Fmcp%2Fauth_callback changes to https://claude.ai/api/mcp/auth_callback. - In the same address, find the text that starts with client_id=.
- Record the value after client_id=. This value is your Client ID.
Add the redirect URI to your Client ID
- In the Recorded Future portal, go to Integration Center.
- Open the Recorded Future MCP tile.
- Edit your integration user.
- Find the credential that has your Client ID.
- On that credential, select Add Redirect URI.
- Paste the redirect URI into the Redirect URI field.
- Select Save.
Sign in again
- Go to your MCP client.
- Sign in from the browser again.
The Recorded Future sign-in page opens. After you sign in, the browser goes back to your MCP client. The MCP client connects to Recorded Future MCP.
Rules for redirect URIs
Recorded Future accepts a redirect URI only if it is exactly the same as a registered redirect URI.
CAUTION: Copy and paste the redirect URI. Do not type it, as a small difference causes the error. For example, an added / at the end causes the error.
| Rule | Correct | Incorrect |
| The redirect URI must be a full address. | https://example.com/callback | /callback |
| The redirect URI must start with https://. | https://example.com/callback | http://example.com/callback |
| You can use http:// only for tests on your local computer. | http://localhost:3000/callback, http://127.0.0.1:8080/callback | http://192.168.1.10/callback |
| The redirect URI must not contain the # character. | https://example.com/callback | https://example.com/callback#done |
| The redirect URI must not contain the * character. | https://app.example.com/callback | https://*.example.com/callback |
| The redirect URI can contain a query. The query must not contain OAuth parameters, for example code or state. | https://example.com/callback?tenant=acme | https://example.com/callback?code=123 |
NOTE: https://example.com/callback and https://example.com/callback/ are two different redirect URIs.
Remove a redirect URI
CAUTION: Make sure that no MCP client uses the redirect URI before you remove it. If an MCP client uses the redirect URI, that MCP client cannot sign in with this Client ID.
- On the credential in the Integration Center, select the redirect URIs.
- Find the redirect URI that you want to remove.
- Select the menu next to that redirect URI.
- Select Remove.
If you still see the error
- Compare the registered redirect URI with the redirect_uri value in the address bar. Make sure that they are exactly the same.
- Examine these items:
- http and https
- A / character at the end
- The domain name
- Make sure that the client_id value in the address bar is the same as the Client ID of the credential.
- If you use more than one MCP client, add the redirect URI of each MCP client.
- If you see Could not add URI when you select Save, the redirect URI does not obey a rule. Compare the redirect URI with the rules in the table.
- If the error continues, send a message to Recorded Future Support. Include the Client ID and the redirect URI from the address bar.
CAUTION: Do not send your Client Secret to Recorded Future Support.
This content is confidential. Do not distribute or download content in a manner that violates your Recorded Future license agreement. Sharing this content outside of licensed Recorded Future users constitutes a breach of the terms and/or agreement and shall be considered a breach by your organization.