FastMCP stores pending browser-to-transaction consent bindings in one signed `MCP_CONSENT_BINDING` cookie. Each approval reads the map from its request's cookie header, adds its transaction, and writes the full map back under the same cookie name.
If two approval requests from one browser are processed before either response updates the browser's cookie jar, both can start from the same cookie snapshot. Each response then contains only its own new transaction plus the prior entries. Applying the later same-name `Set-Cookie` replaces the earlier map. When the identity provider returns for the transaction whose binding was lost, the callback rejects the approved flow with HTTP 403, `Authorization session mismatch`.
This affects overlapping OAuth consent approvals in one browser. Sequential approvals preserve both bindings. It causes an authorization flow to fail; there is no evidence of consent bypass or token exposure.
Expected behavior: each approved transaction retains an independent browser binding so both overlapping flows can complete.
### Example Code
```Python
```
### Version Information
```Text
- FastMCP main: `5baeacfe20eca735cb949564b4915f93a622b916`
- Python: 3.12.15
- OS: macOS 15.0.1 arm64
```
What happened?