Completes the browser OAuth callback once per page load.
This host validates the CSRF state and restores the browser provider. The MCP
SDK transport owns callback parameter parsing, issuer validation, OAuth error
handling, and the authorization-code exchange.
Completes the browser OAuth callback once per page load.
This host validates the CSRF state and restores the browser provider. The MCP SDK transport owns callback parameter parsing, issuer validation, OAuth error handling, and the authorization-code exchange.