Hosted MCP Extensions can use OAuth with dynamic client registration, PKCE, state validation, and a local callback listener.
Connect
- Open Extend.
- Select a hosted integration marked Needs Auth.
- For fieldless hosted entries, click Connect on the card.
- Complete authorization in the system browser.
- Return to TurenOS; the card updates to Connected after token exchange and tool discovery.
Entries with required configuration open a dialog before authorization.
Callback safety
TurenOS starts the callback listener before opening the browser, binds OAuth state to the MCP name, validates the callback state, and clears pending verifier/state data after completion, failure, timeout, or cancellation.
Refresh and access tokens are stored through the Secret Vault. They are not written into Extension manifests.
Browser failures
If the browser cannot be opened, TurenOS marks the connection failed immediately and clears the pending OAuth attempt instead of waiting indefinitely. Retry after checking your default browser and desktop logs.
Review the provider’s requested scopes before authorizing. OAuth grants the remote service access represented by those scopes; TurenOS permissions control agent use of discovered tools afterward.