DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.
MCP OAuth callback listeners are now session-scoped
Under the hood
Useful2Signal2
MCP
MCP sign-in callbacks are tracked per session, so a new session can't inherit another's pending listeners.
What's wrong with this entry?
Anonymous. No account, no email.
What
The two MCP OAuth flows no longer keep their in-flight callback listeners in process-wide maps; registration and abort go through a per-session object, so a new session cannot inherit another one's pending listeners.
Evidence
oauthCallbackListeners
Strings lifted out of the shipped bundle, so the claim above can be checked against them.